Enable RFC4193 IPv6 and security

At the moment I only have IPv4 enabled for my clients but I want to enable the RFC4193 IPv6 option.

When I do this all clients get an Global IPv6 address which is fine but what about the security?

Do I need to change i.e. the rules to just let the devices from within my own Zerotier network talk with each other so no external devices can connect to my IPv6 Zerotier addresses?

RFC4193 addresses are not globally routable. They fall within an address range known as Unique Local Addresses (ULA). This is similar to the private IPV4 address ranges like and

