Worth noting that if you’re trying to block telemetery or ads or things like that, using an adblocking dns is probably the better option. Either through a pihole on your network or some online adblocking dns.
Other than that, if you’re looking for one because you think you “need” one, don’t worry too much if it’s just a personal computer connected to a router. Most distros ship with sensible defaults for security.
If you actually want to use a firewall, block all incoming and allow all outgoing is a reasonable rule of thumb if you aren’t running a server. Note that “block incoming” doesn’t block connections that the system itself started.
Honestly, IMO Mint is just Ubuntu without all the scetchy stuff. The only real major difference (besides the packaging debate) is the default graphical shell.
If you like gnome shell, I wonder if it’s worth installing Mint and then
gnome-shell
…