Here are the guides you should follow.
And as @Mcat12 mentioned, FTLDNS with NXDOMAIN blocking will not need the firewall rules.