yes it does. So Tunnel is up completely.
Did you try to flow trace the traffic to see if it matched policies and routing is correct?
diag debug enable
diag debug flow filter daddr=<destinationip>
diag debug flow filter saddr=<sourceip>
diag debug flow trace start <numberofpackets>
that will show you what the FGT does with the traffic.
FGT uses the routing table to determine the path to the destination in Step #1
In Step #2 it looks for a matching policy. It does top down and the first match will win the packet.
If there is no policy that matches it would hit policy #0 (which is the deny everything from/to everywhere one).
However the fact that the tunnel is up tells me that there has to be at least one policy that references it (because otherwise it would not come up). However that does not neccessarily mean that it matches your traffic...
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams