First of all, you will probably need two security contexts, one for each uplink. Each context will be mapped to a unique pair of physical interfaces with traffic being bridged between the interfaces. Yo will need to change from /30 to /29 as each context will need on mgmt IP. You can then just redirect traffic to FP with policy map.