I have a RV320 router which I block DNS for all except for my ISP's DNS servers on WAN side using a permit for the ISP and a deny for all else for both UDP and TCP. My question is will this stop a client's request to an outside DNS server other than my ISP's DNS? Will it result in a one sided conversation being blocked on the WAN side for the return conversation? Do I have to create a block on the LAN side as well to stop DNS queries going out my network and returning?
Does stateful packet information come into play on these ACLs? UDP is a one sided conversation so it going to be treaded different than TCP in the RV320 router?