The VPN encrypts traffic, preventing the firewall from seeing the destination.
(e.g., deep packet inspection detects OpenVPN), switch to Shadowsocks or V2Ray – these mimic normal HTTPS traffic.
If you have no other option and accept the risks, here is the safest approach: