Drop the default clients-tcp configuration
There seems to be little point in having this. TCP is not recommended for VPN's. It complicates the programming and is not supported by the .ovpn profile download. It means the app only needs to support a single configuration file rather than do everything twice.
If you just delete the clients-tcp.conf file then the Webconfig does not work correctly so this needs to be removed carefully.
The firewall widget would not need to check for tcp:1194 and the OpenVPN_TCP standard service can be removed from /usr/clearos/apps/firewall/deploy/ports.php