DNS based filtering
I use a very old free OpenDNS account where I was able to hold onto multiple networks and different 'rules' for each.
Various VLANs/SSIDs on my home network NATed to different external addresses, thus different filtering rules.
Firewall blocks DNS other than to OpenDNS (except Sky boxes using ISP DNS).
I'm led to believe that Cisco Umbrella/OpenDNS will block known DoH hosts under the Proxy/Anonymiser category and I'm also dropping DoT on my firewall rules.