I'm a little confused about what you are doing. If you want to connect machines in site 2 to some of the machines in site 1, just make the phase 2 match 192.168.100.32/29. Don't know why you are changing gateways, etc. Anything on site 1's LAN is going to be directly connected, messing with your subnet masks is not the way of it. If you want to restrict traffic between machines on the LAN, put them on different interfaces/subnets.