What I just figured out:
When I change the VPN policy from “defined by MAC address” to “global proxy” it is also working.
But actually I don’t want to route every traffic via VPN but just defined devices.