Hi @Metgatz ,
Yes, sir. I understood from the 1st post the issue you were seeing. It is strange. I have not seen it with my customers that run VWire, or with L2 interfaces on my own network.
Maybe it is the VLAN retag. The VLAN is not part of the 6-tuple key that makes up a session. So, a change should not cause a new session for return traffic. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0