You may configure st0 interface to a separate zone (e.g:- VPN) and don't configure source nat from trust to VPN zone. and configure source nat only from trust to untrust zone
↧