The cisco guide for Cloud OnRamp SaaS requires that NAT to be enabled for VPN 0 and a default route that directs traffic out to the internet (This requirement is necessary for the interface to be a candidate for local exit, regardless of any other NAT configured for the site). https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/SDWAN/CVD-SD-WAN-Cloud- onRamp-for-SaaS-Deployment-Guide-2018JUL.pdf