Openvpn kill-switch

i installed openvpn, now i want kill-switch, i mean if vpn disconnected, network disable as well
what should i do?
below is my firewall setting:


If you remove the lan->wan forwarding, then the only way lan can reach the Internet is via VPN. So that's an inherent kill switch. If VPN is down the lan users won't see the regular Internet in any case.

so below is fine and kill-switch is workable?

I don't know what openfw is. If you only had three zones: lan, wan, and vpn, that is the correct setup.

You could of course test it by intentionally breaking the OpenVPN config and confirming that lan can't reach the Internet without VPN.