Yes, you need to create a WSAM destination on the role SAM tab.
You do not need to enable VPN tunneling for using SAM; however you do need to enable Secure Application Manager, WSAM.
can you confirm if the external IP of the SSLVPN refers to the physical port IP (which will cause access to be denied by the AWS ACL) or the NAT IP of outbound traffic from the PCS internal port as routed through your internal network out to the internet (which should be allowed by the AWS ACL)?