We have a 1710 router that exists behind NAT. We don't want this router to perform NAT at all (our edge router performs NAT for us). We also have an EZVPN originating from this router to a remote router on the internet. Whenever the EZVPN renegotiates its SA, NAT gets enabled on the client router and we have to manually enter the commands:
interface ethernet 0
no ip nat outside
interface fastethernet 0
no ip nat inside
clear ip nat translations forced
To clear all the translations. This lasts until the next time the VPN reconnects or the SA gets renegotiated.
The EZVPN is in 'network extension' mode.