Cough cough - time to pitch in an update to the VPN kill-switch, to be moved to the VPN director tab:
Link
Key observation:
In particular, if I have 
Redirect Internet traffic through tunnel set to 
VPN Director, then both 
DNS Configuration and 
Killswitch have to move VPN Director level as well, under device specific rules. As long as a VPN client establishes a connection, the job in that section is done. VPN client cannot have a kill switch - since it's not linked yet to any particular devices. At this point of "VPN client" we have a VPN going between Asus router and some remote VPN server. There is nothing to kill yet.
VPN director role is then to tell a client to use a particular VPN interface, and then this very section could have buttons to set kill-switch for that device if the interface is not available, and to force DNS to be exclusive too.