Right now our CLI disallows using IPv4 internal networks over IPv6 IPsec tunnels and vice versa.
It's an artificial limitation introduced back in Vyatta Core times: https://github.com/vyos/vyatta-cfg-vpn/blob/current/scripts/vpn-config.pl#L543-L550
As far as I remember, we've added that restriction because we didn't have QA personnel time allocated for testing it, and we didn't want to roll out a potentially broken feature.
So, we chose to disable that path until someone comes asking for it, and until recently no one asked.
Now it's time to verify that it works with up to date StrongSWAN and officially allow those configurations.