Dear Gokul,
Yes, the Src-Nat config still in place. Since the policy is the same as tunnel policy remote site (untrust-bgroup siteA) to server lan (bgroup site B), I've just enable the Src-Nat in the same policy as VPN tunneling.
Does it make sense?
Regards.