I have an internal workstation that needs to be NATed to an address separate from the Internet global pool that needs to communicate over a site-to-site VPN tunnel but still use the Internet global pool when accessing the Internet. The tunnel is crea...