Hi,
No problem with the diagram, if it can get the info across then its all good 🙂
So you would want to set the untrust ip for the 5gt with the address of 192.168.179.3 and a default route to the NS25 ip of 192.168.179.2.
Change the trust interface on the 5gt to Route mode 'set int trust route' or via the Webui under the interface settings
On the NS 25 you will need to create a route for 10.56.151.0 network via eth2 gate 192.168.179.3.
Create a policy on the NS25 that allows traffic from the metro ethernet network to the internet. If the eth2 is in a custom zone you will need to turn NAT-Src on on the policy, to do this go into the advance section of the policy and select NAT-src with egress ip.
You will need to add routes on each firewall for all the other networks in the metro ethernet network, if you have a lot of networks you might want to look at running something like ospf to learn all the networks dynamically.
Give that a go and see if you have any luck.
Regards
Andy