I ran into the same issue and found that using private proxies helped a lot with filtering and access control in my setup. This website has some solid proxy options that worked well behind OPNsense and gave me more control over outbound traffic while keeping things stable. Made troubleshooting way easier too.