I have an organization with routed hub and full-tunnel configuration.
![Kamome_0-1575880100104.png Kamome_0-1575880100104.png](https://community.meraki.com/t5/image/serverpage/image-id/10810i9E09EAB7D89F486D/image-size/medium?v=v2&px=400)
This one works well until one of network have to use split network. So, I unchecked Default route option in Site-to-Site VPN configuration. But it still works as full-tunnel VPN.
![Kamome_4-1575880187005.png Kamome_4-1575880187005.png](https://community.meraki.com/t5/image/serverpage/image-id/10814i44A23CF510CB91F6/image-size/medium?v=v2&px=400)
I can understand why this is happening. Every site that participates in VPN network always gets default route from Center MX, and it overwrites site's default WAN route despite of Default route is unchecked because AutoVPN route's priority is higher.
But problem starts here.
Based on my prior knowledge, I excluded 0.0.0.0/0 from Center MX to not to advertise it via AutoVPN, so it won't take over default route when site's Default route setting is disabled.
- Site1 : Default Route -> Hub
![Kamome_5-1575880419658.png Kamome_5-1575880419658.png](https://community.meraki.com/t5/image/serverpage/image-id/10817iE9B4C1AAFDABF486/image-size/medium?v=v2&px=400)
- Site2 : Default Route -> WAN Uplink
![Kamome_6-1575880419660.png Kamome_6-1575880419660.png](https://community.meraki.com/t5/image/serverpage/image-id/10816i3A65693A1AAEADB3/image-size/medium?v=v2&px=400)
- Center MX : Default(0.0.0.0/0), Internal Summary -> Center L3 (In VPN No)
![Kamome_7-1575880419661.png Kamome_7-1575880419661.png](https://community.meraki.com/t5/image/serverpage/image-id/10815iE90A0425B551998F/image-size/medium?v=v2&px=400)
As soon as I saved this configuration, Site1(Default route is checked) cannot use Internet. Only able to use advertised summary network. Site2(Default route is unchecked) is okay.
So, I've captured packet from Center MX, and traffic from Site1 is coming from Site-to-Site VPN interface, but reply traffic is going towards LAN interface.
![aa.png aa.png](https://community.meraki.com/t5/image/serverpage/image-id/10818iF67ECBCE8CC8AAB3/image-size/large?v=v2&px=999)
Therefore, it seems that "VPN Participants" option in Site-to-Site VPN decides not only "selects which network/route will be advertised via VPN" also "decides which traffic is VPN traffic". Why this is happening?