Having just fixed most of my self-inflicted wounds...I think I've almost figured out how much I don't know. So...
I've now established both an IKEv2 and a SSTP connection between a remote MT router and my office MT router. They work...so far. But having two VPN's my hope is to able to poke at one without compromising overall connectivity. My IPSEC setup has a split-include mode-config on the office router listing all the networks I need to able to interchange with the remote site. As a result, I *think* the necessary NAT rules and routes are auto-generated. At least - the rules are dynamically generated even if I'm not sure what's doing it...
But...the routes for my SSTP connection on the remote are manually configured and static. Which means I've defined the SSTP address/interface as the gateway for those routes. How can I have the IPSEC rules at least have higher priority than the SSTP so I'll have immediate failover as long as one connection remains up, but the "better" IPSEC routes will be primary?