As long as "disable NAT in VPN Community" is unchecked, traffic entering or leaving a VPN tunnel is subject to the NAT policy just like any other traffic. To set up NAT for VPN traffic only you'll need to make sure the box is unchecked then set up a manual NAT rule at the top of the NAT policy. Be sure to set the Original Source and Original Destination Fields as tight and specific as possible to avoid catching unintended traffic in that NAT rule.
Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones