Source NAT was causing return traffic to be left out of the VPN. Added a separate rule for specific source and destination IPs and source-nat interface off action. Issue resolved.