For allowing and blocking stuff (like DNS), firewall rules are the way to go.
Filtering on NAT rules is hardly ever needed.
For allowing and blocking stuff (like DNS), firewall rules are the way to go.
Filtering on NAT rules is hardly ever needed.