If you've got VPN Registry is not reachable then you'll need to fix that first, and then deal with the 'unfriendly' NAT. VPN Registry unreachable means AutoVPN will never work. The MX devices must be able to contact their VPN registries on UDP 9350 or UDP 9351, the IP address is given under Help -> Firewall Info on the Dashboard (the information there is dynamically generated as its potentially different for every organisation). You'll need to allow traffic out through the firewall to the VPN Registries and allow the return traffic too (if the firewall doesn't automatically allow the return traffic). That traffic comes from a dynamic source UDP port on the MX, the same one that is ultimately used to establish the connection between the two MXs.
... View more