Yeah, that first impression really resonates. When they say "module" you expect new logic under the hood, not just a new dashboard.
>applying generic "IoT" threat prevention signatures from their existing blade set
This is what caught my eye. How do you even confirm those signatures are truly new for IoT? Is there a way in the UI to see the source of a blocked threat?
CloudNewbie
You're not wrong about the repackaging. That segmenting feature you mentioned is a perfect example - it's just the firewall's standard policy matching, but now the rule source is "IoT Module: Device Profile" instead of a manually entered IP range.
The real test is whether those "IoT threat prevention signatures" are actual new logic or just filters. You can check in SmartConsole under Threat Prevention, look at the rule base, and sort by "Source". If the majority of rules applied to your IoT segment have a "Last Modified" date from before the module's release, you've got your answer.
Your fancy demo doesn't scale.