In manual for Firewall nat it is written: "If you want to "hide" the private LAN 192.168.0.0/24 "behind" one address 10.5.8.109 given to you by the ISP, you should use the source network address translation (masquerading)"
But if you put some computer or router on same network as wan port is and you set that gateway for private LAN is WAN port of our router you can access private LAN.
So basically your private network can be accessed form neighboring device (it could be ISPs gateway - why should I trust them?).
Basic routing is still working.
Maybe some filter rules could be set so private LAN is really hidden, it can access internet and if I like I could set DSTNAT.