Re: IPSec VPN: Client traffic goes through. Remote firewall has no access.
Set an ip like 10.0.0.1/32 on one side, like Home-site's To_HOME interface, and 10.0.0.2/32 on "remote-ip" on the same interface. Do the opposite on the other side. Then add them to phase2 selector sets to let it access to the other side subnets. Routing would be automatically there as connected routes. When you access from the FGT, the FGT use it as the source IP. With interface-mode IPSec the tunnel interface should have an IP for routing to work.