How can I control and enforce VPN connection to be used by the client(s) and even better would be if i can enforce VPN for certain connected devices.

if i allow MOBS1A1 and S2 to use provider DNS's I dont get any internet (if VPN is up) - if I change these to NordVPN DNS's i DO get internet but reporting my local public IP (from the LTE provider)

I do not have failover nor loadbalacing active - and started fresh from RESET'd RUTX12.

