UniFi Controller can't find AP across IPSec site-to-site VPN

I have two sites connected by an IPSec tunnel (192.168.11.x and 192.168.10.x) I setup a cloudkey and 7 APs at the 11.x site and everything was working great. We have since moved one of the APs to the 10.x site but the cloudkey can't see the AP at the remote site (it says it is disconnected). I can ping IPs back and forth to the router, the cloudkey, the various APs. The routers are not USGs but are allowed to pass all traffic back and forth.


Any suggestions what to do?