Earlier quoted context omitted.
When packets traverse the edge router, IX, cable (landing) station, .. if they're recognised as VPN traffic, then the server's IP (or IP / port) is added to a blacklist, every subsequent packet is dropped. https://en.wikipedia.org/wiki/Deep_packet_inspection
Yup; this is why VPN over HTTPS is a thing.
Sizable communications with an uncommon IP can be singled out by netflow analysis.
But yes, it usually works.