Both VM-Series and CN-Series firewalls can be used to protect container environments. The major difference between the two is the granularity of visibility and control delivered by the CN-Series. VM-Series firewalls can enforce cluster-level security policies, which makes them good for basic perimeter security of an entire cluster.
But in many circumstances, you may want to inspect traffic within the cluster for threats or for compliance reasons, or you might want to enforce tighter segmentation between application components hosted within the same cluster. In these circumstances, CN-Series firewalls provide the granular visibility and control over traffic between nodes that will enable these types of use cases.
Learn more here.