This section describes how to configure DS-Lite NO-NAT.
The following configurations must be complete before configuring an interzone NAT policy:
When the CGN device receives packets from the CPE, NAT shall not be performed on the packets in certain scenarios. As shown in Figure 1, public network users in area A need to access the server in area B, and an IPSec tunnel is established on the routing device. The router does not support NAT traversal. If the CGN device performs NAT on received packets, services are interrupted. Therefore, the CGN device is required to perform only DS-Lite tunnel decapsulation but not NAT on the received packets.