That is great. Thank you! I tested this in lab using minimum config and it seems to work. I am going to add the rest of the configs to see if it works. Now, suppose that using an adding an external switch was not an option. Is there another way to solve this issue? Below are some of the things we came up with. 1. Palo Alto tech support suggested an article that configures a layer 2 to layer 3 connection utilizing a combinations of L2 interface and Virtual router and VLAN. It was complicated and when I tested it, it did not work. Either I didn't choose the right options or it just doesn't work. How to Configure a Layer 2 to Layer 3 Connection on the Palo Alto Networks Device 2. If we further divide the WAN subnet so that WAN has 100.100.100.0/25 and DMZ has 100.100.100.128/25, and changing the upstream router route is not an option, does Palo Alto firewall supports Proxy ARP for the new DMZ subnet? or will it only do proxy arp for NAT devices it is responsible for? 4. If we do NAT translation from WAN to DMZ using the same IP, meaning 100.100.100.100 translates to 100.100.100.100 in DMZ. Would this have worked? The reason I am asking these questions is in case I ran into these issues again, I will have other ways to solve it. Really appreciate your feedback. Thank you!
... View more