Hi, I have problems to reach this goal, I have 2 ISP with public IPs and i wanna create 2 IPIP tunnels with Ipsec and reach them from outside. Like the diagram below. is this possible ?? Thanks in advaced

Hi, I have problems to reach this goal, I have 2 ISP with public IPs and i wanna create 2 IPIP tunnels with Ipsec and reach them from outside. Like the diagram below. is this possible ?? Thanks in advaced

It depends how much sofisticated you want it. It seems to me that the simplest way would be just using static routes on central side (3.3.3.2/32 via 2.1.1.1 and 4.4.4.2/32 via 2.2.2.1). It would prevent 3.3.3.1 from connecting to 2.2.2.2 and 4.4.4.2 to 1.1.1.2, but you could make the routing conditional for IPSec only.
Install CHR in cloud, create on them ppp server, configure ospf.Ppp clients(cenral, site a, b) connect to the central router CHR through isp1 or/and isp2