If a site-to-site IPsec VPN tunnel is created using the vti0 interface, VyOS stops routing external traffic (even through interfaces not related to the tunnel).
There is a corresponding question in the forum with discussion, routing tables and config examples:
[[ https://forum.vyos.io/t/external-traffic-stops-routing-when-ipsec-tunnel-comes-up/7673/39 | External traffic stops routing when IPSEC tunnel comes up ]]
version VyOS 1.4-rolling-202109130217. Not detected in version 1.3
Workaround:
change VTI number from 0 to 10 (vti0->vti10)