How much separation do you need? And is it really only outbound traffic or also inbound? If it is only outbound, do you really need the old firewall or can you just configure a VLAN with the subnet of the old firewall and replace the old device? For Internet-access, PAT is done automatically when you send traffic to the MX on a LAN interface.
... View more