I had this situation crop up late last night. We had made some minor changes to our routing that resulted in a near disaster which is not yet fixed (minor changes being we changed our reachable IPs for our two WAN connections). IP addresses changed for privacy reasons.
The router is now improperly routing outbound traffic, in contravention to what the routing table actually says.
We have two WAN connections, WAN1 and WAN2. WAN1 is configured on p3, WAN2 configured on p4. In the routing table on p3 we have a directly attached network with target network address of 188.8.131.52/29, default gateway is 184.108.40.206. This auto creates a default route gateway route 0.0.0.0/0 with gateway address as 220.127.116.11. Metric on both routes is set to 10. The public IP address assigned to p3 is 18.104.22.168
For WAN2 we have a directly attached network on p4, target network address is 22.214.171.124/30. Default gateway is 126.96.36.199. This creates a default route 0.0.0.0/0 with gateway address 188.8.131.52. Metric on both is set to 20. The public IP address assigned to p4 is 184.108.40.206.
We do not have any source based routing entries at this time. Also, the aforementioned reachable IP addresses have been removed and are not in place at this time.
In our firewall rules, we use a weighted connection object for WAN1 and WAN2 that includes failover. WAN1 gets a weight of 10, WAN2 gets a weight of 1. Most connections, obviously, would use WAN1 with a few using WAN2, and with all connections failing over to one if the other goes down. This configuration worked fine for years right up until the day it didn't.
Additionally, we have WAN1's interface (p3) configured in a router layer 2 bridge with p5 and p6. This is to accommodate two devices that need public IP addresses in the 220.127.116.11/29 address space. Again, this has worked fine for a very long time and, indeed, is working now. This is the one major part of our network config that doesn't seem to have been affected. I only mention it for reasons that will be clear later in this post.
As of today, WAN2 is effectively non-functional. I've got WAN1 up and running and its our primary so it hasn't yet caused us a disaster. I'm using a firewall rule on a test machine so that traffic coming from my test machine is using explicit IP for WAN2 (18.104.22.168). The firewall indicates that this traffic is attempting to source nat out of the WAN1 interface (which is the bridging interface). It shows its next hop is 22.214.171.124 instead of the appropriate next hop, 126.96.36.199.
At this point I thought I might need some source based routing entries. I created one for each WAN, more or less matching what was in the routing table. This caused my WAN2 to work, but also caused the default route associated with WAN1 to be list as 'off' in the routing table. Not disconnected, not down, off. This made no sense to me, so I pulled the source routing so I could at least have my primary WAN1 working.
In my troubleshooting, I wondered if my network bridge was causing the issue. I removed the bridge and restarted the network configuration, leaving p3 with only its public IP address 188.8.131.52 and no bridging. Not only did this not help, but the bridge interface was still present, despite the fact that it had been removed from the configuration.
We recently updated our router's firmware to 8.01 and we updated our CC and Range to 7.2 There have been odd things like this happening since that time. I have never encountered a situation where a configuration item, in this case the interface bridge, remained present even after being deleted and then visually verifying multiple times it had been removed from the configuration.
I post all of this in search for a solution to get secondary WAN functioning again, but also as a question. I am strongly considering wiping the router to its originally factory settings and reloading a PAR file to reconfigure it. Should I go that route, which looks increasingly likely, what is the correct way to do it when using a CC to control my routers?