So I've got 50-some spoke networks, all going back to the hub network, split-tunnelling traffic for main campus & internet traffic. Everything works great from spoke to hub. But something is wrong when trying to contact devices on spoke networks from the hub (main) network - example: printer in the middle of Idaho can email the mailserver in Montana at the headquarters with a scan-to-email message, and then the spoke destination workstation gets the email.
But I can't manage the printer remotely via IP & web interface from the Montana headquarters! Pings and traces all stop at the campus LAN MX device IP.
VPN status page says both ends of the network are exported. VPN Configuration page says all local networks are enabled for VPN mode. I've checked & proofread the subnetting on both sides of the tunnel. I'm barely running any layer 3 firewall rules.
Help me from my own stupid, please. I'm sure I've just missed a step.