VPN related firewall settings
From Wiki of WFilter NG Firewall
1 Web UI access
When site to site VPN is established, you can access peer subnets, but you won't be able to visit peer NGF web UI, unless below firewall rule is added(allow WAN input from peer IP):
2 Enable forwarding of branches
Without this setting, branches can access headquarter, but no access between branches.