I dont know. I figured marking the dst-address with a routing-mark to be routed in prerouting would get them to route before the nat rules. It is not the src or interface I am trying to route by but the dst-address that they want to get to, the vpn traffic.