You can't just assign the VPN client users addresses that are in this internal address? Or does this internal server only talk to one specific address?
If so, then no, you can't assign VPN users a pooled IP address AND NAT that to some other address all within the same PIX. You can of course NAT the VPN client packets to this internal address if they go through another router or another firewall just as you would NAT any other packet.