What are the plans for support of FWaaS in OpenStack?

I had heard rumors that FWaaS was being retired in OpenStack. There how ever seems to be blueprint information up to the Mitaka release. Security Groups currently does not allow for a DENY rule and FWaaS and that allows the capability to block certain flows at least at the tenant perimeter if need be. If FWaaS is being retired is there a plan for something to take its place? Thank you.

