just out of interest, did you set up any VLAN based network object rules in the firewall on the Z3? we recently deployed a Z3, that devices connected to it couldn't communicate to the internet, and that was due to what is believed to be a bug(unconfirmed), that when you have a VLAN sourced base rule, it stops the firewall functioning correctly, and blocks most traffic.
Replacing the VLAN rule, with the ip range for that VLAN then allowed everything to function.
Might not be the same problem, but worth checking...