NAT configuration - Firewall behind the Peplink B-580

Hi Peplink guys,

The following scenarios are not our cases:

Our case, or quite normal cases in commercial:
A firewall behind the Peplink B-580, and Peplink is configured in NAT-mode; how we treat the network segment between Peplink and Firewall ??

Is it LAN segment of Peplink, and WAN/untrust segment of the Firewall ?

The “Inbound Access Policy” of the Peplink should not be configured anything ( leave it default ) ?

For 1-to-1 NAT in Peplink…but this NAT IP (supposed LAN IP ) is treated in WAN IP of the firewall or only any LAN IP of firewall ?

A bit confused, hope you guy understand my meaning, thx a lot.