One company I used to work for, we had an MSP on contract to basically back me up and provide 24x7 support. They were a Watchguard dealer and had many properties with WG firewalls onsite
We had Palo Alto firewalls at my company. During my tenure I got to know a lot of the MSP tier 2 and 3 techs, and we’d talk shop occasionally.
It seemed like every day they were rebooting a Watchguard on one of their client properties because it had locked up and become unmanageable, so they were basically taking businesses offline in the middle of the day to get the firewall back
I don’t know if it’s the hardware, firmware, or software that is at the core of those issues, but I am unabashedly NOT a fan of WG gear armed with that knowledge and experience
I run a completely separate switch for OOB, a separate vRouter in the firewall, with rules to allow those devices access to their update servers and nothing else