mangle output log with src-address as WAN2 is clear I leave it couple of minutes while pinging from outside - nothing.
If I remove src-address, then I have many ICMP replies but only from my ovpn tunels and my main WAN1 - SFP1, nothing about ether8 (WAN2)
19:16:34 firewall,info output: in:(none) out:sfp1, proto ICMP (type 8, code 0), x.x.x.58->x.x.x.57, NAT x.x.x.58->x.x.x.57, len 56
19:16:34 firewall,info output: in:(none) out:sfp1, proto ICMP (type 8, code 0), x.x.x.58->x.x.x.57, NAT x.x.x.58->x.x.x.57, len 56
19:16:34 firewall,info output: in:(none) out:ovpn-1, proto ICMP (type 3, code 1), 192.168.11.1->192.168.3.204, len 124
19:16:34 firewall,info output: in:(none) out:ovpn-1, proto ICMP (type 3, code 1), 192.168.11.1->192.168.3.204, len 124
19:16:34 firewall,info output: in:(none) out:ovpn-2, proto ICMP (type 3, code 1), 192.168.13.1->192.168.5.23, len 124
19:16:34 firewall,info output: in:(none) out:ovpn-2, proto ICMP (type 3, code 1), 192.168.13.1->192.168.5.23, len 124
19:16:34 firewall,info output: in:(none) out:ovpn-2, proto ICMP (type 3, code 1), 192.168.13.1->192.168.5.191, len 124
19:16:34 firewall,info output: in:(none) out:ovpn-2, proto ICMP (type 3, code 1), 192.168.13.1->192.168.5.191, len 124