Tech9
Part of the Furniture
I just wanted to tell you ports blocking alone is not a solution. Speaking of Asuswrt-Merlin, better plan of action is multiple barriers: intercept and redirect DNS queries on ports 53, 853 (DNSFilter); block known DoT, VPN and Proxy servers on both IP/DNS (Skynet/Diversion), block common VPN ports (Services Filter), use filtering DNS service with corresponding categories (OpenDNS/NextDNS). Not guaranteed, but will discourage most average users.