My suspicion is that it'd be a bit messy managing the hosts, routes and gateways to effectively have a split bridge at the RED site - but I have no direct experience with such a config. Perhaps someone can share direct experiences with such a configuration.
Otherwise, test and share and/or engage support and share?
I used 172.16.20.200 as IP for the red interface, added a DHCP server with a range from 172.16.20.201 to 172.16.20.210, and used 172.16.20.200 as default gateway and dns-server.
The computer behind the red was able to obtain an ip from the dhcp server (172.16.20.201), but I wasn't able to ping the utm (tried to ping 172.16.20.200) or to ping the client behind the red.
I used 172.16.20.200 as IP for the red interface, added a DHCP server with a range from 172.16.20.201 to 172.16.20.210, and used 172.16.20.200 as default gateway and dns-server.
The computer behind the red was able to obtain an ip from the dhcp server (172.16.20.201), but I wasn't able to ping the utm (tried to ping 172.16.20.200) or to ping the client behind the red.