pfSense does NAT by default on any interface that has a gateway specified e.g. WAN or any OPT-Interface that has a gateway (and thus can be used as additional WAN). If you want to shut down this behaviour you can do so by enabling advanced outbound nat at firewall>nat, outbound tab and specify custom mappings.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.