Hi @J Z
Yes is it possible to have DCs at the end of the VPN link with only a single connection to the main site, without impacting the replication of the other DCs in the forest. If the existing AD site topogoly has a hub and spoke topology, you can create a new AD site for the remove site at the end of the VPN link and then create a AD site link to the main site. This will limit the replication traffic to just these two sites.
Have a read of the following pages for more information on AD replication
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/designing-the-site-topology
I would also specific check the bridging configuration to ensure that the replication is controlled.
Gary.