How to make NAT best way

In main gateway I do one NAT to networks of SXT(wireless part). In SXT i do second NAT to their lan networks (in many examplex: 192.168.1.0/24).
I am not sure if this is best way in case of security. Was thinking to make tunels over this networks, or some kind of MPLS?

it’s a good idea , using IPSec or other security scenarios is depends on importance of data traveling over your network.