I might be wrong, but in the case of Mirai I'm fairly sure you're safe if all your devices are behind NAT.
https://krebsonsecurity.com/2016/10/who-makes-the-iot-things...
Edit: I guess it's more accurate to say that a lot of poorly designed devices use UPnP IGD to work around NATs/firewalls and Mirai takes advantage of this to infect them.