Packets dropped after ipsec decap

Hi, all, I'm setting up an ipsec VPN like below, but the decapsulated packet could be seen in wan interface, not forwarding to br-lan. I also checked firewall, seems the packets passed the firewall rules, can anyone help to advise what can I check else? much thanks.