find the following line
proxyip = <insert your green interface ip here>
In forgetting to update this line after cloning the VM, the firewall was actually forwarding on requests to the original firewall. This was despite me updating the green and red ips and updating all instances of the IP change in the web-gui.
I only noticed this problem after trying to configure OpenDNS to provide an additional layer of filtering on the cloned Firewall. Upon trying to verify the IP, OpenDNS was reporting the wrong external IP...doh!