Currently we use OpenVPN/Wireguard Full Tunnel encryption behind a DNS server for connecting to our clients devices. (We have over 6000+.) We have OpenZiti used within our company connecting to our internal services which works great. However, our Firmware developers want to be able to have both OpenVPN/Wireguard and Openziti enabled. From my testing, I have noticed that if we have OpenVPN/Wireguard Full Tunnel encryption and Openziti enabled, Openziti fails. If we utilize Split Tunnel encryption, it works with OpenZiti.
Wondering what would be the best way of managing this so our Firmware developers can work with connecting to devices as well as staying connected to our internal services?