vpn permanent
block connections without VPN
when the vpn drops, security is deactivated (the key is no longer highlighted) and the Internet uses the standard connection.
I solved this problem by adding iptables rules to block Forward (rooted device) and authorize only the tun0 interface, but I wanted to point out this fault.