I wonder if JANET may have to adjust their MTU, because you're already handing them "q-in-q" traffic, and they (probably) add their q-in-q on top of that - so you're "q-in-q-in-q"-ing.
That being said, and because I looked at your drawing from the other post, why are you using a VMAN? Of course I'm now assuming (and I know how that usually goes) that you're in control of the VLANs on the Palo Alto and the VLANs that come in on the 670, which may not be true. But if it is, why not just tag all the VLANs all the way through your switches, tag them to the port where JANET plugs in, and let them handle the rest?