Hello,
Daniil we had issue described in subject on vyos installation
- VyOS with public network, internal network, ipsec network(far end)
- several DNAT rules from public ip to internal network hosts(like FTP and WEB)
When host from ipsec network(far end) try to access any port which is used in DNAT it will be always forwarded to DNAT destination host, even if explicitly used ip address from internal network range