Earlier quoted context omitted.
I’m thrilled to have good end-to-end connectivity to the degree I’m willing to configure my firewall for it. When I hear people in other threads talking about the “security advantages” of NAT, I imagine someone filling their car’s engine with walnuts and talking about how it protects them from speeding tickets.
That's the thing, you don't have good end-to-end connectivity if you configure the firewall as you should and block everything similar to what NAT does. After which, you have a question, how can you configure end-to-end connectivity securely?, which host(s) do you open up ports towards?
With CG-NAT my IP address is the same one that infected computers are using, so I'm often treated like a second class citizen on the internet.