Hi Redford1980,
Your idea works. I adopted it and I can see that there is OSPF routing between my single firewall (Palo Alto) and the two 8320 VSX nodes I am using. However, I have a question. The firewall sees 2 OSPF neighbors, which are the VSX-peers. How do you tell the firewall to route packets to the primary VSX-peer and not the Secondary VSX-peer? Did you do anything special? According to the VSX guide, I made the firewall the DR but for some reason, the firewall is seeing the secondary VSX-peer as its next hop instead of the primary VSX-peer. At some point, I removed the two VSX-peers from participating from DR/BDR election with the firewall but no changes. The only option that looks promising is to give the primary VSX-peer a higher router-ID.
I would appreciate any advice. Thanks.