Update 2: Fixed it. It is not so clear that vti interfaces ip addresses have to be routed also. To make it simple: use single /24 subnet for all vti tunnels and add this subnet to "Static routes" at every site
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.