The main thing to keep in mind is that the palo NGFW is a zone based firewall.
The most important aspect of building a session is determining the source and destination zone.
So, your VR's can be shared or assigned to an individual vsys, but the real barrier is at the zone level: to have vsys talk to eachother, you need to create the external zones and have one vsys allow traffic to the external zone and have the other one allow traffic from the external zone
the 'vsys visibility' setting actually allows a vsys to participate in the twilight zoney/dark matter 'external zone' that lives between the vsys. without this visibility turned on for a vsys, it does not have access to the 'external' zones
... View more