The transport vpn 0 is the one used to facilitate DIA from the service vpn traffic. NAT is enabled on the WAN interface in VPN 0 and under the service VPN, the correct procedure is to create a default route with VPN 0 as the next hop. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/policies/vedge/policies- book/vEdge-as-NAT-device.html#c_Configuring_Local_Internet_Exit_12245.xml