This article tells you how to set up a VPN behind an existing firewall. Once you are going to set up a VPN with one site behind an existing firewall or third party appliance, you can use routed mode and add a static route down stream on the upstream router?
However, if you cannot access to and configure that third party appliance, to set up an existing firewall is not as complicated as you think.
To set up the VPN behind an existing firewall, you can use site to site VPN with aggressive mode and it's not necessary to do any NAT tranversal.
In this case, for site SAN, you can configure the site as below.
For site LOS, you can configure the site as following picture.
Once the configurations are done, the VPN Tunnel will be up on both sides.