I came into this article with a closed mind thinking it was going to be a bunch of platitudes. It's pretty legit advice and tracks.
30 karma · joined March 19, 2024
You can scope it to just your IPsec service, or whatever it is your hosting, or you can enable full cone for the whole subnet.
It is not DNAT, nor is it port forwarding. If you host a SIP proxy, SBC or peer to peer gaming, it will enable these use cases as well.
https://docs.netgate.com/pfsense/en/latest/nat/outbound.html
It started in 7.3 with the frame buffer changes and the only workaround was to disable the kernel driver.
Maybe more people will get to try out OpenBSD successfully now.