how is it a different mental model? instead of opening the port in NAT via forward feature, you open the port in the firewall. it is in fact significantly simpler while overall being the same actions you take when you want to "forward"
perhaps you could explain how its such a new paradigm and mental model that it simply confuses people? because I dont buy it, its without exaggerating a smaller difference in so far as this goes, than when people get a new microwave oven, and substantially less difference than when people switch phone brands.