VPN related firewall settings
From Wiki of WFilter NG Firewall
1 Web UI access
When site to site VPN is established, you can access peer subnets, but you won't be able to visit peer NGF web UI, unless below firewall rule is added:
2 Enable forwarding of branches
Without this setting, branches can access headquarter, but no access between branches.