Global VPN cannot access Control network zone

I have a TZ270 firewall set up with the SSL VPN. This lets me connect to my CONTROL network zone. Using the global VPN client I'm given an IP address on the LAN zone, but I cannot access the CONTROL zone. Only VPN users should have access to CONTROL, not LAN users.
In the CONTROL zone, all the IP addresses are statically assigned. I have a NAT policy to allow the SSLVPN to connect to the CONTROL zone.
What do I need to change in the settings to allow the VPN to communicate to, and only to, the CONTROL network?
Category: Entry Level Firewalls
Do you have Access Rules allowing traffic VPN to CONTROL?