I'm using an RT-AC86U with Asuswrt-Merlin version 384.6; I'm experimenting with routing a specific device through the router's VPN connection while all others go to the WAN.
Initially I added a rule for the device's IP address, destination address 0.0.0.0, with iFace set to VPN. With the VPN connected, the device in question then couldn't access web pages.
After tearing my hair out for a bit, I finally figured out why - the router was sending the device's DNS requests to the VPN...
Policy-based routing for VPN - how to handle DNS?
Initially I added a rule for the device's IP address, destination address 0.0.0.0, with iFace set to VPN. With the VPN connected, the device in question then couldn't access web pages.
After tearing my hair out for a bit, I finally figured out why - the router was sending the device's DNS requests to the VPN...
Policy-based routing for VPN - how to handle DNS?