Ahhh! After a search of the forums (2.0 forums at least since it seemed like a bug) turns up nothing and me having read most of the pfSense book recently and not seeing that info…quite non-obvious and harder than pfSense usually makes it (and I must have missed it). But, thanks for the link and for there being a workaround :-) Is there a reason this route is not added by pfSense automatically for known networks at the other end of IPsec tunnels?
I did test the solution, though the steps are a bit longer in 2.0 (have to add the new gateway first--and the "add one now" link from the Static Routes page didn't actually do anything when I clicked it, perhaps this is a real bug) it seems to be working now both for ping and for the DNS Override. Thanks!