- Does the protected port group on the vSphere DSwitch have to be VLAN ID 8 as well, or can I just leave it as VLAN type "None"? Both sides will be none in your case. You only need to set tags if you have a Q tag port. In your design these are access ports so none is all you need to do. - Is there anything extra I need to do to ensure that the HA pair will never accidentally create a loop between the two segments of the same network? No, the passive device keeps the traffic interfaces up but never passing traffic. The PA will not participate in STP at all so all you need to do is make sure the switching system never puts the active device into a blocking port. - Are there any other considerations I need to know about in a deployment like this? I have not used the VMs for HA but I assume you still need the HA ports connected to communicate state tables and the like. I don't see that in your setup here. your may find the example for layer 2 HA in the Design guide helpful starting on page 80 Designing Networks with Palo Alto Networks Firewalls
... View more