Thank you for your suggestions.

My idea is to have a dedicated pc to be used as a "tanker"....it will be used to go everywhere, also on probable dubious/ dangerous sites, to run also probable dangerous programs.
With your suggestions I make it more difficult for a program to escape the VM.
This is my first line of defence.
The second is the host, that I would like to have loke a Fort Knox.
I have a back up, the 3rd line of defence but would like to avoid as much as possible risks, even if low, to infect parts than cannot be detected/ deleted (bios, device firmware, router, ...).
I was thinking at using Emsiskft on the host because of its BB, voodoshield as anti exe, an anti exploit (MB, HMP).
Umbra suggested to run the VM with sandboxie paid version.
I used the free one until now to test some safe programs but saw how some managed to escape from it and keep track that they were already installed.
I never used Comodo but saw many members here using it and suggesting it.
What do you think, would it be a good idea to use Comodo firewall on high/max settings on the host with the other programs above (not sure it is compatible with them too)?
Thank you
P.S. If a browser in the VM accesses a bad url, will the AV on the host detect it if the url is in his database or it cannot "see" it as I know it cannot see what is happening inside the VM?