How to design VPN for 30+ branch offices?

what is on-prem data centers?

Its VPN drops every few hours. why and how to resolve?

How to restrict a Client VPN user to access only one subnet?

When would you choose Direct Connect over VPN?