This is working as designed and as it should as far as I can tell. If the firewall rules are for all outbound traffic, your VPN clients are part of that outbound traffic when they route to the internet just like any other client. Maybe you could make another rule that allows everything for the VPN subnet? That way you can still have the firewall protection you intended for the rest of the network.
... View more