maybe the config of the right utm is wrong.
default route should go to internet and dmz-network goes to vpn.
looks like you send "any" or client-Network to VPN/DMZ , also possible default-gateway from the right utm is wrong