Maybe headers are parsed but my understanding is that the whole packet is not copied.
It's a NAT router so needs at minimum to masquerade (change the src/dest IP in the packet headers to match the internal / public). I'd also be running fail2ban or crowdsec for the bare intrusion detection.