Most likely, the problem is that these destinations are not in your policy routing properly. Make sure that lan1 users have lan2 in their routing policy, and that the other users of 2.2.2.2 have the public IP of wan1 in their routing table. Thank you very much for your help, I will study the docume...