It's also completely naive that source routing is your only threat. One can break into a NAT. One can forge packets and address them appropriately. Firewalls prevent this, not NATs.