The behavior I want to setup is: use pi-hole as DNS if available. If Pi-hole server is down, then use 9.9.9.9. What's the proper way to do this?
add-macadd-subnet=32strict-order
That's interesting and thanks for the write-up. But if you use your OPNsense as the central "DNS query dispatcher", why not run AGH on the firewall and have a way simpler setup?