Full agree 🦾
If not possible, place a dedicated firewall (OpenWrt or OPNsense) between your network and the ISP router.
I tried both OPNsense and OpenWrt.
The most cost-effective and simplest option for my use case turned out to be a Banana Pi One running OpenWrt — roughly USD 80.
It does exactly what it needs to do:
act as a clear, predictable control point between the internet and my network.
addons:
- dns over tls (f.e. Unbound) / dns over https (simpler with dns mask forwarder, quad9)
- wlan timer
client side:
- https only
- vpn on device needed