thank you for reply.
I see. What you configured in your lab should be functional in production. As long as PA Firewalls have reachability to build a BGP session. After sessions are established and you configured advertisements of local subnets behind each PA, then every Firewall will learn all prefixes.
... View more