Thanks for the reply, Philip.
The thing is we need a full mesh topology and all sites have their own Internet resource.
So there is no spoke site. And at each site I see more then one default routes.
One points to WAN uplink (Internet), others point to remote VPN sites. But I don't know how to remove the unnecessary ones.
And Site-to-Site outbound firewall has one default policy allowing everything.