I can only comment on 'some' answers, not all. There is no comment button for the latest answer which is frustrating.
Anyhoo, changing interface order, or indeed disabling the first does indeed work just fine, but, this doesn't do what I need. The first interface MOB1S1A1 is by far the fastest and provides the best connectivity, but, due to the ISP's filtering I cannot establish an IPSEC over this connection. MOB2S1A1 is slower by far but doesn't have any filtering and establishes an IPSEC just fine.
So, all traffic to go via MOB1... and just the IPSec over MOB2... is what I'm trying to achieve. I can of course route traffic over the ipsec (table 220) but what I can't seem to do is make IPSec use MOB2... as the originating interface specifically with everything else not. I should be able to use strongswan's install_virtual_ip_on / interfaces_use / interfaces_ignore options to do what I need, but this brings me back to the relationship between MOB1.... and wwan0/wwan1 that I posted at the start. IF wwan0 was always MOB1S1A1 then I could get there but as shown above its not that simple and I don't know how these wwanX get assigned to the modems?
I hope that makes sense?