Hi Brian,
So there would be a few things you would have to do.
1) Update the nat rules to make it so the UC doesn't nat the traffic out (which is what you are saying is happening)
2) You need to update the acl's that describe the interesting vpn traffic
3) You need to ensure the acl's for the appropriate interfaces are not blocking what you are trying to do
4) update the routing tables
5) This "may" be supported.
A much safer way is to use an ISR in front of the UC's to run dynamic routing and something like dmvpn, which makes a lot of this easier... more complex to setup, but 'easier'.
Now you can also do dmvpn, and dynamic routing on the UC. This is NOT a supported configuration, but I know it works and is very functional. When you have an update or you need support, you will have to verify this configuration manually.