Hi,
Question 1:
I don't know about the capabilites of your DSR-250 with respect to IPsec traffic selectors that encompass several disjunct networks. But if it doesn't allow for that, you could trick it by renumbering network 192.168.10.0/24 vlan2 to 192.168.13.0/24 vlan2 and then aggregate both networks
192.168.12.0/24 vlan3
192.168.13.0/24 vlan2
to the single IP range 192.168.12.0/23.
Question 2:
Can you describe in more detail what the scenario behind this shall be? Using IP address 1.1.1.2/(unknown mask) for an inside host within inside networks out of the range 192.168.0.0/16 does not make sense to me, even more if it stems from an IP range 1.1.1.0/30 (or shorter prefix length), that is already in use for the router's wan interface.
PT