怎么解决防火墙IPSec与nat冲突问题

IPSec VPN正常配置nat用以下命令,配置在防火墙上如图,请问怎样解冲突?

nat address-group group1 0
 mode no-pat local
 section 0 56.59.34.4 56.59.34.9

nat-policy
 rule name 1
  source-zone trust
  destination-zone untrust
  source-address 192.168.0.0 mask 255.255.0.0
  destination-address 172.16.1.0 mask 255.255.255.0
  action no-nat
 rule name 2
  action source-nat address-group group1

nat address-group group1 0
 mode no-pat local
 section 0 56.59.34.4 56.59.34.9