Vlan pass through in Sophos UTM


I have a customer with a UTM9 9.715-4 firmware and they need to pass vlan traffic thought the UTM from one DMZ interface to internal zone interface.

My idea is to add vlan interface on both physical interface with 802.1q tag and just let it pass the firewall more like a bridge for that vlan or perhaps put that in a separate zone.

Is that doable or am I thinking wrong here?