@Mwenya_Chansa Do you mind providing some more information to allow us to help? If my understanding is correct, are you trying to stop LAN clients behind the MX from being able to VPN to external services? If that's correct you could setup appropriate firewall rules to stop these connections. To be able to do this, you would have to find out what VPN connection mechanism they are using and then create a firewall rule blocking these connections outbound. Please refer to this document which outlines some of the common VPN mechanisms and associated port numbers - https://blogs.technet.microsoft.com/rrasblog/2006/06/14/which-ports-to-unblock-for-vpn-traffic-to-pass-through/
... View more