I would suggest setting up a Pi-Hole together with an Unbound Reverse DNS Resolver, too. By now i’d also go as far as not having the Router being the DHCP-Server, but having Pi-Hole handle that part (the user-interface is very comfortable and you’ll get some advantages by having the Pi-Hole deal with that stuff.)
If interested, i can dig out my notes and provide a step-by-step guide how to get it all going including save forwarders for Unbound.
The computer serving as Pi-Hole - just a Pi if you’ve got one at hand - can also act as openVPN-Server.
just realized it’s an old thread. Nevertheless i’d go this way. (i’ve got a Pi behind a DrayTek Vigor beside the mentioned router)