Let's say I want to block certain Chinese tablets from phoning home, what are my options?

TL;DR Want to identify and block suspicious connections on Android tablets, OR ensure that I can use synced note-taking apps (e.g. obsidian) and cloud file apps (e.g. Dropbox) containing sensitive info safely on those tablets

I have a number of Android devices with various functions. Several are from Boox, which is a manufacturer that is notorious for phoning home. On one device, I was able to remove the offending packages with uad-ng-linux and install AFWall+, but this may be more complicated on the more recent ones.

I do not wish to block Chinese connections altogether (AFAIK blocking a country is not a thing anyway) and have no xenophobic intent here, in fact I browse Chinese websites regularly on my main device as I am learning Mandarin. It's just these specific manufacturers that I don't trust, and I don't have a choice to pick them because their devices have specific features I need. Of course, Google is even less trustworthy than any manufacturer, but I'm tackling these issues one step at a time.

What would be the most effective and least heavy handed way of making sure that those devices can be used normally with a few select Android apps but that they otherwise cannot contact Chinese servers or at least their manufacturer's servers? Am I barking up the wrong tree here?

In case, you have the IPs of the servers to block, its a piece of cake.

...or the hostname of the phone home server.

Rethink (on Android) could make it much easier than Afwall+ to look at what is calling, where and when (and block it when uninstalling is impossible).
https://f-droid.org/en/packages/com.celzero.bravedns/

Wow this app wonderful thank you!

So let's say I spend some time monitoring and get a list of addresses, what is the correct way to block them? I am currently looking up how firewall settings work and happy to do my homework but I don't feel very confident with messing with the settings for the time being...

I see that rethink has a lot of great lists to block harmful websites, can these lists be installed on the router directly somehow?

Banip package?

You don’t have to enable everything at once. Look at the Logs then go the the Apps and enjoy blocking them. It’s faster than to “recompile” rules on AFwall+.

I don’t know but that would probably defeat the purpose of a spyphone that shouldn't always be connected to your router (in WiFi). What I know is that these lists can be installed on your spyphones / spytablets (Chinese or otherwise).

Back in the good old days, I was able to root most of my spyphones and use AFWall+. But it became more and more difficult and I lost interest in this. I realized with my last tablet that it was almost impossible to remove all the crapware that google allow in it even with programs like ADBAppControl. Then I replaced AFWall+ with Rethink, even in my old rooted spyphones. Every good thing has an end and they’re driving us as fast as they can in the wall.

There is some light in the darkness (Graphene moving towards being independent of Pixel line) but I agree it's pretty grim in general