hey there.
I am going to talk about the concept. I am not an expert but according to the concept, its fairly easy.
You can use your EFW red interface as a PPoE to dial via your DSL modem / router so the RED interface gets the ip 60.168.200.200.
Assuming you have an ORANGE interface for your other IPs for the DNAT rules. Assign IP addresses such as 192.168.200.1 to 192.168.200.x ( x being the last ip and its for easy reference).
Assign your 60.168.200.20x/29 IPs on RED and proceed to Firewall tab on EFW. Click Port forwarding/Nat on the left side of the interface and add your public IP lets say 60.168.200.201 translation to 192.168.200.1 ( allow port 80 or whatever you want dnatted) . So the same for other public IPs.
In the end, set rules for outgoing traffic on ORANGE interface and the destination zone should be RED.
I hope this clears the concept.
Experts: If i screwed it up then correct me and the original poster
Happy firewalling!