What is your build? What does your PS4 report NAT type 2 or? How did you configure it? did you manually configure UPnP or did you just enable it? My PS3 and 360s work with just UPnP enabled I did not manually configure anything.
I allow multicast (224.0.0.0/4 and 240.0.0.0/4) in my LAN firewall rules for LAN-net devices and set my consoles to a specific range of IP's. (I also allow access to UPNP (2189) and PMP ports (5351), via created an Alias for all LAN net, maybe redundant because of defaults created by activating UPNP service? but it doesn't hurt either)All my consoles are ranged within CDIR 192.168.0.80/29.So I create a Hybrid rule.Hybrid Outbound NAT rule generation(Automatic Outbound NAT + rules below)With mappings 192.168.0.80/29 to be static.With the UPNP service I set my consoles to:By default deny access to UPnP & NAT-PMP? active YES !!!! (important!!!)User specified permissions 1: allow 88-65535 192.168.0.80/29 88-65535 (Consoles, DHCP MAC assigned, udp 88 lowest port for xbox/xboxone)User specified permissions 2: allow 1024-65535 192.168.0.0/24 1024-65535 (other PC's and laptops, only 1024 and higher)