With even just IPv4 you can have multiple IP addresses assigned to one NIC, the one used will be determined based on your destination. This is a part of the protocol, having a local address and a global address was expected from the very begining with IPv4 (well more like having multiple IP addresses was expected), NAT was made as a bandaid to fix the fact that there weren't enough addresses to support this. Pretty much any VM you make in the cloud will actually follow this traditional model by default with each VM having it's own local and global IPv4 addresses at the same time. It's nothing special, you can expect
every NIC to support this, this is basic stuff, you can expect it to work on everything every time.
Fundamentally all NAT does is simulate this kind of traditional network. It's an attempt to replicate this behavior by having all hosts "share" a global IP address that the router would then dynamically redirect back and forth based on which local host initiated the connection.
However the packets must physically pass through your firewall to get into your network. The IP addresses are simply an identifier to put onto the envelope, a firewall does not give a fuck about what the envelope says if a remote host attempts to initiate an inbound connection and this is forbidden (which it always is by default). Before a packet from the Internet even gets an opportunity to even get to the NAT part it is trashed. The firewall is the security guard at the door checking your badge, after that you go to the reception who "routes" you to the correct host. If an address isn't routable, which may be the case in a NAT network, then it's no big deal since you can just threaten the receptionist to tell you where to go
All NAT routers with Internet access will have both a local address and a global address natively, that's how it is even capable of sharing it's Global addresses in the first place, the firewall is what protects it, not NAT. If something can magically get past your firewall then that implies they have full control of your router now and can route packets wherever they like, remember this is hypothetical because breaking past a firewall is already a complete system failure, the boat has already sunk. At the end of the day it's all the same firmware, why would you trust the NAT part more than the Firewall part? It's literally just semantics.
> This is a lot more to expect from a host than with IPv4 NAT, where Host A just uses its local address, and the router transparently handles the differences between local and global connections.
I'm reiterating here but everything I've described so far is in relation to IPv4, all IPv6 introduces to the equation is: more addresses so you don't need NAT, a clever way to do dhcp on a local host without router intervention: SLAAC (routers can still advertise what to use as prefixes to these addresses). It also fuses together some of IPv4's extensions into one cohesive protocol that's simpler to understand. It's not nearly as radical as you may believe, it simply brings things back to how they were when IPv4 addresses were abundant and simplifies your firewall since you can easily configure which traffic can go to which host without involving weird port forwarding shenanigans.
Attachment to NAT for security is fundamentally a misunderstanding of what role it is serving, an assumption that it has more responsibilities than it actually does. It is not DHCP, it is not a Firewall. If you want to expose a local host to the Internet with NAT you configure the firewall to "forward the port" so inbound connections get redirected to your designated local host. If you want to expose a NAT-less local host to the Internet, you go to the firewall configure it to allow inbound connections with destinations set to your local host's global IP address and it's port.
FYI if you want you can have a static global address only used for inbound connections in addition to randomized globals for outbound connections. Though generally if you are setting up a server anonymous outbound connections are kinda pointless imo.