I only want to have NAT at the vApp
The org edge gateway should not provide any NATing. I will set static routes in the core routers pointing to this edge gateway for the assigned subnet.
I could just aswell add a direct connection to the org, but i would like to have an edge gateway to provide firewalling there.