ssl vpn to site to site vpn to lan - no connection

The set up is

remote user → ssl-vpn → xgs-116 → branch lan → site to site vpn → other brand router → main lan


The site to site vpn has been working fine for years. Branch lan users access main lan fine.

I have the new remote user to branch lan working, but I cannot reach on through to the main lan.

I do have both the branch and main lan listed under tunnel access permitted network resources.

Tunnel all is off.

I must be missing something?