Hi,
The egress interface mode plays no role. If the ingress interface is running in the NAT mode, the source-NAT is perfomed or not, depending on the source and destination zones and their mapping to the virtual routers.
As described in KB4761:
Interface based NAT only works From and To the following zones in the Trust-VR:
- Trust zone to Untrust zone
- Trust zone to DMZ Zone
Traffic From and To other zones will be routed.
The behavior for interface NAT with the Untrust-VR is different. If the destination zone is in the Untrust-VR, then NAT will take place from ANY zone.
I recommend to never use interface based NAT.