Hi
I have setup in my house, i using capsman and one cap. I have a firewall on router. Am i need firewall on cap for input chain? (ipv4)
Second one, accept RA:yes on ipv6 settings for cap. Am i need firewall ipv6 on cap? Cap have a global ipv6 address. Because cap is my second dns server.
If you trust all the devices in your home network, a firewall on the device connecting the home network to the internet is sufficient. If you don’t trust all of them, and create multiple VLANs/SSIDs so that trusted devices would use one VLAN/SSID and non-trusted ones would use another, it may still be enough to have a firewall on the main router if the cAPs have no IP interfaces in the non-trusted VLANs. I have most of the client devices in “guest” network, so from these devices it is not only impossible to connect to the management interfaces of the Mikrotiks, but they even cannot exchange data with each other, only with servers in the internet.
NB: the proper name of a “public” address in the IPv6 vernacular is “global”.