If you're using merlin asus and set the openvpn config in policy routing mode there's an option to not allow traffic if the VPN goes down.
I'd use policy routing mode, set the DNS option in the openvpn config to exclusive and not put AirDNS in the WAN settings.