The wide port range I think is Nintendo throwing their hands in the air and not actually knowing what ports third party switch software uses
Most readers of HN will understand (or at least understand the goal of) the checklist for debugging network issues.
Skipping straight to Port Forwarding eliminates any issues on whether UPnP is actually working correctly. Growing up, some of my friends had routers struggled to handle UPnP correctly. If I knew they were the only one needing port forwarding, I'd simply turn that on for them instead of trying to figure out if UPnP was actually working correctly.
more than likely i'd think this is for enabling inbound responses to outbound ephemeral ports given the port range
Unless you're doing something like active FTP where it's replying to a different port than the one the request originated from. Which would be a interesting choice for a console designed in like 2018.
Stateless firewalls, however, need to have explicit rules for UDP traffic. So that’s what Nintendo are addressing here.
Among the 4 first links, 3 explicitly tell me that UPnP is dangerous.
Although I will say that if you are forwarding all ports, at least it’s to a device you know about. Not some random IoT or PC software or whatever opening up ports without your knowledge.
(Oh.... and it resets randomly...)
https://forums.att.com/conversations/att-internet-features/h...
AT&T does a lot to make me angry, but removing uPnP is the right call IMHO.
UDP hole punching via STUN requires continuous work on the part of a malicious app to keep that port open. Work that could be noticed much easier than a rogue UPnP-using bit of malware. And it can't open ports to other devices on your network.