You can't use subnets contained inside your VPC subnet anywhere but the VPC itself. Use something outside of that for the other side of the VPN. Sorry. That's just the way AWS works, as you can see from that error message.