This view always seems to get crucified in these discussions. While it is certainly true that a NAT is neither necessary nor sufficient for the kind of protection provided by a properly configured firewall, it's way better than the realistic alternative in 90+% of the cases: "Literally nothing". Just think how many actual businesses got nailed by e.g. Mongo's former default of listening on all interfaces.