Set up a vpn tunnel of your preference, add a /30 transport network to it and set appropriate routes for the remote subnets.
Make sure you add accept rules for the traffic from/to the other subnet to traverse.
Add a NAT rule to masquerade traffic from the other subnet out to WAN.
Add routes to the services you would like to re-route with gateway=.
Well, I’d say this is normal as routes should point to connected networks - and 10.10.200.0/24 is routed, not local.
I’d suggest a GRE tunnel through IPsec to accomplish this.
And be sure you set up your masquerading rules on the remote side accordingly.