Does their current firewall have the ability to do routing? If so why not set the device behind the network. LAN and WAN (do not prefer to double NAT but it works.)
After that give the Z3 a LAN IP address and setup a static route in current firewall for any traffic destined to the local LAN on remote office to the Z3 LAN IP address.
Make sure site to site VPN is on for the Z3 and the other site as well.
Voila you still are using your Verizon internet connection with the current firewall that is able to utilize the throughput verizon gives and if the client needs to reach their office they are able to as well as all traffic to the clients other office will be destined to the Z3.
Cloud Network Engineer | cloudIT
Certified Meraki Networking Associate
Kudo this if it helped! 🙂