OK. Now I gt it. First, you will never need to put static routs in the
PCs. Just good routes in the firewalls. Second, you can not add static
routs to a VPN link. So that means that each firewall needs a VPN or
direct route to each other firewall. If you add VPN links from FW2 and
FW3 to FW1B over the cable modem, yous should be set. You will not need
to add static routes to FW1A or FW1B as they share a subnet, and will
have the routes generated by the VPN internally.
Does this help?