You can just assign those machines the open dns ip addresses the rest could reach another dns server, skipping the policy's. Ok its not the best professional option, but it would still work?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.