Fallback to WAN

Hope that someone can give a push in the right direction:

I have a setup with a LAN, Wireguard and WAN/WAN6 setup

I can swap between Wireguard and WAN through VPN Policy Routing.

What I need is an automatic fallback to WAN in case the wireguard tunnel is broken ... I have to sacrifice security for operational stability if that happens.

Any ideas ?

put both to wan zone and use mwan3 to use wg as primary?
(with rule to remote peer as real wan only

Try to set up failover using mwan3:

Thank you all for your input ...

This seems to have solved my problem:
I created two WG interfaces (separate private keys) and did not mark the "Route Allowed IPs" in the Peers section of both interfaces.

I created two WG interfaces (separate private keys) and did not mark the “Route Allowed IPs” in the Peers section of both interfaces.

I created the firewall as you can see on Zones picture.

A positive side effect was in the “VPN Policy Routing” where the default Service Gateway now is the WAN. (not randomly between Gateways, WAN, WG1 & WG2).
This means that the router has an auto fallback to WAN in case a WG tunnel looses connection, by using the config parameter "Strict enforcement" with "do not enforce policies ....."

