1. Are you looking to restrict a single host to VPN only or the entire network? - the answer to this question would determine what rules to use.
Do you establish VPN connectivity via an IP address or a hostname (which must be resolved via DNS)? - the answer to this question would determine if DNS should be included or excluded from the kill switch (if I need DNS working to resolve my VPN hostname I can't include it within the kill switch).