I did have routes for each of the Catalyst 2960s VLANs. Initially, I left them in place but then I deleted them for VLANs 1 and 5, the two that I was testing.
The uplink from the switch to the firewall is trunked. I didn't clear the arp cache. Good suggestion, I'll try that next time. How about the question about which port to use to connect the switch to the firewall. Do I connect to the port that I designate as VLAN or the one that is designated as LAN?