If NAT is security, double NAT must be double security! 
@catsalad that's why i have triple NAT ​​

CG-NAT
NAT in the shitty ISP modem/router
NAT in my own router

no way to open up ports anyway on this ISP anyway so i'm not really losing anything
@jiub @catsalad That's what VPS+VPN is for ... To circumvent lousy ISP limitations.
@dazo @catsalad indeed, i forward my server's ssh port to a vps using autossh so i can easily log in remotely and access everything on the lan from there

i don't mind accessing things in an ad hoc manner so i haven't bothered with a full vpn yet