Hello Michael,
thanks for your reply. Sorry for the confusion.
The current behaviour is unintentional in my point of view: If default policy is set to DROP, connections from GREEN and BLUE to RED are forbidden by default, but not from ORANGE to RED. As far as I know, this is not even documented.
Thereof, I suggest to change behaviour to DROP, too.
@All: Opinions?
Thanks, and best regards, Peter Müller