By default, a Palo Alto Networks firewall will not block multicast traffic when configured in VWire Mode. To block multicast packets:
Configure a VWire with multicast firewalling enabled
Configure the ports to use for the VWire and the zones
Configure the policies to allow viewing the VWire traffic and block the unwanted multicast. The block policy needs to be above the allowed policy. The allow policy will allow the administrator to view the multicast traffic.
Connect the prots to the VWire. The port from the switch on one port, connect the port on the Palo Alto Networks to the other side of the VWire
Commit the changes and confirm that multicast is blocked by looking at the traffic logs