Within a Palo Alto Networks firewall, a packet may hop from
one virtual system to another virtual system or a shared gateway.
A packet may not traverse more than two virtual systems or shared
gateways. For example, a packet cannot go from vsys1 to vsys2 to
vsys3, or similarly from vsys1 to vsys2 to shared gateway1. Both
examples involve more than two virtual systems, which is not permitted.