After you check the logs and anti-spoofing, check the interior router and make sure it has valid return routes via the SMB 1575 gateway. How is your L2TP client connecting to the network; is it connecting via the SG1575 external interface, or something else? Check the active routes on the L2TP client to see if the routes are being installed correctly. You can try traceroute, but this may be ambiguous for an L2TP client, so don't fall into a trap of troubleshooting the wrong problem if traceroute fails. However, if it works, then that is excellent.
If line 9 can be pinged, but others cannot, check the internal router to make sure it has interfaces in "Up" state for those VLANs. Check the hosts on those VLANs to make sure they can send return traffic via the internal router for your L2TP client (either default route, or something else).