Network security hardware is growing, but channel partners should not mistake the rebound for a return to once-lucrative box-first security.
In its July 2026 five-year forecast, Dell’Oro Group said it expects worldwide network security hardware spending to exceed $90 billion from 2025 through 2030, with revenue growing at a 7% compound annual rate. That’s nearly twice the 3.8% CAGR recorded from 2020 through 2025.
Targeted replacement serves as the near-term catalyst, Mauricio Sanchez, senior director of enterprise security and networking at Dell’Oro, told Channel Dive. Systems approaching end of support, carrying known security exposure or running short on performance headroom are pushing customers to act. Importantly, Sanchez noted, “replacement and new capacity are often intertwined.”
That overlap can turn a refresh into a larger infrastructure project. Customers may use the work to increase throughput or encryption capacity, improve resilience or make room for additional security services. As such, Dell’Oro expects hardware revenue growth to reflect a mix of replacement activity, some unit expansion, larger configurations and pricing and subscription attachment.
The rebound follows a major shift in how customers buy network security. SaaS and virtual revenue overtook physical appliances in 2025, a full year ahead of Dell’Oro’s forecast from 2022. The shift to software outran the analyst firm’s schedule and hardware kept accelerating anyway. In the firm’s 2026 outlook, SaaS accounts for about 40% of revenue, virtual products 15% and physical appliances 45%.
Security Service Edge, meanwhile, is growing faster than hardware. Dell’Oro expects SSE revenue to double from 2025 to 2030 at a 16% CAGR. Sanchez described the market as “more balanced,” not a return to hardware-first architecture.
The web application firewall forecast, meanwhile, shows why market growth does not necessarily translate into appliance growth. Dell’Oro expects the WAF market to nearly double and exceed $7 billion by 2030, with SaaS, virtual and physical products all included.
“SaaS-delivered WAF and broader WAAP platforms are expected to capture most of the incremental spending,” Sanchez said, citing distributed enforcement, elastic capacity, rapid security updates and integrated WAF, API, bot and DDoS capabilities as reasons why. Physical and virtual WAF products remain relevant in certain private, sovereign, regulated and performance-sensitive environments, but they are not expected to drive most of the expansion, per Sanchez.
Firewalls are on fire
Where organizations are deploying appliances is changing, too.
“The hardware growth is not centered on traditional low-end branch appliances,” Sanchez said. Rather, branch security continues moving toward secure SD-WAN, Firewall-as-a-Service and SSE platforms. Stronger appliance opportunities lie in data centers, campuses and larger branches, service-provider infrastructure and private, sovereign, regulated or disconnected environments.
“This is not a return to putting a box at every location,” Sanchez said.
Instead, organizations are using appliances selectively alongside virtual firewalls, SaaS security, host-based enforcement, microsegmentation and other distributed controls.
Yet the hardware categories themselves are not moving in lockstep.
“Physical firewalls are carrying most of the hardware growth,” Sanchez said.
That particularly applies to high-end and midrange systems in data centers, campuses, larger branches and service-provider environments. Application delivery controller, or ADC, hardware is getting support from lifecycle migrations and capacity additions, but Sanchez called the category mature and expects growth to moderate.
“Traditional SWG appliances remain in structural decline as web security shifts toward SSE,” he said, referring to secure web gateway appliances.
Against that backdrop, Fortinet, a key security hardware vendor that sells through the channel, offers insight into what’s sustaining firewall demand. CFO Christiane Ohlgart told Channel Dive the company is seeing changes across network security and adjacent markets, especially due to AI, rising traffic volumes and demand for greater performance, visibility and control across hybrid environments.
Customers also have more choices in how they deploy security, Ohlgart said. That can be through the cloud, through a customer-controlled FortiGate or locally with FortiGate and FortiSASE services, she said. Performance, compliance, sovereignty and operational requirements determine the approach.
Ohlgart said that flexibility “is helping define the emerging SASE Firewall market.” She also pointed to “new opportunities for channel partners to help customers modernize infrastructure and deploy the right mix of hardware, software, cloud-delivered security, and services.”
Those local, customer-controlled and cloud-delivered models can coexist. Even so, Dell’Oro does not expect the current pace of hardware growth to persist.
“The forecast is somewhat front-loaded, and we expect the growth rate to moderate later in the period,” Sanchez said. “However, we do not view this as one synchronized replacement cycle that suddenly ends.”
Support deadlines vary by vendor and product generation, Sanchez said. Data-center modernization, rising throughput requirements, sovereignty concerns, application growth and security risks also create demand at different points during the forecast period.
AI infrastructure investment represents one of those factors, but Dell’Oro’s forecast does not assume that AI growth translates uniformly into appliance sales. Asked what AI infrastructure investment means in this context, Sanchez said it refers to “several specific security and application-delivery requirements rather than a blanket assumption that AI will cause every type of network traffic to surge.”
Those needs vary by product. Firewalls can protect AI data-center perimeters, front-end networks, inference environments and north-south traffic boundaries. ADCs can support load balancing, TLS processing, session management, availability and traffic control for model delivery and inference applications. WAF and WAAP products can protect model endpoints, APIs, retrieval systems and interactions among agents, tools and data sources.
The architecture also puts boundaries around the physical-appliance opportunity.
“The fastest AI backend fabrics are less likely to insert conventional appliances directly into every traffic path,” Sanchez said.
Instead, those environments may lean more heavily on virtual firewalls, host-based controls, DPUs, switches or microsegmentation.
“AI expands the overall security requirement, but it does not create an identical physical-appliance opportunity everywhere,” Sanchez said.
The partner opportunity
For partners, Sanchez identified opportunities around the refresh and modernization work itself. Channel experts can help with installed-base discovery, end-of-support and vulnerability assessments, capacity planning, platform sizing, migration and implementation, he said.
The initial project can also create openings for longer-running revenue. Sanchez said subscription attachment, managed services, policy and telemetry integration, lifecycle operations and ongoing optimization stand out as the more durable opportunities for partners.
The type of work depends on where customers are modernizing.
“At the branch, the work is shifting toward secure SD-WAN and SASE architecture rather than simply replacing individual boxes,” Sanchez said.
In application security, he said the work increasingly includes WAF-to-WAAP migration, API discovery and protection, virtual patching and managed application-security operations.
For partners, the immediate opportunities include assessment, sizing, migration and implementation work.
“In many cases, the services surrounding the product will be more durable than the initial hardware margin,” Sanchez said.