FlexVPN vs DMVPN behavior. Advice?

So I'm testing FlexVPN and I've found, for me anyway, a pretty big deal breaker.
I can't ping, telnet, connect to in any way (other than routing protocol,which works fine), the "directly connected" network.
What I mean by that is say my Tunnel interface is on one of my spokes, I can't connect to my hub at or another spoke at
Day to day this wouldn't be an issue but sometimes in the event of a network outage I need to be able to get in via my VPN backdoor.  So I'd go to and telnet to and wallah I'm in.  DMVPN this worked great and saved my bacon many times.  With FlexVPN this option is no longer available to me best I can tell.
Is this known behavior?  Is there a fix? Am I just doing something wrong?


Ping will automatically use the IP address of the interface the request is leaving from, but just for grins I went ahead and tried sourcing it explicitly.  No change. Again, keep in mind, EIGRP works fine.  So neighbors are forming between these Tunnel interfaces. Just no other traffic.  Here's the commands I used to add FlexVPN to my router:
ip access-list standard Flex-Route
permit any
crypto ikev2 authorization policy default
route set interface
route set access-list Flex-Route
crypto ikev2 keyring Keys
peer Router
  pre-shared-key X
crypto ikev2 profile FlexVPN
match identity remote address
authentication remote pre-share
authentication local pre-share
keyring local Keys
dpd 12 3 on-demand
nat keepalive 10
virtual-template 1
crypto ipsec transform-set ESP-GCM esp-gcm
    mode transport
crypto ipsec profile default
set ikev2-profile FlexVPN
set transform-set ESP-GCM
interface Virtual-Template1 type tunnel
ip mtu 1400
ip tcp adjust-mss 1360
ip unnumbered Tunnel673
ip nhrp network-id 673
ip nhrp shortcut virtual-template 1
ip nhrp redirect
tunnel path-mtu-discovery
tunnel protection ipsec profile default
interface Tunnel673
ip address X.X.X.X
ip mtu 1400
ip tcp adjust-mss 1360
ip address negotiated
ip flow ingress
ip nhrp network-id 673
ip nhrp shortcut virtual-template 1
ip nhrp redirect
cdp enable
tunnel path-mtu-discovery
tunnel source GigabitEthernet0/2
tunnel destination X.X.X.X
tunnel protection ipsec profile default
no shut