None. There is no way for ConfigMgr or any application for that matter to know that traffic is coming over a VPN explicitly.
The best you can do here is mark the DP as slow for the boundary group and then in the deployments, set the option to not download content from slow locations on the distribution settings tab (I think that's the correct tab for this setting).
Jason | http://blog.configmgrftw.com | @jasonsandys