Users with network connect, the SA use NAT for this users, or each user use its ip addres to reach the network.
With Network Connect and Pulse, the client PC receives an IP from either DHCP or an address pool, which is confgiured in the relevant Network Connect Connection Profile. This is used as the source IP for any connection over the VPN to the internal resources. Split tunneling can be configured if you do not want all traffic to be directed over the VPN tunnel.