route vpn users without nat

Hi
i have a network with some local web servers that this servers are behind a firewall
my users in order to connect to internet use vpn connection to a 1100 mikrotik and in mikrotik vpn source ip become NAT to valid ip

my question: when local users connect to mikrotik (via vpn) for reach to local web servers, i want to route them to my firewall in order to route to local web server without using nat in mikrotik and with caller id source( nic ip address) not pptp tunnel ip( that ip is dynamically). i need source caller id (ip) for some security and logging reason.

who know to do it?

best regards