IPsec, connecting and sending packets, not recieving them


Hoping someone can point me in the right direction.
I have set up an IKE2 IPsec VPN using the guide here:
The client connects, is assigned an IP.  I can see in the DNS server logs and the Firewall logs that it is sending out DNS packets and will attempt to connect to webservers.  From quick packet capture of the IP interface it that no packets are being returned.
Which configuration settings and logs are relevant here?  from search around i've not found anyone in a similar position.
thanks !
NAT mode is: "Hybrid Outbound NAT rule generation."  & i can see the VPN network range added to the auto rules section
Pfsense version: 2.4.1-RELEASE
Outbound there are two routes, WAN and an OpenVPN tunnel (where pfsense is the client).


