It seems ISPs are performing Src PAT within the residential internet service provider space. I must have missed this I think. Notwithstanding, it's use I suspect is growing at an alarming rate, and has the potential to extend any associated investigation over an unexpected and extended period.

The symptoms I have observed is firewalls dropping flows with port 'reuse'

There's a few RFCs I see on google, here's one :

