Hi,
You can enable NAT under the 'Advacned' section of your policy.
Also, 'tunnel all' from a VPN client gets complicated wit a policy based VPN. I would suggest using a route based VPN (https://kb.juniper.net/InfoCenter/index?page=content&id=KB15272) to make the setup more flexible.