Hi, as stated before.. not a good idea. 🙂
Its like a firewall-on-a-stick setup, and I would guess that you will need to spend some time to get the routing set up and working. But yeah - sure I can't see that it wont work.
I have had setups where you had a main vrf with several 'child' vrf's, connecting the firewall to the main vrf and providing access between the 'childs' on the SG. This can be comapred to what you are asking.
Regaring the question on 'icmp redirects' vs. 'all networks connected to a router' gives me a confused picture on how you are planning to actually set this up.. is there to be several networks/subnets ? If you have ex. 2 client subnets and a subnet where the SG is to be placed, the packet flow will be pretty regular, just entering and leaving on same.
But all in all. not a good idea.