Just to say, for anyone else who wants to know, that I think I solved this myself!
1. In routes, add the IPs that you want to be routed through the VPN.
2. In DNS, switch to "Disabled" but also add your DNS servers.
3. In Networking, untick "Remove the gateway route" and set "Layer IPv4" to "Outside Tunnel". (You can do the same for IPv6 if required. Untick "Switch to 'Block' if issue is detected.)
4. Under Network Lock select Mode: None; Incoming: Allow; Outgoing: Allow.
This then seemed to work for me.