Good morning, We just got a Palo Alto Firewall for a small testing lab with several virtual servers and clients. The firewall will be then connected between the lab and our ISP gateway. Most of the network traffic will be internal, since the clients will be connecting to the servers with a switch, and the switch will then be connected to the FW. However, we will have a few clients (3 or 4) that will connect directly to the FW, so for the servers will appear they are connecting from outside. Besides the application testing inside the network lab, the most important will be allowing all these clients to get updates from the internet. We don’t have much experience configurating the palo alto FW, but we would like to make sure nothing nasty is coming from outside. Could you please give us some advice about what design could be better for it (Virtual Wire, L3, L2, etc)? Thanks in advance,