

I don’t understand your response. You’re essentially doing the exact same thing I am. Preventing iot devices from accessing wan. The end result in the same, except you’re blocking it from accessing other devices on lan as well. But access to wan is blocked which is the most important. If a device has a security vulnerability then by blocking wan access, you’re blocking an attacker from getting in, unless someone malicious is already on your local network, which in that case you’re fucked anyway. Apologies if i misunderstood your point.
So most alternative router firmware comes with a feature that can be configured to re-route any hard coded DNS through the pihole. I.e., my Smart TV will switch to Google DNS if it can’t connect through your set DNS. The feature I mentioned will force this to always go through your configured DNS. This is completely solves that issue. I’ve thoroughly tested this and it 100% works. Also routers have a feature that can block a device from accessing the WAN at all, and only allow them to access the LAN. This is just a simple toggle in my router and extremely easy to use. I block certain devices that I don’t want to have intentet at all but that I want to access over the network (i.e. plex)
Just to be clear, my goal with my setup is limiting tracking, telemetry, and ads.