i use Stormshield Endpoint Protection "https://www.stormshield.eu/endpoint-protection/" , you can configure in only witelist application checking the application certificate id and is very good to prevent cryptolocker attack.
take a loot also to this solution
https://www.stormshield.eu/francais-protection-du-reseau/network-protection/
this has a better UTM based on RFCs, Sophos is always the best for proxy features
"It could be more vendor independent."
why you tell this? i use clearpass guest module for hotspot build on chillispot (so opensource based devices) and radius coa works well
i use zabbix nms for snmp and wmi monitoring and graylog for syslog message analysis, also i monitor graylog from zabbix using the api (a simple script based on curl and jq)
actually i monitor more than 1300 devices and zabbix feature like remote proxy, graphical maps and…
stormshield v2.2 is a great product, if your fw is an u250S you can upgrade to stormshield firmware, if is only u250 please contact your reseller for a tradeup
what version are you using? still netasq firmware or stormshield
stormshield v2.2 is very stable.
is your firewall crashing (so under /log you can find some *.core files or maybe you've spoofing alarms?)
on netasq in bridge mode sometimes you've spoofing issues not for…