If you used a true Load Balancer, you could scope the remote IPs on the Front End connector to the Load Balancer IPs and that would force end users to send through the Load Balancer and not directly to Exchange.
If you were to set the remote IPs to just the Email gateway, then it would block ALL sending internally except for those allowed on the "relay connector".
This could potentially work for you, but prevent any email submissions directly to the Exchange Servers other than what you allowed. Give it a try and test.