Everyone pushes SASE as the obvious upgrade. But you've already got Palo Alto NGFWs in your branches. They work. So when does switching to their SASE actually make sense?
I see two real scenarios. First, when you're consolidating tiny sites with no local IT. The SASE client on the router is fine, cheaper than a physical box. Second, when your "branch" is just a bunch of remote users. Forcing them back through a physical NGFW for security is a latency nightmare. SASE makes sense there.
Otherwise? You're trading a known, capable appliance for a cloud service with potential performance hits and new failure points. ROI seems shaky unless you're drowning in boxes or your network model has fundamentally changed.
If it's not flaky, is it even tested?
You're spot on about the scenarios where SASE shines. I'd add one more: when you're expanding fast with new branches and don't want the lead time for hardware shipping and configuration. Spinning up a SASE connection through code can be faster.
But your point about trading a known appliance is crucial. We hit a snag when our main SASE POP had an outage. With an on-prem NGFW, the branch is isolated. With SASE, that whole region's branches were dead until we failed over. The cloud service introduces a new single point of failure you have to design around.
It really comes down to whether your WAN model is already shifting to direct-to-cloud. If most traffic is headed to SaaS apps anyway, backhauling it to a box just adds cost and latency for no benefit.
State file don't lie.