Not an expert and this could be a guess on my part, but I think the issue is that the node will only answer to ssh, ping, and https from devices inside of its LAN (192.168.250.x in this case). Since my VPN connection traffic is coming from 172.28.x.x I think the node is refusing the connection...