For policy based vpn you need to have two separte tunnel enabled polcies adding one on both sides for the new ip address pair.
Locate your tunnel policy from 192.168.11.0/24 to 192.168.1.0/24
Create another policy with the same zone to zone designation using the new pair 192.168.11.0/24 to 172.16.2.0/16
The action needs to be tunnel and a pair policy
move this policy in the order to be right next to the current policy
This will need to be done on both SSG20