I'm not talking about a size or throughput. I'm referring to a "must have" functions of an edge device for a larger environment.
1. No dynamic routing. There is no way to propagate routes into upstream MPLS. I get that that with VPN you may not need to do that, but there is also no way to learn routes from a core/distribution downstream switch. The only option is to use static routes.
2. Many:1 NAT is not an option (this is a big one). I have multiple ISPs, yet there is no way to make server (Exchange for example) available on both of them. There is 1:1 NAT and with that you have to set outbound priority.
3. Limited port forwarding. There is no way to claim one of the public IPs on WAN and configure port forwarding. The only port forwarding you can do is done on IP assigned to WAN interface. Well I guess you can do 1:Many NAT, but that ties that internal server to one particular interface.
4. Layer 3 firewall rules can't be assigned per interface, or LAN / WAN side for that matter. No way to whitelist / bypass Layer 3 rules on all LAN traffic for example.
5. Layer 7 firewall lacks filtering all together. The only option is "Deny", can't make any exceptions. Once again all traffic is included LAN-side along with WAN. Something that happened recently in our environment, "Deny peer-to-peer" actually broke LAN side SQL traffic.
6. No visibility (this is also a big one). Tech support offered to create an exception to Layer 7 rule I mentioned above, which brings me to a point. Why can't I see what is being blocked and by what, and how come I can't make those exceptions?
7. IPS / IDS, once again, provides very little control. You can whitelist the rule, but not interface or traffic side. Some things I would like to whitelist as I know what they are (like outdated RDP or something), but I don't want to whitelist it on WAN side, just LAN.
Let me know if you want to know more.... "Best firewall money can buy" can't compete with some free products out there as far as firewall or Edge device goes. I do regret that we went with MXs and a 3 year license. Will be switching as soon as it expires.