It's honestly not that hard. Tell your router to reject new inbound connections from the WAN interface, and you're done.
You have to do the exact same thing to make sure inbound connections aren't possible on v4 (even with NAT in the picture), so you might well have already done this or got it from the default ruleset. Plus it's trivial to test, by attempting to connect from another network.