My opinion was that the current on-prem enterprise environment would remain due to change reistance but that eventually the cloud implementation principals would move on-prem.
Not just change resistance. Plenty companies still have on prem presence and hardware. They need firewalls to segment this, especially on an east-west scenario.
I've been trying to get a major MSP to implement threat intelligence on a popular firewall from pre-pandemic. Zilch delivery. Told them to escalate to the vendor. Still Zilch. I'll believe it when I see it.
Thats an issue with people / MSP, not the devices or technologies
Practical experience shows that vendors don't deliver on automation and require manual configuration by a trained expert even on the most simple of tasks.
Well this depends, I mean a SOAR system does automation at a pretty good level, but obviously needs to be told what to do or at least have some parameters.
Fortinet, who is miles behind has automation stitches built in that can do tons of stuff. I've seen plenty firewall environments managed using other automation tools like ansible.
Provisioning occurs with many vendors and works out the box with tons of scenarios.
Firewalls don't implement the latest networking encapsulations or advanced queuing. The latest linux kernel build as well the mac does have them. They lagging.
I know firewalls that can do pretty advanced queuing, H-QOS, tagging, segment routing etc
They also have dedicated asics for certain functions, like inspection functions, routing convergence etc
Again, every side will have a win at some point and I agree, for traffic steering and manipulation, SD-WAN devices are more geared and suited for this. But they are not geared for proper security, at least not yet. And I think it would be silly to try push them that way when we are looking at a dissolved perimeter and would rather cloud our security.
What about when the firewall claims to do SD-WAN? In actual fact, market leader. Mostly because the feature is enabled by license but not used.
Not sure what your point is here. SD-WAN in my opinion is not a replacement for a perimeter firewall which is what your article is kind of saying. What this is doing is going the other way round that firewall vendors are doing and just moving security services on top of a device trying to do SD-WAN. I dont think either is the way forward.
A secure services edge is where the security services should be migrated if possible and SD-WAN should be used for traffic steering, optimization, acceleration, peering etc.