Hello.
What do you mean "bandwidth consumed by VPN module"?
If you meant IPSec overhead, then
1) You may try "sh crypto engine accelerator statistic" and check counters before/after encryption.
2) In theory, you may expect the overhead on single packet of about 70-100 bytes (dependent on the encryption algorithm and tunnel mode), you may gather statistics of mean packet size (on the router) and calculate overhead in percentage.