points
Use a filtering proxy instead and no gateway / route to the internet.
2) You're advising security through obscurity instead of a network namespace + firewall.
or DNS stubs with filtering capabilities.