that scenario need to apply some changes over normal configuration to allow branch 1 communicating with branch 2 passing by the dfl 800
its necessary to declare remote branch network on the ip sec tunnels and the subsequent route from too branches.
in dfl 800 ip rule set you need to allow traficc passing from one tunnel to another form and to the respective branches.