Traffic sourced from a local host and destined for a remote subnet over a policy-based site-to-site IPsec VPN (IKEv2) does not undergo the configured Source Network Address Translation (SNAT), and the translated source address is not observed at the remote endpoint. This occurs on SonicOS 8.2.2 and 7.3.2 when a manual NAT policy is configured under Network > NAT Policies for traffic that also matches the Local and Remote Networks defined in the IPsec VPN Policy.
1. Verify that the traffic in question matches the Local Networks and Remote Networks defined in the site-to-site IPsec VPN Policy.
2. Note that when a Policy-Based VPN is configured, the IPsec Policy takes precedence over manual NAT policies for traffic matching the negotiated Security Association (SA).
3. Configure the required address translation using the built-in NAT feature inside the IPsec VPN Policy configuration instead of a manual NAT policy under Network > NAT Policies. Reference: https://www.sonicwall.com/support/knowledge-base/how-can-i-configure-nat-over-vpn-in-a-site-to-site-vpn/kA1VN0000000NBA0A2
4. Verify the translated source address by capturing packets at the remote peer and confirming the expected translated source IP appears.
Note: