HQ has firewall and LAN IP segment of 192.168.90.x
Digi WR31 in the field has static WAN IP over cellular ( Verizon ) and LAN IP segment of 10.90.33.x Eth0 on Digi is 10.90.33.5
HQ and Digi are connected via an IPSec VPN Tunnel
Once the tunnel is up, I can connect to the web interface of the Digi on 10.90.33.5 and can also ping that interface.
There is a switch connected to Eth0 and devices connected to that switch ( all are on the 10.90.33.x network )..... but... I can't ping any of those devices or connect to them from HQ.
If SSH into the Digi, I can ping them from inside the Digi, which tells me there is a config issue on the Digi.
Firewall is only enabled on the PPP1 interface.