Is the correct solution for such outbound NAT to use "Single host or Network" and use the IPSec VPN subnet instead of selecting "IPSec net" for "Source address" in the manual outbound NAT definition for IPSec traffic?