While testing out an AdGuard Home instance on a Docker container, it failed to reach upstream TLS servers.
Upon closer inspection, I traced the packets back to the AX86U router IPTables.
There is a chain called "DNSFILTER_DOT" that is blocking any packet on port 853 that is not destined for...