Would use a transit subnet/vlan on the lan side and then set static routes. IPS also work between vlans. make sure to get firewall rules in place to allow only necessary traffic sourcing from your side, deny incoming from there IP's
If they where behind the wan interface you have challenges like default route-flow preferences, nat, and you need internet connection on that interface