Cisco IPSec, NAT, Port Forwarding Issue

I have an issue on a Cisco router using IOS 12.4(20)T3 where I already have one port forward that
works which uses a route-map to avoid dramas with the remote subnet begin subjected to the
static port forward locally
.

Traffic destined for the VPN tunnel cannot be natted. It needs to travel through the vpn tunnel
untranslated. A special nat configuration must be used to prevent vpn “interesting” traffic from being
translated while still translating normal internet bound traffic.

!

This is the working configuration :

ip nat inside source static tcp 192.168.100.2 80 210.xxxx 80 route-map No-Eden-NAT extendable
ip nat inside source static tcp 192.168.100.2 443 210.xxxx 443 route-map No-Eden-NAT extendable
ip nat inside source static tcp 192.168.100.2 3389 210.xxxx 3389 route-map No-Eden-NAT extendable

And below is listed the route-maps :

route-map No-Eden-NAT permit 10
match ip address 120

!

access-list 120 remark “Deny Eden subnet being routed in via port forward”
access-list 120 deny   ip host 192.168.100.2 192.168.101.0 0.0.0.255

##############################################

Here is the short list of commands :

ip access-list extended NAT
deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
permit ip 192.168.1.0 0.0.0.255 any
!
route-map POLICY-NAT 10
match ip address NAT
!
ip nat source route-map POLICY-NAT interface s0/0 overload
ip nat inside source static tcp 192.168.1.10 25 12.34.56.2 25 route-map POLICY-NAT extendable

##############################################

Same route-map POLICY-NAT can be used to accomplish the same task.
This will deny local lan traffic from being NaTTed across IPSEC VPN and cross the
VPN Tunnel untranslated and at the same time allow local break-out to the internet.