Thanks for the replies,
From the looks of the settings on the phone, they are pulling ISP DNS settings, unfortunately, I'm not exactly sure how this is getting assigned. The guy prior to me was the one who put this all together. As far as roles and permissions go it's every role that has this issue. Permissions for the group that I'm in are "AllowAll" for the ACL. It's not really restrictive at all because it's the SSID used for IT and our the company directors.
@VFabian
I ran the datapath command on my phone and it appears that it's communicating with google (Andriod phone) and that's it.
74.125.225.135 172.***.***.*** 6 443 54394 0/0 0 0 12 tunnel 19 c1
172.***.***.*** 125.225.135 6 54394 443 0/0 0 0 12 tunnel 19 c1 C
173.194.68.188 172.***.***.*** 6 5228 51798 0/0 0 0 11 tunnel 19 578
172.***.***.*** 173.194.68.188 6 51798 5228 0/0 0 0 12 tunnel 19 578 C
Again this is happening with every phone regardless of what SSID or Role it has. I'm sure this is a firewall issue, but I have no clue where the issue is as the logs are showing no drops what-so-ever.