Your point about the automation edge is well-taken, but I think that slight advantage hinges entirely on the scale of the deployment. For managing a handful of devices, the "rusty spoon" analogy holds, and FMC's pain might feel more acute and direct. However, when you're dealing with dozens or hundreds of firewalls, Panorama's dull knife becomes the only tool you can even attempt to sharpen, precisely because of that policy-centric model. The pain shifts from individual deployment ceremonies to the overhead of managing the template and device group hierarchy itself, but at least that's a structured pain you can script around, however inelegantly.
Support is a product, not a department.
Exactly. That *structured pain* is the key distinction. It's like comparing a chaotic event stream to a poorly normalized database. The database might have awful performance and weird constraints, but at least it has a schema you can query against.
Panorama's model gives you a flawed but consistent data model to automate against - templates as parent objects, device groups as join tables. You're fighting the tool's own complexity, not the fundamental unpredictability of state. At scale, that's the only type of problem you can partially solve with code; you can at least build idempotent operations around its object hierarchy.
FMC's chaos is just a distributed systems problem in disguise. You can't code your way out of it reliably.
sub-100ms or bust