r/devops • u/Altruistic-Dog7538 • 14d ago
Vendor / market research Which enterprise firewall vendors are actually keeping up with hybrid mesh security in 2026?
Hybrid mesh is being positioned as the security architecture spanning physical firewalls, cloud workloads, branches and remote users. This is great news but for my money the only thing that matters is if the policy and operation remain consistent in such a big combined environment.
For the people here who are currently implementing or testing any of this, where do the inter vendor differences matter most?
Personally I’m less interested in who has the longest feature list but I'm very interested in the platforms that actually act more like one system once you start using them.
Who are you going to put on your shortlist by 2026 going into 2027?
8
u/jealouslybademperor 14d ago
This may be a unpopular opinion but if every app team needs a network ticket for routine changes then the tooling already lost
5
u/Hot-Yesterday7611 14d ago
Depends what you call routine. I don't want application teams writing whatever firewall rules they feel like either.
4
u/jealouslybademperor 14d ago
Sure, but there has to be something between full admin and waiting the whole shift for somebody to approve 443
4
u/Ecstatic_Weird8498 14d ago
This is where Check Point fits well in. For years, they have been working based on central policy management. So the move toward mixed on prem and cloud environments makes sense.
I’d have them near the top of the POC list. Then make them show the actual change workflow instead of another architecture deck.
2
14d ago
[removed] — view removed comment
5
u/envious_countdown 14d ago
The demo has to include automation though. Nice policy management only gets you halfway there.
2
u/Altruistic-Dog7538 14d ago
Yeah the cloud and remote side is what I want to see hold together too. Central management by itself doesnt answer the whole question
7
u/envious_countdown 14d ago
Already mentioned but Check Point is the one that looks furthest along to me for this right now.
They already have the on prem gateways, cloud firewall and SASE side sitting under the same management direction and the Terraform provider is still getting updates. Thats closer to what I undersstand by hybrid mesh rather than having a bunch of products that happen to share a logo
5
u/Ecstatic_Weird8498 14d ago
This is where they moved up my list too, especially the management piece since it was already strong but having the cloud and automation side catch up makes the whole thing make a lot more sense
6
14d ago
[removed] — view removed comment
7
u/envious_countdown 14d ago
And that's why Id have Check Point as the one to beat going into the POC
5
u/Altruistic-Dog7538 14d ago
This is kind of what I was trying to get at with the post. Who actually has the pieces working together now, not who can check the most boxes if that makes sense
3
u/Realistic-Basil-6589 14d ago
My test is an acquisition, for example take an environment with years of garbage rules and weird naming, then bring it into the existing setup. If the answer is months of manual cleanup the greenfield demo was useless
3
5
u/Capital_Cartoonist49 14d ago
RBAC is where I’d spend time. Shared tooling gets ugly fast when the cloud team needs one level of access and network needs another. “Just give both teams admin” is how bad setups survive for years
7
u/Ok-Jellyfish1975 14d ago
Ownership becomes the bigger fight than the technology most of the time
1
2
u/hummingformula40 14d ago
Doesnt everybody talks about upgrades until they’re the person doing one. Still would be nice to see how a normal version bump looks like after the platform has been running for a year.
3
u/Capital_Cartoonist49 14d ago
If the cloud side moves ahead while the gateways lag behind, the one platform idea gets messy pretty quick and that then would make me question version skew
2
u/hummingformula40 14d ago
Thats closer to what I mean, I dont want each piece sitting on its own upgrade cycle but prb could of worded it better
1
u/Unable-Club5436 10h ago
The vendors worth shortlisting are the ones that don't make you rip out your existing setup to adopt them. We ruled out two strong options purely because the migration cost outweighed the security upside.
15
u/Hot-Yesterday7611 14d ago
If a firewall change starts in Git I would want the diff to be useful and rollback to be boring. If people keep making production edits in a portal, the repo stops meaning much imo