Yes, enabling VPN for those subnets too, will make sure that the static routes via 8.1 are also distributed to the VPN peers. Keep in mind that you'll need to setup return routes in those subnets too. Otherwise the responses to packets can't be delivered.