This port will be opened automatically when S2S is configured.
If your router does not have an Internet IP, or if you have manually configured other firewall rules, you will need to ensure that this port is open.

No. Only main router need it.

When you select the S2S device on goodcloud, you can see the “Advanced” button at the bottom of the dialog.