Firewall Decommissioning Checklist: How to Retire an End-of-Life Firewall Safely

The new platform is live, the cut-over went well, and the old firewall is switched off. It still holds your VPN keys, your certificates, the passwords of the service accounts it used and a complete map of your network.
Retiring a firewall safely takes four phases: map what depends on it, archive what you need for audit, revoke every secret and trust relationship it holds, and only then sanitise and dispose of the hardware. This checklist walks through each phase, with the vendor commands that do and do not wipe the device, and what European rules expect along the way.
How do you decommission a firewall securely?
Map every dependency and notify partners first. Archive the final configuration and the evidence your auditors need. Revoke all secrets and trust relationships the firewall holds, including VPN keys, certificates and service accounts. Then sanitise the storage, remove the unit from vendor portals, end the contracts and hand the hardware to a certified disposal partner with a chain of custody.
Why this is worth doing properly
In 2023, researchers at ESET bought 18 used core routers and firewalls on the second-hand market. Of the 16 that still worked, 9 contained complete corporate configuration data and only 5 had been properly wiped. The exposed configurations included VPN credentials and keys, routing details and, in several cases, credentials that gave access to partner networks. In one case the former owner had paid a disposal company to wipe the device.
A firewall is not a server with some files on it. It is where your trust relationships with the outside world end: partner tunnels, certificates your laptops trust, accounts that can read your directory. Switching it off does not end any of those.
The checklist at a glance
| Phase | Step | Owner | Evidence to keep |
|---|---|---|---|
| 1. Map and prepare | Map all dependencies: VPN peers, routes, NAT rules, published services, VLANs, DHCP and DNS roles | Network security engineer | Dependency list |
| 1. Map and prepare | Notify partners whose tunnels end on this firewall and agree a date | Network operations | Communication log, change schedule |
| 1. Map and prepare | Run a controlled isolation window before final removal | Network operations | Change ticket with results |
| 2. Archive for audit | Export the final configuration, rule base, NAT and objects, and a vendor system backup | Firewall administrator | Archive with checksums |
| 2. Archive for audit | Move logs to central log storage under your retention policy | SOC or log owner | Log transfer record |
| 2. Archive for audit | Record the retirement as an approved change and update the asset register | CISO or compliance lead | Approved change, register entry |
| 3. Revoke and sanitise | Remove VPN peers and pre-shared keys on partner and branch devices | Network security engineer | Partner confirmation |
| 3. Revoke and sanitise | Revoke device, VPN and inspection certificates | PKI administrator | Revocation records |
| 3. Revoke and sanitise | Disable service accounts and rotate shared secrets, API tokens and SNMP credentials | Identity and network teams | Directory and change logs |
| 3. Revoke and sanitise | Sanitise the storage with the vendor procedure, and remove any removable media | Network security specialist | Console output, signed sanitisation record |
| 4. Release and dispose | Remove the device from vendor portals and cloud management | IT asset manager | Portal confirmation |
| 4. Release and dispose | End support contracts and subscriptions | Procurement | Cancellation confirmation |
| 4. Release and dispose | Hand over to a certified disposal partner with chain of custody | IT asset manager | Transfer document, certificate of destruction |
Phase 1: map what still depends on the firewall
The informal method is to switch the box off and wait for complaints. For a firewall, that fails, because many dependencies do not show up in the first week. Monthly replication jobs, quarterly scripts, a disaster recovery sync or a building management system can run for weeks before anyone notices they stopped.
Build the list instead. Start from the configuration: every VPN peer, every static route, every NAT rule and published service, every interface and VLAN, and any DHCP, DNS or NTP role the firewall plays. Practitioners regularly find devices with the firewall’s internal address hard-coded as gateway, DNS or time server: badge readers, printers, cameras, industrial equipment. Search for the old addresses in your other configurations before you remove them.
Tell every partner whose tunnel ends on this firewall, and agree the date. A partner device that keeps trying to reach a retired address fills its own logs and, in some cases, triggers blocking on their side.
Phase 2: archive what you need for audit
Decommissioning does not mean erasing the history. NIS2 expects asset management and change management, CyFun asks for the same, and DORA sets strict ICT asset management expectations for financial entities. When an auditor asks how a boundary device was retired, you need to show it.
Keep a compact archive:
- the final running configuration in readable form, plus the vendor’s own backup file;
- the rule base, NAT rules and objects in a structured export;
- routing and interface information as it was on the last day;
- checksums of every exported file, recorded at the moment of export;
- the approved change and the updated asset register entry.
Treat traffic logs separately. They contain IP addresses and user identities, which are personal data under GDPR, so they fall under storage limitation: keep them only as long as your purpose requires. Move them to your central log platform under your normal retention policy, then clear the local log storage on the device. Configuration and change records do not contain the same kind of personal data and can be kept for your audit cycle. The regulatory side of running and retiring old systems is covered in end-of-life systems under NIS2.
Phase 3: revoke every secret and trust relationship
This is the phase that gets skipped most, and it is the one that matters most. Trust relationships do not expire when the firewall is switched off. They stay valid on the other side until someone removes them.
| Secret or trust relationship | Why it matters after retirement | Who owns the fix |
|---|---|---|
| Site-to-site VPN peers and pre-shared keys | A partner device still accepts the old peer. If the key is recovered from the hardware, or the public IP address is reassigned, a tunnel into the partner network becomes possible. | Network team and each partner |
| TLS inspection CA certificate | If the firewall inspected TLS, its CA is trusted by every company laptop. Anyone holding that private key can issue certificates your laptops accept, for any site. | PKI administrator and endpoint team |
| Device and VPN certificates | Allow impersonation of the gateway or access to services that trust it | PKI administrator |
| Directory service accounts (LDAP, Active Directory) | Stored credentials give read access to users and groups | Identity team |
| RADIUS and TACACS+ shared secrets | Allow forged authentication exchanges | Identity and network teams |
| SAML service provider registration | The firewall’s SSO app remains registered in your identity provider | Identity provider administrator |
| API tokens and automation credentials | Long-lived tokens used by scripts, SIEM or ticketing integrations | Automation or security engineering |
| SNMP and logging credentials | Allow reconnaissance or forged log data | Network operations and SOC |
| DNS records pointing to the old WAN address | Whoever receives that address next receives your traffic, for example vpn.yourcompany.com | DNS administrator |
| Cloud management registration | A reset device that is still claimed can pull its old configuration when it comes online again | IT asset manager |
Two items deserve extra attention. The TLS inspection CA can be abused anywhere, without the old firewall or its IP address, for as long as endpoints trust it: revoke it at the issuing CA and remove it from endpoint trust stores. And VPN peers must be deleted on the partner side, not only disabled on yours. Certificate hygiene around changes like this is covered in certificate lifecycle management for the mid-market.
Sanitise the device: a factory reset is not the same thing
Firewalls store their configuration and logs on flash memory. A factory reset usually replaces the configuration and marks old data as deleted, but flash memory does not overwrite deleted blocks straight away. Forensic recovery of configuration fragments, keys and logs from reset network devices is documented.
NIST SP 800-88, the reference standard for media sanitisation, distinguishes three levels. Clear protects against simple recovery with standard tools. Purge makes recovery infeasible even with laboratory techniques, for example through cryptographic erase or firmware-level secure erase. Destroy makes the media unusable. Revision 2 of the standard, published in September 2025, puts more weight on a sanitisation programme and on validating that sanitisation worked.
| Vendor | Documented procedure | What to watch |
|---|---|---|
| Fortinet FortiGate | execute factoryreset; execute formatlogdisk for models with a log disk | The log disk is formatted separately. Fortinet does not describe the factory reset as purge-level sanitisation. |
| Cisco ASA | write erase and a reload, with additional steps to clear flash | write erase alone clears the startup configuration, not the flash file system. |
| Cisco Secure Firewall (FXOS) | erase secure from FXOS local management | Documented by Cisco as a secure erase of the internal storage. |
| Cisco Meraki MX | Reset on the device and unclaim it in the Meraki Dashboard | The configuration lives in the Dashboard. A claimed device pulls it back. |
| Palo Alto Networks | request system private-data-reset, or factory reset from maintenance mode | private-data-reset removes configuration, certificates, keys and logs. Check the enhanced factory reset documentation for your PAN-OS version. |
| SonicWall | SafeMode, restore firmware with factory default settings | Restores the default state; no vendor claim of purge-level sanitisation. |
| WatchGuard Firebox | Reset button at boot, restore factory default | Restores the default image; no vendor claim of purge-level sanitisation. |
| Sophos Firewall | Reset to factory defaults from the console menu, or reinstall from ISO | A full reinstall rewrites the partitions more completely than a reset. |
Source: vendor documentation. Procedures differ per model and software version, so check the current documentation for yours.
The practical rule: run the vendor procedure, keep the console output as evidence, and assume that it counts as Clear unless the vendor documents otherwise. If the device leaves your control, the storage should be destroyed by a certified partner, or the device should go through a documented purge. A dead unit that cannot boot needs its storage removed and destroyed. Degaussing does nothing to flash memory.
ISO/IEC 27001:2022 covers this explicitly: control 7.14 on secure disposal or re-use of equipment and control 8.10 on information deletion both expect you to verify and record that data was removed.
Phase 4: licences, portals and physical disposal
Vendor portals. Remove the serial number from FortiCloud or FortiCare, from Palo Alto’s customer support portal, from Cisco Smart Software Manager, and unclaim Meraki devices in the Dashboard. A device that stays registered can reconnect to its old configuration, and it keeps showing up in your contracts.
Contracts. End support and subscriptions in time for the notice period of the next renewal.
Resale. Selling a retired firewall is rarely worth it. Subscriptions and support are usually tied to the serial number and the original owner, and new owners pay to relicense. Palo Alto does not recertify end-of-sale or end-of-life hardware at all. Cisco treats licences as non-transferable in general, with a separate provision for transfers within Europe. For most mid-market organisations, certified recycling is simpler and safer than resale or donation.
Physical disposal in the EU and Belgium. The WEEE directive prohibits disposing of IT equipment as ordinary waste. In Belgium, Recupel coordinates collection of professional electrical and electronic equipment, and the regions set the waste rules through OVAM, the Service public de Wallonie and Bruxelles Environnement. Work with a certified IT asset disposal partner, require a chain of custody listing serial numbers, and keep the certificate of destruction stating the method and the standard used, such as DIN 66399 for physical destruction.
Mistakes that keep coming back
- Disabling the tunnel locally while the partner keeps the peer configured.
- Forgetting the TLS inspection CA, sometimes for years, on a unit stored on a shelf.
- Pressing the reset button on a cloud-managed device and donating it while it is still claimed.
- Leaving a retired firewall racked and powered “as a spare”, unpatched but still configured.
- Relying on a disposal company without asking which method it used and without a certificate per serial number.
The case for keeping it simple
“A factory reset and a drill through the board are enough.” For a home router, perhaps. A drill can miss the memory chips entirely, and a hole in a board gives an auditor nothing to check. What makes disposal defensible is the record: method, serial number, date and who did it.
“Once it is unplugged and the IP is returned, the secrets are dead.” They are not. The partner still trusts the old peer, the address is reassigned to someone else, and a TLS inspection CA works anywhere your laptops trust it. Secrets are revoked at the source, not abandoned at the edge.
“Delete everything, and there is nothing to leak.” GDPR limits how long you keep personal data such as traffic logs. It does not require deleting configuration and change records, and NIS2 and DORA expect you to keep them. Separate the two: purge the logs under your retention policy, keep the technical archive.
Where to go from here
This checklist applies whether the replacement is a new appliance or a cloud platform. If you are still deciding what replaces the old firewall, the thirty-day plan from end of life to SASE covers the replacement side, and the cross-vendor end-of-life tracker shows which devices are next. Two recent examples are FortiOS 7.4 end of support and the Palo Alto PA-220 and PA-800 end of life.
If you want to see what fewer boxes to retire next time looks like, try Jimber free, or book a demo.
Frequently asked questions
How do you decommission a firewall securely?
Work in four phases: map dependencies and notify partners, archive the configuration and audit evidence, revoke all secrets and trust relationships and sanitise the storage, then remove the device from vendor portals, end contracts and dispose of it through a certified partner with a chain of custody.
Does a factory reset delete all data on a firewall?
Not reliably. A factory reset usually replaces the configuration and marks old data as deleted, but flash memory can retain fragments, keys and logs. Treat a vendor reset as a basic clear unless the vendor documents otherwise, and destroy or purge the storage if the device leaves your control.
What is the difference between NIST Clear and Purge?
Clear protects against recovery with standard software tools, for example through overwriting or a logical reset. Purge makes recovery infeasible even with laboratory techniques, for example through cryptographic erase or firmware-level secure erase. Destroy renders the media unusable.
Why must VPN pre-shared keys be changed when a firewall is retired?
Because the trust stays valid on the other side. A partner device keeps the old peer and key until it is removed there. If the key is recovered from the old hardware or the public address is reassigned, an unauthorised tunnel into the partner network becomes possible.
What should happen to the TLS inspection certificate?
Revoke it at the issuing CA and remove it from endpoint trust stores. Anyone holding its private key can issue certificates that company laptops accept for any website, without needing the old firewall or its IP address.
How long should firewall configurations and logs be kept?
Keep configuration, rule and change records for your audit cycle, since NIS2 and DORA expect evidence of asset and change management. Traffic logs contain personal data, so keep them only as long as your retention policy and purpose require under GDPR, in your central log platform, not on the device.
Can we resell or donate an old firewall?
It is rarely worth it. Subscriptions and support are usually tied to the original owner and serial number, and Palo Alto does not recertify end-of-sale or end-of-life hardware at all. The new owner often cannot get security updates, and you remain responsible if data is recovered.
How do you dispose of a firewall in Belgium?
Through the professional collection channels for electrical and electronic equipment coordinated by Recupel, or through a licensed waste collector or certified IT asset disposal partner. Ask for a chain of custody by serial number and a certificate of destruction stating the method used.
Does degaussing work on a firewall?
No. Degaussing affects magnetic media such as spinning hard disks and tapes. Firewalls store data on flash memory, which is not affected by magnetic fields. Use secure erase, cryptographic erase or physical destruction instead.