@paul-heidenreich-0
Outbound NAT doesn't work with policy-based IPSec tunnels. You have to do the NAT inside IPSec.
It should work with VTI IPSec, however.
If you have already a phase 2 to for the NAT-IP or subnet at the remote side, an additional is not needed in most cases.
You have always have to add the remote networdk to the "local networks", no matter if you use BINAT or outbound NAT.
That's correct. But you didn't mention, that you have already done this.