To be honest, I've had a bad experience with SRX and FTD.
We once lost a lucrative customer, a bank, because of Juniper and SRX.
We had only recently acquired the customer and, at their request, migrated an important cluster to SRX. Then an upgrade was due, and during the change we had a split brain situation. Even the Juniper experts present couldn't find the cause at first. Until a colleague of mine found out in a user group that the behaviour of sync traffic in VLAN had changed with the new release and how to revert it. But that was still enough for the customer to kick us out.
As for FTD, we once set up a two-tier DMZ environment. Checkpoint on the inside and FTD on the outside. Again, after an FTD upgrade, every few days the FTD cluster decided to reject all DNS requests to the outside. The only workaround until a patch version was delivered was to reboot the nodes. Simultaneously.
Since these incidents, I have not wanted to have anything to do with either of them.
and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite