Hi Bucket, it isn't that NAT stops working, it's that the default route installed to the appliance creates an asymmetric route. For sites with resources that need to be accessible from the public internet, you need to either create a VPN exclusion rule to break traffic out of the VPN tunnel, or deploy the appliance as a hub to prevent the default route from being propagated.
... View more