But yes, the fact that it's on by default is questionable.
However, most ISP-supplied consumer routers have firewall rules on by default, for very good reasons. Although I personally think this one should be opt-in, on by default is not necessarily evil in this particular use case.
Besides being a bit ham-fisted, there's nothing inherently wrong with an ISP offering filters against malicious content.
Also, with the user-accessible opt-out, it would even be legal under the Netherlands' much praised Net Neutrality law. Unlike most of these alarmist headlines, the ISP is not blocking anything.