The first thing I'd try is besteffort in both directions. You have no controlee of what goes in what TIN and this will avoid other traffic having priority over the VPN. You must also consider what traffic is in the VPN as a download could cause the entire VPN to be slowed for other traffic such as net controls. VPN might not be a good fit for cake unless it has it's own cake interface and that's not implemented.
Good luck,
Morris
Second thought, you stated all traffic is tunneled and no split tunneling allowed. QOS on the router can not help you. If you VPN has the feature it might. Talk to your company's help desk.
Good luck,
Morris