Banjaie: Banjaie: Which, 1 or 2, would you say is more leak/bleed proof, If I truly needed that level of certainty, I’d go with a harder to screw up / more certain, but much less convenient approach (use separate virtual-machines, with firewall’s configured to block all traffic other than to the specific VPN server I want that specific VM to connect to, and then use that VM to connect to just the single site or service you want to isolate). There are both more extreme and less extreme ways to compartmentalize depending on your goals.