Well, that was fun.
Turns out, CNServers (and our tunnel setup) was just fine. The issue was (of course) HE.
Fran noticed that when he shoved outbound traffic back through CNServers, everything started working fine again (though this couldn't be a permanent solution, as it put a ton of strain...