Maybe the portal should not be in one of those 44.190 networks that are not supposed to be on IPIP, but it should be in another net-44 subnet that is both BGP routed on internet and IPIP routed on the mesh. Then it would work OK.
I could move it to a different block (not within 44.190/16) and set it up so that it’s part of the tunnel/mesh as well if folks think that will be better?
73, Chris - G1FEF