Coincidentally I had previously enabled this somewhere to test and things were working, enabled at another client today to further check things out and I guess this issue popped up an issue as inbound client vpn (AnyConnect) was shut off.
The documentation doesn't seem clear that this will happen nor what rules are necessary to avoid it. Might be helpful to spell out examples in the documentation of how to allow this.
If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.