The Expected Lifespan of a Business Firewall
Firewall hardware is typically designed with a 5–7 year lifecycle. The hardware lasts longer than that in most cases — the problem is that the software and security capabilities don't. A firewall that stops receiving security updates is no longer a security device; it's a door that looks locked.
For Fortinet FortiGate devices — our platform of choice for Melbourne SMBs — end-of-support (EOS) typically occurs 5 years after a product's general availability date. After EOS, the device no longer receives FortiGuard signature updates, critical firmware patches, or support from Fortinet TAC.
| Device still receiving updates | Device past end-of-support |
|---|---|
| Daily IPS signature updates from FortiGuard | Signature database frozen at EOS date |
| Critical firmware patches within days of CVE disclosure | Known vulnerabilities accumulate, unpatched |
| TAC support available for incidents | No vendor support — you're on your own |
| New threat intelligence feeds active | Threat intelligence stale from EOS date |
| Hardware under warranty | No warranty — hardware failure = outage |
The Five Signs Your Firewall Needs Replacing
Check the Fortinet product lifecycle page for your exact model. If your device is within 12 months of EOS, planning a replacement now is significantly less disruptive than emergency replacement after a failure or a security incident. EOS devices should be treated as a critical risk, not a "when budget allows" item.
Firewall throughput is rated under ideal conditions — typically without deep packet inspection (DPI) or IPS enabled. When you enable the security features that make a firewall useful, throughput drops significantly. A FortiGate 60E rated at 1.5Gbps without UTM might deliver 200–400Mbps with full UTM enabled. If you've upgraded to a 500Mbps or 1Gbps NBN service and the old firewall was spec'd for 100Mbps, you're throttling your own internet connection.
SSL/TLS inspection — where the firewall decrypts, inspects, and re-encrypts HTTPS traffic — is essential for detecting malware in encrypted traffic. But it's computationally expensive. Older hardware often can't perform SSL inspection at full wire speed, forcing administrators to disable it to avoid performance complaints. An underpowered firewall that can't do SSL inspection has a fundamental blind spot.
Devices marketed as "business routers" — including some TP-Link, ASUS, Netgear, and D-Link products marketed for small offices — are not enterprise firewalls. They lack IPS, application control, SSL inspection, proper logging, and security subscription feeds. If your "firewall" doesn't have an active security subscription model, it's almost certainly not providing enterprise-grade protection.
A FortiGate 40F purchased for a 5-person office is not the right device for a 30-person office. As user count, internet speed, and cloud application usage grow, the firewall's security processing capacity becomes the bottleneck. Undersized firewalls lead to performance problems that are typically misdiagnosed as ISP issues.
The Risk of Running an EOS Firewall
The risk isn't theoretical. Firewall vulnerabilities are actively exploited in the wild, often within days or weeks of public disclosure. Fortinet has had several significant CVEs in recent years that were exploited by threat actors targeting businesses — including CVE-2022-40684 (authentication bypass in FortiGate management interface) which was exploited in the wild before many organisations had patched.
A device past end-of-support will not receive patches for vulnerabilities like these. The attack surface is fixed at the state of the firmware on the day support ended, and it only gets worse as new vulnerabilities are discovered that will never be fixed.
Throughput: What Your Firewall Spec Actually Means
When evaluating firewall throughput, there are three numbers you need to look at:
| Spec | What it measures | Why it matters |
|---|---|---|
| Firewall throughput | Raw packet forwarding with no inspection | Not representative of real-world performance with security enabled |
| IPS / NGFW throughput | Throughput with intrusion prevention enabled | Closer to real performance — this is the relevant number for most deployments |
| SSL inspection throughput | Throughput with SSL/TLS decryption enabled | Often 3–5x lower than IPS throughput — the real bottleneck for M365 environments |
As a rule of thumb: size your firewall so that the SSL inspection throughput is at least 2x your internet connection speed. This gives headroom for peak loads and future internet upgrades.
10–20 staff, 100Mbps NBN: FortiGate 40F or 60F
20–50 staff, 250–500Mbps NBN: FortiGate 80F or 100F
50–100 staff, 500Mbps–1Gbps fibre: FortiGate 200F
These are indicative — exact sizing depends on application mix, SSL inspection requirements, and VPN usage.
The Replacement Planning Cycle
Our recommendation is to budget for firewall replacement on a 5-year cycle, aligned with vendor support lifecycle. In practice, this means:
- Year 1–4: Active support, firmware updates, FortiGuard subscription current
- Year 4: Check EOS date. Begin budgeting for replacement if EOS falls within 18 months. Review whether the current device is still adequately spec'd for current internet speed and user count.
- Year 5: Replace before EOS where possible. A planned replacement during a scheduled maintenance window is far less disruptive than an emergency replacement after a hardware failure.
Hardware replacement isn't the only cost — allow time for configuration migration. A well-documented FortiGate configuration can typically be migrated to new hardware in a half-day maintenance window with minimal service interruption.
What If You Don't Know How Old Your Firewall Is?
If you're not sure what firewall you have or whether it's current, ask your IT provider. The information you need is:
- The exact model number (visible on the physical device label or management console)
- The current firmware version
- Whether FortiGuard subscriptions are active and current
- The end-of-support date for the model
If your IT provider can't answer these questions, that's a problem in its own right. Network infrastructure status should be part of any managed IT service relationship — not something you have to ask for.
You pay no annual subscription fee for security updates. The management interface looks like a home router. The device is branded TP-Link, Netgear, ASUS, or similar consumer brands. Your IT provider has never mentioned firewall lifecycle or patching. Any of these is worth investigating.
The Bottom Line
Firewall lifecycle management isn't glamorous — but it's one of the most important and most neglected parts of SMB network security. An EOS firewall with a stale IPS database and unpatched vulnerabilities is not a security control. It's a liability that gives a false sense of protection.
If you're not sure about your firewall's status, we can check it as part of a network assessment and give you a straight answer on where you stand, what the risk is, and what it costs to fix it.