So, we are like a sledgehammer/freight train ... a sledgetrain? A freighthammer?
Standard press release template: Tech stuff is changing. This is a problem because waffle. Therefore buy our expensive shiny bauble.
I might have more sympathy if I hadn't spent so much time scraping their revolting faulty crudware off PCs that come pre infected with it, choking the machine to a crawl and blocking most Net access by mistake (the UI had stopped working, so everything was blocked pending a dialog box that never appeared). I've seen a lot of malware that's easier to uninstall cleanly, even before the AV tools have signatures for it!
In a sense, firewalls were always a stupid idea: most threats, statistically, come from inside anyway, rendering the firewall useless. To cap it all, these days we have increasing numbers of users outside the network anyway (telecommuting, distributed offices, all sorts) - and some of the services are off-site too. When it isn't between all the users and all the servers, or between all the users and the Internet, or between all the servers and the Internet, it does look rather like an overpriced fan heater in the racks...
Solution: bin the stupid packet filter, secure the servers properly like you have to anyway, make sure the client devices have decent AV protection where applicable. Symantec would probably like to think they can offer the latter, just like Saddam Hussein probably wanted to think he was a nice guy, and about as plausible.