I've managed to do it for now by creating an IP on that VLAN, that the Ubuntu box can use as a default gateway, then setting an Access Control List for the VLAN
acl number 3002 name VLAN208_Restrictions
 rule 0 permit ip source 0
 rule 10 deny ip source
int vlan 208
 ip address
 packet-filter 3002 outbound
 packet-filter 3002 inbound
Which seems to be working in that it only allows traffic out of the VLAN from the Ubuntu box's IP, and any other device has its inward and outward traffic blocked. I'd still prefer to have the Smoothwall as the only route out if possible - less points to be breached - but at least I'm at a working solution for now.