You don't need a system access rule for this. A system access rule will make the RED interface listen for the connection which is what happens when you enable the OpenVPN service on the firewall itself anyway.
A of questions:
1. Are you trying to use an OpenVPN server other than the firewall itself?
2. If so, what is the IP address of the OpenVPN server on the GREEN zone?
Just to make sure, if your GREEN interface IP address is the 192.168.1.1 you posted, then your rule should point to the IP of the "real" OpenVPN server provided the answer to question #1 is "yes".