Is it OK if I can’t ping or netcat host IP behind of VPN gateway?
I can ping the VPN gateway but not the host.
Looks like a problem with the routing traffic in the VPN.
$ ping 10.10.16.1  
PING 10.10.16.1 (10.10.16.1) 56(84) bytes of data.
64 bytes from 10.10.16.1: icmp_seq=1 ttl=64 time=224 ms
64 bytes from 10.10.16.1: icmp_seq=2 ttl=64 time=51.4 ms
64 bytes from 10.10.16.1: icmp_seq=3 ttl=64 time=343 ms
64 bytes from 10.10.16.1: icmp_seq=4 ttl=64 time=65.1 ms
64 bytes from 10.10.16.1: icmp_seq=5 ttl=64 time=181 ms
64 bytes from 10.10.16.1: icmp_seq=6 ttl=64 time=54.3 ms
64 bytes from 10.10.16.1: icmp_seq=7 ttl=64 time=226 ms
^C
--- 10.10.16.1 ping statistics ---
7 packets transmitted, 7 received, 0% packet loss, time 6011ms
rtt min/avg/max/mdev = 51.365/163.554/343.025/102.990 ms
                                                                                                                                                                                                                   
$ ping 10.10.11.252           
PING 10.10.11.252 (10.10.11.252) 56(84) bytes of data.
^C
--- 10.10.11.252 ping statistics ---
23 packets transmitted, 0 received, 100% packet loss, time 22508ms