Although with DoH these days, I'm not confident my firewall rule is still doing a good job :(
At this point every device on my network is hostile, default deny outbound is starting to feel like the reasonable starting point.
I don't want to add an extra router because that would add unnecessary latency. The above is not an unusual setup at all.
Although with DoH these days, I'm not confident my firewall rule is still doing a good job :(