Hi!
One can think of a scanario where:
- udp/500
- udp/4500
- ESP
- AH
is sent out through a particular interface by virtue of "ip local policy"
Traffic generated from the box doesn't work with PBR, you need a separate local policy.
On top I'd advise you tu use RRI or DVTI solution to avoid problems with routing through tunnel.
That being said, it's probebly not the best idea to set it up like this.
Please be aware that above solution will make ALL IPSec traffic go through this link, regardless of RA or L2L.
Marcin