Is it possible to have the client based DNSBL ACL in Bind where I can choose what to block based on the client? At present in Kids VLAN inappropriate content is blocked. Now I am planning to merge Kids devices to main VLAN so I need client-based filtering.
Thanks in advance.
No, only way would be to force Kids IPs to use bind and rest using a different DNS with other rules
What type of fw rules should I have to force it?
You can run Unbound and bind together and via portfoward redirect parents to Unbound and Kids IPs to bind