This should work, but you may not acces your fire via green network and need to use red port acces to connect via ssh or anything else
red may work when nat is used too only pings don´t get reply´s
it may be beeter to use 2 bridged interfaces in order to run ipfire because everything should go from bridge1 -> green -> red -> bridge0