Old one: https://www.juniper.net/documentation/en_US/junose15.1/topics/concept/nat-traversal-overview.html
IPsec VPN: https://www.juniper.net/documentation/en_US/day-one-books/DO_IPsec_VPNs_2018.pdf
NAT-T for IKE peer: NAT-T is used when there is a network device between the two tunnel end-points that enforce NAT.
all the IPSEC tunnerl to traverse the NATing equipement
ESP over UDP/4500 ???
edit security ike gateway gateway-name
[edit security ike gateway IKE-GW1]
root@srx3200# set no-nat-traversal