Hi, I would need to put up a lab to do some tests and give you all the needed steps, the best solution would be to declared 0.0.0.0/0 as a remote network using the other side of the ipsec tunnel as gateway, but I saw myself it complains about overlapping networks (your local net is comprised into 0.0.0.0 obviously). Need to do some tests.
Luca.