Endpoint dvices should not be direct peering (security). Always go through either a passthrough inspection device or router.
And then we are back to NAT...