Connecting to the VPN server with enabled redirect-gateway changes the default route on the client.
When providing virtual networking with NAT, the guest's upstream is routed over the host.
This can result in a deadlock when the VPN server runs on a VM hosted by the VPN client.
You can use the virtual networking method that does not depend on the host's default route.
Otherwise, set up another VM to serve the VPN client role, or disable redirect-gateway.