And due to different reasons.. let say that site-to-to is 10.35.0.0/16.
And openvpn clients need to be 192.168.xxx.xxx
Due to restrictions of already used networks..
And since it is IPSec site to site, they are not local networks, but routes into a local network.
From 172.16.20.0/24 to 10.35.0.0/24 local.