Update:
I've been on the stock ASUS FW (3.0.0.4.386_45898-gfa90458) now for the past 4 days, using my ISP's DNS servers, DOT disabled, router acting as local LAN DNS server (no DNS servers specified in the LAN section). Everything working nicely.
I feel like the issue has something to do with...