portforward bypasses dnsmasq, the other solution disables dnsmasq. if the dns query schema does not include dnsmasq, then the vpn policies will not work