Since you mentioned that you want the customer to perform the NAT before the packets enter the tunnel, the customer can configure Source NAT (SNAT) on their internal network to translate their internal IP addresses (e.g., 192.168.1.0/24) to a single ...