Is it possible to block-non vpn traffic on specific device (MAC address)

I’ve been testing leaks these days. But I failed to reproduce the issue.
Can you help to export debug info?