Setting up your Access Point to use IoT devices safely can be challenging. Consider this video to be your ultimate guide. We start off by creating a separate WiFi interface and placing it in a VLAN, and then we adapt the default firewall and limit the bandwidth available to IoT devices. But even if you have a single access point, and you don't need VLANs, you will still find something useful in this video.
00:00 Intro
1:33 2.4Ghz WiFi
3:36 Optional: access-list
4:37 Optional: Datapath for CAPsMAN
5:36 Defconf WAN and LAN
7:00 VLANs
8:35 IP and DHCP interfaces
9:05 Enable mDNS repeater
9:17 IPv4 and IPv6 firewalls
9:59 Exception for mDNS
10:31 ICMP security
11:08 Protect LAN from IoT
11:33 Addional rules for VLANs
12:04 Optional: disable IoT WAN access
12:27 Rate limit with Queue Tree
13:19 Testing the setup
14:43 Thoughts on Home Servers