Then you need - an outbound NAT rule that maps OpenVPN client addresses to one from 192.168.100.0/24 when accessing 10.1.1.0/24 - add a Manual SPD entry in IPSec Tunnel Settings with your OpenVPN client network (Tunnel network) to the phase2 IPsec definition.