@alzhao thanks for the reply. All understood but disappointing.

Is my only option then to use DMZ to the main gateway and have double NAT?