Chapter 11 IPsec VPN for FortiOS 5.0 : Gateway-to-gateway configurations : How to work with overlapping subnets
  
How to work with overlapping subnets
A site-to-site VPN configuration sometimes has the problem that the private subnet addresses at each end are the same. You can resolve this problem by remapping the private addresses using virtual IP addresses (VIP).
VIPs allow computers on those overlapping private subnets to each have another set of IP addresses that can be used without confusion. The FortiGate unit maps the VIP addresses to the original addresses. This means if PC1 starts a session with PC2 at 10.31.101.10, FortiGate_2 directs that session to 10.11.101.10 — the actual IP address of PC2. Figure 257 shows this — Finance network VIP is 10.21.101.0/24 and the HR network is 10.31.101.0/24.
Figure 257: Overlapped subnets example