Assuming that your Domain Controllers are not normally accessible then we can assume that your VPN tunnel is providing connectivity. The next step it to determine if routes exist and if they are allowed, but we do not have any information about the subnet that the member servers are located. My initial gut feeling is that
Please provide the subnet information to the member services.
You may also want to provide the Domain Controller subnet information so we can more quickly identify what is different about the two routes and access-list.