As explained in some links shared above, the easiest way is:
- to make a qube dedicated to VPN and check it’s providing network
- enable network-manager service in it
- use the firewall tab to only allow reaching the VPN server
- assign this VPN qube to all the other qubes
that’s 100% GUI configuration and the only traffic allowed from the qubes and the vpn qube is reaching the vpn server on a given port.