By default EFW won't allow anything coming from RED, unless you create some incoming rule to allow it.
I never did anything like you need, I usually worked by creating a service on WAN, and redirecting a port to some IP:port, but not a LAN to LAN connection. This is intended to work on "controlled" zones: GREEN, ORANGE, BLUE and VPN.
You can try by creating some rules on "Port forwarding / Destination NAT" firewall, maybe using the "Do not NAT" option you can have some sucess on what you need.
On Cisco you probably need to add an static route to reach the LAN behind the Endian Firewall. Always make sure that the traffic goes like you expected (use traceroute a lot).
Try to read the docs fromEndian, to see if any option fits what you need:
http://docs.endian.com/firewall.html