Hi
I am trying to do NAT translation inside the VPN tunnel and i cant wrap my head around this configuration.
The topology looks like this:

In the Encryption Domain on the Check Point i have 192.168.18.10 and 192.168.20.0/28
So server 192.168.18.10 should communicate with 10.10.13.1, which in turn is translated on the Fortigate side to 10.10.12.10.
First issue, Check Point will not route packet over VPN tunnel when i have 192.168.20.0/28 in the EncDom.
If i put 192.168.20.0/28, which i did for a test the phase2 fails, because of course this net is not on the other side really.
NAT is enabled in the community.
I need some suggestions on how to think here