How is the main edge router connected? To the outside of the ASA or to the inside of the ASA?
1) If it's connected to the outside of the ASA, then you would need to configure the following:
same-security-traffic permit intra-interface
nat (outside) 1
Assuming that you already have a corresponding global statement with sequence of 1 for the outside interface.
2) If it's connected to the inside of the ASA, then you need the following instead:
route inside 0.0.0.0 0.0.0.0 tunnelled
Assuming that your main edge route is doing the PAT for web browsing to the internet, then you would need to include the VPN Pool subnet in the NAT statement on the router, plus route for the ip pool subnet back towards the ASA inside interface.