Full Tunnel I assume refers to Hub Mode.
It's "allowed" in the gateway object here:

You can require your clients to use it here:

As far as I know Updatable, Dynamic, or Domain can ONLY be used in this exclusions_ group and ONLY when Hub Mode is used (as configured above).
The only item in your RemoteAccess Encryption Domain is this exclusions_ group and not other objects (i.e. the stuff you want the client to access directly without being routed through the VPN tunnel).
When you are not using Hub Mode, then you must manually specify what hosts are in your encryption domain using standard Network and Host objects (not , , or