I think the automatically generated outbound NAT rule would only apply to the LAN interface's local network (172.16.16.0/29). Since you're routing other networks behind that, I think you'll have to use manual outbound NAT and create rules to cover them.