Coincidentally I had previously enabled this somewhere to test and things were working, enabled at another client today to further check things out and I guess this issue popped up an issue as inbound client vpn (AnyConnect) was shut off.
The documentation doesn't seem clear that this will happen nor what rules are necessary to avoid it. Might be helpful to spell out examples in the documentation of how to allow this.
