If you are receiving that message, the firewall believes based on the src/dst IP addresses of the packet that it should have been sent encrypted from a VPN peer but it wasn't. You will need to adjust your VPN domains such that the firewall does not believe that traffic should have arrived in a VPN tunnel. The inspection of the packet and determination whether it should have been encrypted happens before the packet is passed to the Gaia OS between inspection points i-I, so it can't even reach the GRE handling in the Gaia OS.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com