My two cents.
-
It Is not a good idea to mix production and lab on a same device.
If you don't have a second suitable device, 95-99% (excluded wifi) of configurations can be emulated/simulated with CHR in GNS3. This allows you a lot more possibilities without risking to bring down the real network. -
Touching the default firewall should be the last thing you do, only once you
have become very familiar with the matter.
Unlike other settings that - if wrong - usually have direct, noticeable effects, a mis-configuration of the firewall (drilling accidentally a hole in It) may become evident only when It Is too late.
See Rule #8:
The twelve Rules of Mikrotik Club