WSA is always supporting multiple LDAP Realms and it starts supporting Multi-Forest NTLM since version 7.7.
Here is the quote from release notes.
Configure the Web Security Appliance to authenticate users from Multiple untrusted NTLM realms. Sometimes creating trust relationships between distinct NTLM realms is not practical. You can now support these configurations using the same WSA without expending the cost and effort associated with enabling NTLM trust.
Authenticate users from multiple NTLM realms if those realms posses a trust relationship. Create multiple identity policies using these untrusted NTLM realms and then configure user and group policies associated with these identities. See Authenticating Users Against Multiple Active Directory Domains in the user guide or online help.