I have OpenVPN with x.509 cert authentication, tunneling ipv4 and ipv6 traffic, and I believe properly starting with systemd...
You know... let me just delete that default ipv6 route until I get firewall settings set up to block services that were never intended to be exposed to the scary Internets. (for example minidlna)