I don't think Gun-Slingers question is answered here. The bridging shown is dependent on physical interfaces, which are limited. In a situation where all traffic is moving across one Aggregate Ethernet trunk, bridging would need to take place inside the firewall. As the OP indicated, supporting a data center would not be practical using physical interfaces for bridging. Our situation is the same, and it looks like we may need to use two Aggregate Ethernet interfaces, with common VLANs between different Zones, pruning VLANs as necessary on one of the AE interfaces.
... View more