When on the UI, we select one network zone, all traffic is being scanned on that zone. That means creating a scenario where RED and ORANGE is scanned, but RED and GREEN is not is unintuitive because only ORANGE needs to be checked. This is an OR connection. An AND connection would be better so that traffic between two zones is only scanned when BOTH are checked. I would expect that.
Patchset has been sent to the development mailing list. https://patchwork.ipfire.org/patch/2213/ https://patchwork.ipfire.org/patch/2214/ https://patchwork.ipfire.org/patch/2215/