And again there’s no need to be so draconian on something like a ResNet.
Edit: or that security includes availability in addition to confidentiality and integrity
NAT won’t have issues. Bridged will.
Regarding the IP range, on most most hypervisors that’s configurable.
One place where cgn addressing can trip people up is with DNS; lots of DNS servers (especially the flimsy ones used in lab-in-a-box setups) end up filtering host records for those ranges which can screw up SSH by making the reverse lookup fail, for instance.
Edit: from the text of the RFC -
"""Because CGN service requires non-overlapping address space on each side of the home NAT and CGN, entities using Shared Address Space for purposes other than for CGN service, as described in this document, are likely to experience problems implementing or connecting to CGN service at such time as they exhaust their supply of public IPv4 addresses."""