So, the /29 is for internal hosts that need to be accessed by the outside world? You can create the /29 subnet on the LAN side of the MX. Then create 1 to 1 NAT rules using the same real IP in both the Public and LAN IP spots. Screenshot examples below. And apologies if I misinterpreted your goal.
Or if the inside hosts will have private IPs then just adjust from the screenshot below to have the real/Public IP map to the corresponding private IP.