The AdGuardHome isn’t supposed to be called by LAN clients directly (because of non standard DNS port as you’ve mentioned). When activated, it will divert DNS in the BRUME that will forward DNS request to AGH. So the BRUME is / will be your client DNS. And you will have to define what external DNS to use inside AGH options. I recommend using encrypted DNS for more privacy.