Enabling Guest Network on AP - or in IPFire?

So I was pondering the effects of this implementation - yes. sorry I do ponder a lot and am sometimes a slow learner. Then again I hardly ever have system crashes or stuff that keeps breaking randomly.

Nothing done yet, only checked that I have the cabling in place so far.

An example: I have some Aqara sensors to measure electricity consumption and temperature. They are connected to an Aqara Hub and that Hub is connected to my WiFi - which is still on the Green network, thus have internet. These are IoT devices and a standing recommendation among a lot of people is to deny them Internet access.

If I put them on Blue and do not add pinhole to that, will I not be able to access them from devices with pinhole?

Another thing.
I run SuperMicro IPMI from my smartphone. I do many things from my smartphone and the Green network. So when I add that to Blue, I assume from the Pinhole guide I will have to open up all relevant protocols via Pinholes, not just TCP but RDP, SSH and some more. OR, I set the phones MAC to access everything?