We are using the vrf nat where the customer demands the firewall services.
For implementing this we are advertising a default route and vrf nat is used
per VPN basics.This is the rate services in case of whole sale.
Actual implementation; we are creating a INTERNET VRF which is having a
default route; In customer vrf the RT of internet route is imported and vrf
is able to get the default route. For reverse traffic a ipv4 route is added
at the PE towards customer interface.