routing VPN traffic only in one direction

We normally setup VPN’s from WR21’s (remote) to our VC7400 using address (remote) 172.168.x.x/28 to (VC)
I need to setup some routers not using the, say 172.172.x.x/28 to 172.169.x.x/28 (I have set Eth3 to
The tunnel builds and I can ping from the remote to the VC, but cannot go from VC to remote.
What do I need to set at the VC end? default route or a specific firewall?