Chapter 11 IPsec VPN for FortiOS 5.0 : GRE over IPsec (Cisco VPN) : Configuring the FortiGate unit : Enabling overlapping subnets
  
Enabling overlapping subnets
By default, each FortiGate unit network interface must be on a separate network. The configuration described in this chapter assigns an IPsec tunnel end point and the external interface to the same network. Enable subnet overlap as follows:
config system settings
set allow-subnet-overlap enable
end