With the understanding that this equipment is no longer supported, but also in recognition that you have submitted this question on behalf of a long-standing customer having diligent service contract coverage for more current equipment, I believe it merits an iteration or two in pursuit of an answer.
If you are comfortable with including the elements of your vlan, ciscodp, policy, and cep configs that relate to what you are trying to do here, I can at least see if they include any obvious flaws.
Thank you.