Also, please do not use /57 as LAN networks, you must (almost) always use /64 for IPv6 networks.
Place hosts that share an outbound policy in a common network/VLAN and ignore host addresses. Filtering by address does not scale and is easily spoofed.