Hi Kevin,
Like below:
global (outside) 1 interface
nat (inside) 1 10.10.10.0 255.255.255.0
nat (inside) 0 access−list inside_nat0_outbound
object networ obj-10.10.10.0
subnet 10.10.10.0 255.255.255.0
nat (inside,outside) dynamic interface
nat (inside) 0 access−list inside_nat0_outbound
For VPN you need to do nat exempt where you will define local subnet let's say obj1 and remote as obj2
so statement would look like:
nat (inside,outside) source dynamic/static obj1 obj1 destination obj2 obj2.
Regards,
Kanwal
Note: Please mark answers if they are helpful.