Go "Security Appliance/Traffic Shapping". Whatever port you select under "Uplink selection/Global Preferences/Primary Uplink" because the port used for client vpn. Note it can take 10 minutes to kick in after you change it.
From where you can configure "Flow Preferences/Internet Traffic" to override this and make all your Internet traffic go back out WAN1 (if that is what you want).