Dear Concern,
I need to configure an IPSec VPN on my FortiGate firewall, where user traffic should be NATed to a specific set of dynamic IP addresses before reaching the remote side. This is necessary because the remote side will only allow traffic from a few specific IP addresses. Kindly assist me in configuring this setup.
My Firewall Details:
Model: FortiGate-201F
Firmware Version: v7.6.2 build3462 (Feature)
Here is the official documentation for IPSEC VPN with overlap subnets (meaning using NAT).
Site-to-site VPN with overlapping subnets | FortiGate / FortiOS 7.4.3 | Fortinet Document Library
The only difference from you case is that you only need to make the changes for NAT on your side, just ignore the remote side.
@adrianiovita 
Thank you for sharing the guide — I will follow it accordingly.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.