@chjara NAT is equivalent to SPI firewall, so CGNAT = SPI firewall on the ISP's side; this is how i have ipv6 working equally to ipv4 (cannot open port even though is ip6 native)
it's good cause any attack would be dealt with on the isp's powerful infrastructure and wont clog up your weak little pipe and box (maybe even cost u money if ur metered)