Hi,
You could implement it through an always running script that would check if it pings through the OpenVPN tunnel to the end device.
This way after it meets one or another condition it can initiate a command to shut the firewall rule or just shut the mobile/WAN connection.
As we're not writing scripts for our customers - you will have to do it yourself.
Hope this helps.
EB.