I am only allowing the DNS to the opnsense server.
Which brings me back to the question, why can't I disable/delete the auto-generated rules?
block on ingress interface: just block dns-traffic from iot-network to any except "this firewall"