You will need to move the interface eth0/3 into a separate virtual router with its own default route.
By default all the interfaces are in the same virtual router and share the same routing table. If you move this interface to a new VR then it can connection using its own default route.
Create a new zone and assign this to a different VR than your existing untrust zone
On the eth0/3 move this to the new zone
Create any necessary policies for the new zone traffic