Seems like for a lot of popular consumer VPNs, you can't have split tunnel and kill switch at the same time on Linux. For anyone who is interested, I'm sort of able to get this functionality with this command using firejail (for Proton VPN with advanced kill switch on Ubuntu 26):
firejail –noprofile –net=[YOUR_WIFI_ADAPTER] –defaultgw=[YOUR_ROUTER_IP] –dns=9.9.9.9 google-chrome
To fill in the placeholders, anyone can run:
ip route show default
On the line that isn't the VPN, the word after dev is the Wi-Fi adapter (like wlp0s20f3 or wlan0), and the address after via is the router IP (like 192.168.1.1).
A few notes:
Chrome must be fully closed first, or it opens in the existing VPN Chrome.
Some distros disable firejail's networking by default. If it errors with "networking feature is disabled," run:
sudo sed -i 's/^restricted-network yes/restricted-network no/' /etc/firejail/firejail.config
Check it worked by visiting ipleak.net: it should show your real IP, not the VPN's
Is this safe/a legit workaround? I'm a Linux noob so if this is crap/dangerous please let me know how it can be improved.
Source: r/linuxquestions · by /u/Pale-Assistance-8943