What i can approve is that you need a static route:
10.201.0.0/255.255.0.0 to the GREEN network 192.168.10.254
That will not work in your setting, ipFire seems to be set to that IP already.
You will need rules for the ports needed by GINA. GREEN to Firewall (GREEN ):
DNS
http
https
3496 TCP (Security Layer)
Just for Information (because card readers and the GINA should be in the same network anyways):
GINA to Card Readers:
9225 TCP (PCSC)
http
https
Card Reader to GINA:
6666 UDP (Multicast Locator Service)
What I don’t understand is, that your card readers are in the BLUE network. Normally they should be in GREEN so the medical software can access them.
I have a similar problem with the static route (simple router works, ipFire blocks) and currently i’m not sure if static routes might be needed on both sides.