Depending of the type of vpn you might need to create some ip rules with the vpn services and protocoles.
see : service named pptp_suite, ipsec_suite, there must be some for l2tp and l2tp over ipsec.
just create a new service group with these service inside and then create the ip rule that will use this new service group.