Hi,
if you mean traditional L3/L4 even application firewalling -it is supported even with DNA Essentials. If you need advanced features like URL filtering/AMP ,then you need DNA Advantage, for Umbrella SIG feature you need DNA Premier.
https://www.cisco.com/c/en/us/products/collateral/software/one-wan-subscription/nb-06-dna-sw-rout-sub-faq-ctp-en.html#PurchasingCiscoDNAforSDWANandRouting
Note that, not all SD-WAN routers support all security features. Some supports with more resources (DRAM for example).
In general, to understand Security features in SD-WAN, you should check below link:
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-security-policy-design-guide.html
Basically, answers for questions:
1) Depends on security- "firewall" features that you want to use -enable on router
2) Yes, it is basically L7.
Regards,
HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.