Hi @whocares01
Thanks for posting in our business forum.
Depends. Bear the purpose of the VPN in mind. You are using VPN for tunneling between two sites or a client and a server. If you use IPsec site to site, then the clients of two sites are available for each other. Client to site permits the client to access the other site. You can specify the IP range of the site.
You can probably implement ACL because it can be IP-based.
But your questions seem to be pretty weird. Seems to be that you want to mask the IP address on your local site. I don't know how much VPN knowledge you have. But if your goal is to mask the real public IP on the WAN setting, you should use Proxy(full tunnel) mode instead.