Nope, don't use groups - when you put a group into a VPN policy on a ScreenOS device, it can cause it to try to use 0.0.0.0/0 as the proxy-ID for the group. Unless the other end is also a ScreenOS device, this probably won't work.
Unfortunately, to get the correct proxy-ID pairs, you'll probably need to create 4 separate policies:
192.168.1.0/24 to 10.0.1.1
192.168.1.0/24 to 10.0.2.2
192.168.2.0/24 to 10.0.1.1
192.168.2.0/24 to 10.0.2.2
(Tick the 'modify matching bidirectional VPN policy' box if you need access in the opposite direction too)