Hello,
I want to give you my experience. I have an alix box with IPFire on it.
I wanted to have wifi from the internet box, so as not to have 5 firewalls / Access Points and routers.
The DHCP server is configured on my Firewall which has the default-gateway itself. Then I added a static route which points to the Swisscom internet-box (same subnet).
The only fault is that the return of traffic does not pass via the firewall but given that the NAT only allows the return of traffic generated by the LAN and authorized by my Firewall, that is enough for my confidence.
To connect from the outside (internet) to my local network, only VPN (OpenVPN) is possible and termination is done on my IPFire where I manage all the rules.
Ultimately, all my devices (on LAN or Wifi) receive an IP from my IPFire, and send the traffic to the Firewall (in my case the IPFire), then my Firewall inspects the requests and sends all the traffic back to the internet box . Then the return traffic is sent directly to the devices from the internet box.
Good day