Try testing firmware V3, as I believe that has policy routing.

In V3, “force VPN” is (rather clumsily) enforced automatically (ie. once you have clicked “connect”).