Just ran in to this in 20.1.3.
Testing with two OpenVPN instances. One for RDP only, other is 'full access'.
Connecting to RDP instance everything works as expected. I can only ping, DNS lookup, and RDP per my rules.
Connecting to Full instance, I can do everything, but only via IP, no DNS lookups. nslookup gets request denied. I had to restart the Unbound service before it recognized there was another OpenVPN instance, even though Unbound was set to listen to all interfaces. I did not have to do this when I made the first OpenVPN server.
Hope this helps someone that might be head scratching. Bug report maybe?