How did you configure IPSEC? Classic or VTI mode.
In VTI mode, just add routes to tunnel interfaces (or let OSPF do it automatically).
In classic IPSEC mode, you need to add second tunnel under peer definition, allowing 10.1.1.0/24 <-> 10.1.11.0/24 traffic