Ah, that makes sense - also sucks that AT&T doesn't make things easy...
In that case, one change I might make to your design is to move the Dev VMs (the 1.1/24 segment) under the UTM, so pfsense doesn't have to run a mix of static IPs and NAT (assuming you want the dev VMs to access the...