Rebooted with portsentry off, routes (at least the one internal one that was failing before) are now ok! Somehow I either misconfigured portsentry, or it is malfunctioning.
I prefer to have it on to guard against threats, but I have to have this working.
Actually when I say "I misconfigured" it is more than likely Webmin itself (version 1.300) actually made the config. files, it's only a question of what I could have put in the GUI to make it do so.