@viragomann
I finally managed to do it by adding 10.10.10.0/24 to phase 2 at local and remote site.
I should have been more concrete in the initial problem description.
The problem was not, that I could not add a phase 2 entry at the remote site, but that there is another router behind the vpn remote gateway and the remote clients.
And it would have been impossible for me to add routes on this router.
Now I added 10.10.10.0/24 as phase 2 just to bring up the tunnel and force the kernel to route the traffic (DNS responses) over IPSec. In this configuration, native communication between 192.168.0.0/24 and 10.10.10.0/24 is still not possible, but port forwarding from 10.120.0.250>10.10.10.10 now works like a charm 👍
So it's more like a hack than a solution, but it's not stuppid als long as it works 😁
Thank you for your support and merry christmas! 🎄