On the server-side (if that's the right config), looks like it's set up as a remote access server, which isn't what you want. You need to change the server mode to one of the Peer to Peer options and configure the server for either a shared key or PKI setup.
On the client-side, the client is not routing any networks over the tunnel.
So, there appear to be several issues:
The server-side needs to be reconfigured for Peer to Peer mode
The client-side is not routing any networks over the tunnel.
a. If the objective was shared key, here's one of your issues
b. If the objective was PKI, the server-side will need iroute statements for the client's network(s) in the CSO section
The client override screenshot posted in your OP is missing an entry in the "
IPv4 Remote Network/s", which will autogenerate the iroute statements needed for the server to reach the client's network behind this connection. Assuming you went with a PKI setup.
This is unlikely, but the client-side is double NAT'd behind an edge device, so if basic end-to-end IP communication still isn't working after making your corrections, it's possible that the client may need a static route on the edge device for the tunnel network.