The firewall lives under Advanced → Firewall and is genuinely powerful (InControl adds even more, including database-backed capabilities).

Rules are grouped: Outbound (LAN or VPN user network out to WAN), Inbound (WAN in to LAN), and Internal (between LAN networks/VLANs). On an outbound rule the source can be an IP address, IP network, MAC address, or client type; the destination adds domain name, plus grouped networks and access control lists if you have created them. Intrusion detection / DoS prevention is a simple on/off toggle.
Local service rules

Local service rules govern the services used by the router itself — SpeedFusion, DNS, SNMP, FusionHub, web-admin access. This lets you run a strict deny-all-in / deny-all-out posture and still explicitly permit the SpeedFusion tunnel in, so a bonded connection keeps working on top of a locked-down firewall.
Content & application blocking

Content blocking can block adware and malware, block specific applications, and take custom domains you add. You can auto-update the blocking database from InControl, exempt individual domains, and exempt whole user groups — for instance, block everything in the world but exempt the IoT group.