This is a known limitation of PaloAlto firewalls. If you do inter-vsys routing then everything is done in software. The only way to get the full performance of the box is if you "think outside of the box": the traffic needs to go out of the firewall and come back over a switch/router to another interface of the next vsys.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!