By the way, I wasn't completely explicit. I supposed that in both cases all incoming ports are closed, except for the ones you explicitly open. That way, the only difference between the NAT and the firewall is the address translation.
My scenario is narrow, but I expect it to be a common one: IPv6 internet boxes will likely include such a firewall by default.