Got it. Thank you. Kudos.
Here's the whole setup in case anyone else is in this position:
DNS DNAT rule for all port 53 traffic on the LANs pointed to the ER, except the pihole IP address. Pihole has reduntant upstream servers for sure, but what it doesnt have is a RTC or power if the connector for the usb power gets moved at all, which is why I was going to keep the dnsmasq and filtering on the ER in addition to the RPi for the time being, with the future being a better solution for the pi as far as power goes. It runs my primary RADIUS server as well, with failover across the network to an always on server also running a RADIUS instance. The ER is running the auto-config blocking service that's posted in this forum. Not sure which one to stick with for the moment