I can only get wireless Internet where I live, and that means CGNAT. I need to run some public services, so I'm running Mikrotik CHR inside a cheap Azure VM. Site-to-site VPN is working great, and all hosts can see each other at home and in the Azure subnet I've set up the public IP in Azure to fwd ...