Blocking GREEN network for vpn client

i’m wondering about the fact, that my vpn client can connect to the green network, so it can access the firewall itself on GREEN. Even if i make the rule and block the vpn client to GREEN, just allowing RED, it can connect to GREEN.

The log of the firewall shows me INPUTFW from the 10.x.x.x (vpn client) to the 192.x.x.x (green ip of the firewall). What is this INPUTFW? It seems to be over all the rules.