The Expected Lifespan of a Business Firewall

Firewall hardware is typically designed with a 5–7 year lifecycle. The hardware lasts longer than that in most cases — the problem is that the software and security capabilities don't. A firewall that stops receiving security updates is no longer a security device; it's a door that looks locked.

For Fortinet FortiGate devices — our platform of choice for Melbourne SMBs — end-of-support (EOS) typically occurs 5 years after a product's general availability date. After EOS, the device no longer receives FortiGuard signature updates, critical firmware patches, or support from Fortinet TAC.

Device still receiving updatesDevice past end-of-support
Daily IPS signature updates from FortiGuardSignature database frozen at EOS date
Critical firmware patches within days of CVE disclosureKnown vulnerabilities accumulate, unpatched
TAC support available for incidentsNo vendor support — you're on your own
New threat intelligence feeds activeThreat intelligence stale from EOS date
Hardware under warrantyNo warranty — hardware failure = outage

The Five Signs Your Firewall Needs Replacing

01
It's past or approaching end-of-support

Check the Fortinet product lifecycle page for your exact model. If your device is within 12 months of EOS, planning a replacement now is significantly less disruptive than emergency replacement after a failure or a security incident. EOS devices should be treated as a critical risk, not a "when budget allows" item.

02
It can't keep up with your internet speed

Firewall throughput is rated under ideal conditions — typically without deep packet inspection (DPI) or IPS enabled. When you enable the security features that make a firewall useful, throughput drops significantly. A FortiGate 60E rated at 1.5Gbps without UTM might deliver 200–400Mbps with full UTM enabled. If you've upgraded to a 500Mbps or 1Gbps NBN service and the old firewall was spec'd for 100Mbps, you're throttling your own internet connection.

03
SSL inspection is too slow to run

SSL/TLS inspection — where the firewall decrypts, inspects, and re-encrypts HTTPS traffic — is essential for detecting malware in encrypted traffic. But it's computationally expensive. Older hardware often can't perform SSL inspection at full wire speed, forcing administrators to disable it to avoid performance complaints. An underpowered firewall that can't do SSL inspection has a fundamental blind spot.

04
It was purchased with consumer or SOHO hardware

Devices marketed as "business routers" — including some TP-Link, ASUS, Netgear, and D-Link products marketed for small offices — are not enterprise firewalls. They lack IPS, application control, SSL inspection, proper logging, and security subscription feeds. If your "firewall" doesn't have an active security subscription model, it's almost certainly not providing enterprise-grade protection.

05
Your business has grown beyond the device's original spec

A FortiGate 40F purchased for a 5-person office is not the right device for a 30-person office. As user count, internet speed, and cloud application usage grow, the firewall's security processing capacity becomes the bottleneck. Undersized firewalls lead to performance problems that are typically misdiagnosed as ISP issues.

The Risk of Running an EOS Firewall

The risk isn't theoretical. Firewall vulnerabilities are actively exploited in the wild, often within days or weeks of public disclosure. Fortinet has had several significant CVEs in recent years that were exploited by threat actors targeting businesses — including CVE-2022-40684 (authentication bypass in FortiGate management interface) which was exploited in the wild before many organisations had patched.

A device past end-of-support will not receive patches for vulnerabilities like these. The attack surface is fixed at the state of the firmware on the day support ended, and it only gets worse as new vulnerabilities are discovered that will never be fixed.

Figure 1 — Security protection gap: supported vs. end-of-support firewall over time
End of SupportSupported device(protection ↑ with updates)EOS device(no new updates)Growing protection gapThreat sophistication ↑PurchaseYear 2Year 5 (EOS)Year 7Year 9+

Throughput: What Your Firewall Spec Actually Means

When evaluating firewall throughput, there are three numbers you need to look at:

SpecWhat it measuresWhy it matters
Firewall throughputRaw packet forwarding with no inspectionNot representative of real-world performance with security enabled
IPS / NGFW throughputThroughput with intrusion prevention enabledCloser to real performance — this is the relevant number for most deployments
SSL inspection throughputThroughput with SSL/TLS decryption enabledOften 3–5x lower than IPS throughput — the real bottleneck for M365 environments

As a rule of thumb: size your firewall so that the SSL inspection throughput is at least 2x your internet connection speed. This gives headroom for peak loads and future internet upgrades.

💡
FortiGate sizing for common Melbourne SMB scenarios
10–20 staff, 100Mbps NBN: FortiGate 40F or 60F
20–50 staff, 250–500Mbps NBN: FortiGate 80F or 100F
50–100 staff, 500Mbps–1Gbps fibre: FortiGate 200F
These are indicative — exact sizing depends on application mix, SSL inspection requirements, and VPN usage.

The Replacement Planning Cycle

Our recommendation is to budget for firewall replacement on a 5-year cycle, aligned with vendor support lifecycle. In practice, this means:

  • Year 1–4: Active support, firmware updates, FortiGuard subscription current
  • Year 4: Check EOS date. Begin budgeting for replacement if EOS falls within 18 months. Review whether the current device is still adequately spec'd for current internet speed and user count.
  • Year 5: Replace before EOS where possible. A planned replacement during a scheduled maintenance window is far less disruptive than an emergency replacement after a hardware failure.

Hardware replacement isn't the only cost — allow time for configuration migration. A well-documented FortiGate configuration can typically be migrated to new hardware in a half-day maintenance window with minimal service interruption.

What If You Don't Know How Old Your Firewall Is?

If you're not sure what firewall you have or whether it's current, ask your IT provider. The information you need is:

  • The exact model number (visible on the physical device label or management console)
  • The current firmware version
  • Whether FortiGuard subscriptions are active and current
  • The end-of-support date for the model

If your IT provider can't answer these questions, that's a problem in its own right. Network infrastructure status should be part of any managed IT service relationship — not something you have to ask for.

Signs your firewall might not be enterprise-grade
You pay no annual subscription fee for security updates. The management interface looks like a home router. The device is branded TP-Link, Netgear, ASUS, or similar consumer brands. Your IT provider has never mentioned firewall lifecycle or patching. Any of these is worth investigating.

The Bottom Line

Firewall lifecycle management isn't glamorous — but it's one of the most important and most neglected parts of SMB network security. An EOS firewall with a stale IPS database and unpatched vulnerabilities is not a security control. It's a liability that gives a false sense of protection.

If you're not sure about your firewall's status, we can check it as part of a network assessment and give you a straight answer on where you stand, what the risk is, and what it costs to fix it.