I have the D2 router as well as the AX1800. I have 500 mbps fiber as well. I get around 200-250mbps wired with access control on the D2. It’s worth the drop in speed for the features you get. You will never notice this drop in download speed browsing the internet or streaming content. 200-250 mbps is more than enough to power a home. My D2 runs about 25 devices smoothly. Never had a problem. Now you can leave access control off and setup DOH to get most of the features through NEXTDNS that you would with access control. But then you have to do everything through NEXTDNS. There is no drop in speed if you go the DOH route. It is true that DOH can hide your DNS requests from your ISP. But then NEXTDNS gets your DNS requests. I prefer to just keep everything on the router.
Also, the D2 can do about 150-200mpbs through wireguard with access control on for all devices except the device that is routed through the vpn. Not much point in having all the boxes checked if your using a vpn.
I would just roll with the D2 if your on a budget as long as your ok with a speed drop when using access control. It’s a capable router.
My AX1800 has no drop in speed with access control enabled.