Can you add a service object group in an encryption domain when setting up a s2s on an ASA?
Example:
object-group network local network-object host 10.0.1.0 object-group network remote network-object host 10.0.2.0 object-group service ports service...