Good firewall practices

Hi everyone and thank you for reading this,

I have two routers in an ISP that I control. The first one is a border router, an CCR1072 and after that one I have a CCR1036+ that handles my pppoe clients.

My doubt is, witch of the routers has to have firewall rules? Both? Are they going to be the same rules (except for some like MSS and such)?

Do you guys have any rules that you consider to be reliable and that you could share with me?

I receive my traffic through BGP session, and I don’t use radius on my pppoe clients.

Any help would be welcome. And before anyone starts saying that I should know that, I’m going to say that I landed on this function by chance, so I’m learning as I go.

Thanks again for the help.

Sometimes you have think want you want to allow and not what want to block. On the second router allow all you need to for your pppoe clients. Set the rest to blocked.