Earlier quoted context omitted.
> Azure's network team decided to unnecessarily use NAT for IPv6, making it exactly (100%!) as complex as IPv4... People like the NAT. It's a feature, not a bug. If your selling point for IPv6 is "no more NAT" then no wonder it never went anywhere! P.S. No, "you're doing it wrong" and "you're not allowed to like the NAT" are not valid responses to user needs.
> "you're not allowed to like the NAT" Well, the bigger question might be why do they like NAT? If it's about having a single /128 address so they can do ACLs then that's easily fixed by just lowering the CIDR number. (unless you have an ancient version of fortigate on prem, which likely doesn't work with ipv6 anyway). If it's about not having things poking at your servers through the NAT then the "NAT" really isn't…
People like NAT because it's an easy batteries-included way to manage, secure and understand your LAN.
Taking it away and forcing them to migrate to an incompatible zoo of firewall technologies for no benefit is asinine.
> They're just sold to consumers as a single package.
Exactly. How in the world is this a bad thing now? Do we really want to make network security for the average do-it-yourself home LAN harder?