I have to configure a VPN site to site, the vpn is already working. but some CEOs doesnt like how its done, because one subnets of the peer is 10.*.*.* and it matches with my private subnet (10.*.*.*), so they want me to nat my subnet. The vpn site to site now is configure with the 10.X.X.X and peer (4.4.X.X)
Does anyone did that before?
This is a common practice when there is overlapping local networks when doing L2L vpns, this is call Policy NAT, where either end NAT their internal IPscheme in their tunnel policy, here is a link with an example of Policy NAT in L2L vpns.