Why not have your publicly accessible services registered in DynDNS by their current GUA from the systems running these services themselves?I find proxying/reverse NAT for IPv6 rather fruitless. Getting rid of all that stuff is one of the points of IPv6. You can still have e.g. a crowdsec log collector on each and a central bouncer on the firewall.