Hello, you are essentially correct. There are several ways to do this, but in keeping as close to your proposed solution here is what I would suggest- Create two new zones, untrust-b and trust-b, create an L3 interface for each zone with an IP address (I would use the Sonicwall's LAN and Sonicwall WAN IP). Create new virtual router, put both interfaces in that VR, config default gateway in that VR pointing to same Default gateway as sonicwall had) Create security policy to allow inbound and outbound traffic, create NAT rules, configure DHCP on new trust L3 interface. Move cables from Sonicwall LAN and WAN interfaces to your newly configured PA trust and untrust interfaces, Commit.
... View more