In order to overcome the limited number of physical interfaces on the PA-200, I need to have one physical interface handle traffic for two different zones, A & B. These zones need to talk to each other and to other internal zones (with security policies enforced by the firewall). In addition, they need to access the Internet using Dynamic-IP-and-port NAT, using the IP address of the external interface (which is on the Internet zone). All the ethernet interfaces are configured as layer 3 and all are on the same virtual router. They work fine with NAT. I'm having trouble with Zone B. For zone A, I used ethernet1/3. It has its own static RFC1918 subnet. Untagged Subinterface is not checked. For zone B, I use ethernet1/3.1. It has another static RFC1918 subnet. Its Tag is 3. Now I attach a workstation to physical interface 3 and I create a virtual interface on the workstation with Tag 3. I configure this virtual interface with an appropriate IP address, subnet, and gateway for zone B. I turn off the "normal" Ethernet interface on the workstation. (This is all done through Mac OS 10.8 System Preferences > Network.) At this point I can ping devices on the Internet side of the firewall. I can also traceroute. However, web pages don't load and DNS doesn't seem to work. Any suggestions on what I might be doing wrong or how to make this work?
... View more