S2S VPN traffic has asynchronous routing

I have an RB5009 establishing a s2s tunnel via SSTP over Starlink to a headend CHR router and a /29 of public IP’s assigned to the RB5009. I see ping traffic coming from my home network via torch but its going back out via the WAN and if I build a static route sending my static IP at my house and aiming it at the gw down the vpn pipe then I see return pings.

I believe that what I need is policy based routing to say if it came from the tunnel send the return traffic back thru the tunnel.

I really hope that I have conveyed my issue if however I need to answer more questions I am all ears. I really appreciate any assist that may be offered.

edit: The /29 of public is coming from a larger /24 off the CHR, both are running rosv7

Well just for giggles I tried to use ChatGPT but its responses were less than helpful :smiley: