Hi,
You can simply add e0/6 to bgroup0. Then, any traffic hitting 0/6 with tag=20 will be considered as a part of bgroup0.
But, I see that 0/6 is connected to a dumb switch, so traffic reaching e0/6 will not have any VLAN tag, am I right?
If that is the case, that won't work. The firewall needs incoming traffic to come with a TAG, to identify it as belonging to a sub-interface domain (say e0/6.20 or bg0.20). If there is no tag, then it will be considered to be traffic for the physical interface (e0/6) and dropped.