Basically you need to put the RED Network into the "Local Network" in Ipsec. Thats it.
(Maybe you need a new firewall rule).