Glad it's working. It looks like you're using split tunnel, so my thought was it had to be on the client end, but you're also double NATing and using port 443 instead of 1194… that probably has something to do with it.
Also, I'm curious to know why you're pushing out google DNS with a split tunnel deployment.