> Is it even possible to reliably know that a connection is from a VPN?
No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.
Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.
If you tried to identify it, you would block every real connection.
I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.