I had the same issue: WoL packets allowed by policy, but droped by the firewall (PA-3020 in my case). I can see it when doing a packet capture on the firewall (stage drop).
On the Palo Alto, you can go on Network -> Interfaces -> (outgoing interface) -> Advanced -> ARP Entries
You add the broadcast address (192.168.1.255 for exemple), and the mac FF:FF:FF:FF:FF:FF. And the magic packet goes magic!
Alex from vpnwelt