Access from VPN Client over next VPN

I have two location - office with Synology for users sharing files and VM in datacenter with next server for company information system. In datacenter is pfSense with connection for external users over IPSec VPN client (Windows). Between office and datacenter is connection over site-to-site IPSec VPN. Now we need access from mobile client to office Synology. Router in office is ZyXEL USG Flex 100.
Schema


VPN 192.168.173.0/24 to 192.168.89.0/24 works O.K., access from client to server 192.168.173.3 is O.K.


If I was enabled second Phase 2 for IPSec clients, connection from client to server 192.168.173.3 don’t work. It is to possible add any routing rules ?

This is correct settings Phase 2

Phase2