You are correct that you cannot use untagged frames for all the sub-interfaces. The point of the sub-interface is to connect multiple separate vlans on a single physical port. To do this we need to tag the frames with the vlan number and of course the switch (which you apparently don't control) would also need to have those vlans setup and tagged identically on your connected port. In short, if you want subnet, vlan and zone separation of clients you need the switch setup to be appropriately changed along with the PA for this to work. But perhaps you don't need this if user id setup will get you what you need. If you can get the connection to AD or whatever the local auth is setup you can create your policies using security group membership and there is no need for physical network zone separation.
... View more