Hi.
You can try something like this:
1- If you can, configure subinterfaces on the link between PE/CE. One will be inside the VPN, and the other will be the "public" interface from the CE standpoint.
2- On the "public" link between PE/CE you can use private addressing as long as it doesn't overlap with the addressing being used in the rest of the network. The PE can do NAT to a public address.
The best way to do this should be different: you should have public addressing on the "public" PE/CE link, and the CE would do NAT.
Hope this helps.
NM