Hi Aghiles,
The initial role is set to something to force captive portal authentication.
Normally all the traffic, including VPN traffic, will be dropped and a user needs to be authenticated before internet access is available.
Please check the ACL’s connected to the initial user role. Can you share the initial role connected to this network?
You can use the command ‘show rights <rolename>’ for this