I figured it out, the remote subnets that terminate at the hub were not specified in the "site to site out-bound firewall" rules. Specifying an allow from our AnyConnect subnet to those subnets corrected the issue. I had mistakenly added that same rule under the standard outbound firewall rules.
... View more