I don't think this will work, typically ezvpn creates an SA from the outside of the client to the outside of the server, but in this case I am not sure it and since this is not affected by split tunnel or any config I doubt it will work. Reason you need to make sure that an SA is created from outside of the ASA to the DHCP server, not the EZVPN server. Your most feasible solution would be a normal dynamic to static and yet on this one you will find problems when the ip address changes.