Hi @mnaylor , You could add a secondary NIC to one of the VMs in the vending device subnet. You can configure that VM to route. You can add a route on the other VMs to point to the multi-homed VM. Only a handful of VMs will have the route in your network. If you don't want to go that route (pun intended), I recommend you keep the vending network connected to your internal network. From what I understand, it seems unlikely that you will sell the public IP prefix and internal users will need it before you decommission the vending machines. The PANW definitely can provide a solution via NAT, but adding complexity to the design comes with its own problems. Thanks, Tom
... View more