@KCL - Scott, an NGFW box with an integrated PoE switch, let alone one with more than 4-5 PoE ports, is a rare bird, and a dying one at that.
IMHO, your best option is the outgoing (but still available) Fortinet FortiGate 80E-POE or 81E-POE, with 12 total PoE+ ports (
datasheet here). They're about $1K new, $2-5K depending on what level and length of licensing you add on. The replacement "F" series will give you considerably more throughput per dollar, but Fortinet has reduced the size of the onboard PoE+ switch down to 8 ports (
datasheet here).
There are also lower port-count options from Sophos, Sonicwall and Forcepoint, but none with enough PoE ports for your use-case, plus I think Fortinet makes a better overall product and ecosystem than any of those vendors.
There's also the SMB VPN router/firewall products, like the recently EOS Cisco RV345P or DrayTek 2952P, but they're more or less completely lacking in the NGFW/UTM front when compared to the likes of a FortiGate.
Anyways, hope that helps. Any more questions, feel free.