Once the vpn scope between PAN and the hub site is expanded to allow the ip address range from site A there is no need for NAT.
In addition to the policy check, you can use snoop to verify the return flows.
https://kb.juniper.net/InfoCenter/index?page=content&id=KB5411