IPsec routing (firewall4)

There's an option for that. Within the wan zone, set
list masq_dest !10.5.5.0/24

That will exempt the 10.5.5.0/24 subnet from masquerading. This way no manual rules are required.

5 Likes