From my experience, the OPNsense firewall is a good choice for terminating a lot of site2site IPSec connections with a need for various NAT combinations due to network complexity. The NAT possibilities of OPNsense are really flexible and can cover all necessary combinations…