One IP versus several services, how?

But this is just a setting how AGH is going to resolve DNS request towards upstream DNS server. This has nothing to do on how clients will resolve DNS request towards AGH. Just activating DoT inside AGH will not have any effect on how clients are going to resolve their DNS request. And I doubt it will block anything. Blocking is done based on Ad block list you are going to add into AGH.

Yes I know

should be like on attached pictures?

I guess you are trying to block DoT access for your clients right? But I don’t know if this is working like shown on the screen prints as I’m not familiar with your router model. As well, ensure you have activated DoT server inside AGH.