Outbound NAT / Relayed concerns

I have several remote networks that talk to each other via netbird (hosted).

The biggest problem we’re running into is that most of the servers are using Relayed instead of P2P.

Upon researching it more, it seems it’s due to NAT randomizing the outbound port.

We use opnsense firewalls at most of our sites.

Coming across docs.netbird.io/get-started/install/opnsense, docs suggest creating a manual outbound NAT entry to force the port, but that doesn’t work when there’s 50+ devices at each site.

I could set a range and force each client to use a different port, but that’s a lot of upkeep.

Am I missing something here? Is there a better way to do this to prevent all traffic being sent to our relay servers.

Hi, you could just create an alias with all the devices and use it in the outbound NAT as a source, and tick the static port checkbox in the rule. No need to specify ports or create one rule per device. That’s how I did it on my pfSense.

Hi,
same problems on site-to-site with opnsense. Can you give us some examples?
best regards