A self made router with OpenBSD/FreeBSD and iptables is one option. It will require skills to secure a such router tho.
Other options are Tor hardware routers, there are a few models at the market (always better to control your installation your self tho). Or you can download the software and make one your self.
Avoid routers with built VPN-clients, AFAIK non of then have a kill switch and will fallback to clearnet if successfully interrupted.
I think a router that has a unlocked shell to flash custom FW´s on them is a good alternative.
GL-Inet is good, install Luci on it, with that you can edit pretty much everything on the router and clear the ARP Table in general.
Other options are Tor hardware routers, there are a few models at the market (always better to control your installation your self tho). Or you can download the software and make one your self.
Avoid routers with built VPN-clients, AFAIK non of then have a kill switch and will fallback to clearnet if successfully interrupted.