the device roles of the user are all except useradmin. No OU roles defined. Devices are in two different OUs.
If i understood your explanation right the user shopuld not be able to configure the vpn if the devices are in two different OUs. So the button should be diabled, but it isn't!
The behavior is correct because it enables to create VPNs between devices of different OUs. Possible use-case would be a Supplier => Manufacturer scenario. The button should be and is currently disabled if you do not have configuration rights at all, whether implicitly via OUs or directly for devices.
I see that in that case you are not able to use the VPN policies though, which is a bug.
the problem can be reproduced when a backup pre 2.050 is installed. The OU of the ipsec policies is not updated correctly when the backup is installed. We will fix the problem for the next release.