When you logon with the administrator credentials, you may be being ignored by the UserID agent (check your configs, as admin users are often part of the ignore list). So, when you log on with administrator credentials, the firewall may not have a mapping for you, (as administrator) and so the CP page is exhibited. The reason folks put the administrator account in the Ignore List is to not create a mapping for that account as many services log in with that account (in the background) and can potentially overwrite the actual user to IP mapping for a user who may be at that IP address. If that is the case, that your administrator user is in the ignore list, the CP page is to be expected but only for web browsing and https:// To not see this page, consider creating a CP policy such that it excludes your DCs so that your policy will read "no captive portal" for the set of IP addresses that are Domain Controllers - where you log on with your administrator account.
... View more