A firewall can easily do that. Just add an outgoing rule imposing that the destination IP for all protocols/ports/whatever is that of the "VPN" server. This way all connection attempts that go directly to the real server instead will fail.
The rudimentary built-in Windows Firewall is perfectly capable of imposing such restriction.