Try testing firmware V3, as I believe that has policy routing.
In V3, “force VPN” is (rather clumsily) enforced automatically (ie. once you have clicked “connect”).