With a shared APN solution, the CPE WAN IP (SIM) is generally obtained using dynamic private IP addressing. If 2 sites are connected via the same Packet gateway, CGNAT would allow sites to communicate to the Internet (outbound) to public destination IP addresses. Can 2 sites on Private IP, set up an IPSEC site to site tunnel using UDP hole punching (persistent NAT) via the Packet gateway?