Not sure why posted this onto this as surely a different question,
Whilst you can enable Hub Mode and enforce it so that when connected to the Remote Access VPN then forces you to go via the VPN, it won't block access to the Internet when not on the VPN.
Possibly with the Endpoint Suite and the Connected/Disconnected Policy then on the Disconnected Policy then could block access to the Internet and just access to the Gateway, and DNS, DHCP etc. Make sure that HotSpot is enabled so can authenticate as well to Wifi if neccessary.
That way when out of the Office forces the Client to hookup the VPN to get anywhere