Thanks @apparatus
That guide only explain how to prevent traffic to be forwarded if the VPN is not up, but from within the qube, this is practical when using the VPN provider App because you can’t guess the IP : PORTS for the firewall. The drawback is that the qube itself is able to remove the killswitch if it’s compromised (or if you mess with nftables rules)
The only killswitch that will block the traffic for sure, but requires to know the VPN endpoint IP and port, is this one (it’s a direct link to the killswitch section)