Ugh… That policy routing stuff is soo powerful that the inevitable result is that it takes eons to troubleshoot just about anything :frowning: I try to avoid it as much as possible…
To me it seems that the key is the route table entry default via 10.86.1.1 dev eth0.1 table 1 as that’s the only one I see that can override the 10.89.5.0/24 dev wg0 entry.
The rule list says 2001: from all fwmark 0x100/0x3f00 lookup 1 but I’m hazy on how to link all the iptables stuff to that rule being chosen. Would take another dive into the manuals…