Thanks for your update, I am again attaching my proposed diagram.
I am explaining my requirement again, we have zsclaler cloud proxy in my environment. 1st External interface connected to CISCO ASR router and we created GRE tunnel between CISCO ASR and zscaler, and 2nd interface connected to 2nd ISP, we applied PAC file for all users, users traffic pass through GRE tunnel.
and we have multiple server in Internal network and DMZ subnet, Server don’t have PAC file. If anyone login to any server and accessing internet they will pass through ISP-2 (without any security policy), and we want to pass specific traffic Https &http through ISP-1, which we can achieve with sk32225.
but my next requirement is we have one DMZ subnet, from internal to DMZ and DMZ to internal communication will require with port http & https.
which we can achieve through PBR, but my question is if we change the table.def file and allow specific traffic from ISP-1, in that case if my internal user will try to access DMZ server, will it take table.def configuration or it will work on PBR and traffic we will reach DMZ and vice versa?