You should still be blocking incoming requests for IPv6 endpoints and only open ports you intend to serve publicly.
You should still be blocking incoming requests for IPv6 endpoints and only open ports you intend to serve publicly.
100% of consumer IPv6-capible routers block unsolicited inbound IPv6 by default. It's not something you need to worry about unless you are hosting, and in that case your concerns are the same as if you're using IPv4.
NAT wasn't meant to be a security mechanism and because of that, the practical designs found in most devices don't treat it as such.
On IPv4, NAT and firewalls are usually one and the same rule set. That rule set is slightly smaller with IPv6 because of the lack of NAT, but the mechanisms are still the same. If your IPv4 firewall fails, NAT won't save you, because that's part of the system that failed.
If you're still insistent on using NAT then... use NAT. The core technique works on both protocols, you'll just have to set it up yourself because router vendors don't usually implement it.