Hi,
You can't do NAP with VPN enforcement using ISA for the VPN server because VPN enforcement currently requires you use a Server 2008 computer running RRAS. However, you can do IPsec enforcement on users that access the network over any type of VPN (or other) connection.
Have a look at the
NAP with IPsec enforcement step by step guide for details about how to configure this method. It is similar to DHCP except that instead of a DHCP server you use a Health Registration Authority (HRA) as the "NAP enforcement server." You will also need a NAP Certification Authority (CA).
With the IPsec enforcement method, you also have the option of using the "no enforcement method" where you deploy all the components except IPsec policies. This can be a good way to get started with the IPsec enforcement method.
Let me know if you have further questions,
-Greg