L2TP/IPSEC VPN cannot ping machines in the HOTSPOT

Hi, I just bought a CCR 1036 to be an access router in my network. I have three WANs and one LAN. And I setup L2TP/ipsec VPN. It’s OK. And I also setup HOTSPOT on my LAN port. Now I have a problem. The users cannot ping the LAN machines when they successfully connected with VPN services. I have setup VPN ip address to the walled garden but it’s no use. Any suggestion is appreciated.