“firewalls” have been obsolete for years. instead of protecting a perimeter and then assuming (incorrectly) that your corp network is safe, only let devices on your network that can cryptographically prove they belong there. it requires that you have your inventory shit together, of course.