Bridging VLANs like that is generally not recommended. How many internal interfaces do you need configured like that? If it's just one you could try breaking the ix2-3 lagg and reconfiguring the switch to connect Eth8 to ix2 directly and bridge that. Removing the VLAN will probably prevent the loss there. Make sure you have some access to the firewall other than via the switched ports if you try that as it's very easy to get locked out! Do you need to filter traffic across the bridge? If not you would be better off using an external switch to set that up.