Firewall rules for the second router needed or not?

Hi All

I have 3 routers:

Primary Rs4011, 2nd is Audience (used as an access point only) and the Ltap for 4g connection


Primary has my main wan link terminated
Audience is connected to the primary via a trunk port with 2 vlans: main and guest and then those vlans are assigned to ssid and the 3rd router works like pass through lte modem and provides a back wan circuit via 4g to fail-over in case the primary goes down

My question is do I need any default firewall rules on the second router (Mikrotik Audience ) I enabled one to test “block all not coming from Lan” and it’s counting (on the screenshot i just reset the counters)

Do I need any rules on the Audience or the rules on the primary router Rs4011 are enough?
primary.png

Thank you
Alex
audience.png

I dont read diagrams of configs, hurts my eyes, but I will read a config.
In general only the RB4011 needs firewall rules. In some cases on an AP there may be a need for further access list or other measures taken.
However that depends on the requirements which were not provided.