With my limited understanding, I don't really follow how ISP CGNAT would affect why opnsense would accept connections to WAN net. My only guess at this stage is that all traffic is routed to the default gateway in order to reach an address to the internet.
For example;
Unless I put a packet sniffer on the interface or I wade through the logs, I guess I am just guessing! :D
But while I am interested, I am not all that interested to find out just yet. Still got lots of other interesting bits to learn here. Going to go with your experience and change it to "any" later.
			For example;
- Vault LAN device has IP 10.10.10.10, receives packet for internet bound, routes to its default gateway 10.10.10.1.
- LAN interface 10.10.10.1 (FW). FW rules says auto NAT then route to WAN interface (internet bound traffic).
- WAN interface (ISP DHCP assigned) 123.123.123.123 receives packet and says send it to my default gateway which is 123.123.123.1.
- From there, its out of the vault doors to its destination.
Unless I put a packet sniffer on the interface or I wade through the logs, I guess I am just guessing! :D
But while I am interested, I am not all that interested to find out just yet. Still got lots of other interesting bits to learn here. Going to go with your experience and change it to "any" later.
 "
"