I'm still learning and not very good at this.
First, I have a fairly large (geographically) network connected together over PTP wireless links. The links are routed with OSPF (no WDS/EOIP) and it works fairly well. For internet, all the sites route out the HQ internet connection which has a Sonicwall 3060 firewall. Two remote sites (HS & J) have internet connections and HQ has a second internet connection all for the purpose of site-to-site redundancy (internet traffic only routes out HQ's primary internet connection) in the event a wireless link goes down.
Here is a simplified diagram for purposes of this conversation.
The wireless part had been working fine but I hadn't configured redundancy. I opted for IPIP tunnels (J-to-HQ and HS-to-HQ) encrypted with IPSEC transport mode so I could run OSPF over them. That worked fine and I now have redundancy except for one problem... when traffic is routed over the IPIP tunnels I cannot use the internet at them. If I fail back to the wlan links it works fine. More specifically, I can ping out to the internet fine but HTTP web traffic doesn't work. Sometimes it will pull a small part of the webpage but then it doesn't load. All site to site traffic of all nature works fine including intranet HTTP traffic.
I feel like the 1480 MTU size is the problem (upsetting my sonicwall?) but I'm not sure. I tried all sorts of MTU settings changes to make it work but nothing helped.
Any ideas or suggestions on what to do or do differently? Switch to VPLS for the redundant links?