Hello All, We have a CSR running in AWS in a transit VPC design and have been using this for NAT'ing to hide the servers private addresses to 3rd party vendors further downstream. Server <--- VPN A (inside) ---> CSR <--- VPN B (outside) ---> OnPrem...