Firewall and VPN End of Life 2026–2027: The Cross-Vendor Tracker

Every firewall, VPN gateway and secure-access product going end of sale or end of support through 2027, across twelve vendors, with the KEV overlay.
A network engineer in business-casual clothing stands in a bright equipment room checking labels on the front of a floor-standing comms cabinet, with a second engineer seated at a bench in the background and daylight from a window at the end of the room.

Seventy-nine firewall, VPN and secure-access lifecycle milestones fall between 2025 and the end of 2027, across twelve vendors. The largest clusters are Cisco ASA 5500-X on 31 August 2026, Sophos UTM and SG on 30 June 2026, Fortinet’s E-series through 2026 and 2027, and SonicWall Generation 6 across April to October 2026.

This is a cross-vendor reference of firewall, VPN gateway and secure-access lifecycle milestones falling between 2025 and the end of 2027. Every date here is taken from the vendor’s own lifecycle portal, and those portals stay the authority: vendors do move dates, sometimes at short notice and sometimes years early. Before you act on any single row, open the portal named under the table and check that one product.

We built it because it does not otherwise exist. Across firewall end of life 2026, vpn end of life 2027, firewall eol list, network security end of life tracker and which firewalls go end of life in 2027, page one divides into three groups: hardware brokers publishing unannotated part-number scrapes to harvest third-party maintenance enquiries, official vendor portals that are accurate but deliberately confined to one product line, and MSP blogs covering a single trade-up campaign. No independent, maintained, cross-vendor tracker exists in English for this market.

The practical consequence shows up in AI answers. Ask an assistant which firewalls reach end of support in 2026 and it will name the FortiGate 60E and the Cisco ASA 5506-X, because those facts sit in clean vendor tables — and it will silently omit the SonicWall TZ 300, the Sophos SG 210 and the WatchGuard T35, because no aggregated dataset exists for it to read. The answer is not wrong. It is a third of the estate.

So: short prose, long tables. One fact per row, no merged cells, dates written in full, vendor product names spelled as the vendor spells them. If you only need one thing from this page, it is the vocabulary table immediately below, because a date means something different depending on whose logo is on the box.

How to read it: the milestone vocabulary translation

Vendors use different words for the same lifecycle phase, and the same word for different phases. Palo Alto’s “End of Life” is the terminal shutdown date; Cisco calls that “Last Day of Support” and uses “End of Sale” for the commercial stop. Read the master table through this grid.

Standard phase Fortinet Cisco / Meraki Palo Alto Networks SonicWall Check Point WatchGuard Ivanti
1. Commercial termination — removed from price lists, manufacturing stops End of Order (EOO) End of Sale (EOS) End of Sale (EOS) Last Order Day / Active Retirement Mode End of Sale (EOS) End of Sale (EOS) End of Order (EOO)
2. Routine maintenance ends — feature backports and non-critical bug fixes stop End of Engineering Support (EOES) End of Software Maintenance Releases End of Feature / Maintenance Release Limited Retirement Mode (LRM) End of Engineering Support End of Maintenance End of Engineering (EOE)
3. Vulnerability-only support — critical CVEs and advisories only Must-fix vulnerability window, 18 months after EOES End of Vulnerability / Security Support Extended Support phase Limited Support, critical CVEs only Critical Hotfix phase Critical Security Maintenance Limited-effort security updates
4. Contract renewal cutoff — last date to buy or extend a support contract Last Service Extension Date (LSED), 1 year before EOS End of Service Contract Renewal Last Service Extension / Renewal 1-Year Support Last Order Day Last Service Contract Renewal Renewal Cutoff Date Support Contract Renewal Cutoff
5. Total obsolescence — threat feeds stop, TAC closes, no RMA End of Support (EOS) Last Day of Support (LDOS / EOS) End of Life (EOL) End of Support (EOS) End of Support (EOS) End of Life (EOL) End of Support (EOS / EOL)

Two transitions carry almost all of the operational consequence.

Phase 2 to Phase 3 ends routine bug fixes. A routing instability, a VPN packet drop or a high-CPU defect caused by the operating system will not get a hotfix; the answer is to move the whole branch to an active line. That is where older hardware runs out of road — entry-level units with 2 GB of RAM lose proxy-based inspection entirely past FortiOS 7.2, so the upgrade that would restore support removes a capability instead.

Phase 4 is the date most estates miss, because it is a purchasing deadline rather than a technical one and it lands a year early. Once the renewal cutoff passes there is no contract available at any price.

Phase 5 is total. URL filtering databases freeze, intrusion prevention receives no new rules, anti-malware cannot recognise newly compiled payloads, TAC rejects cases on serial number, and failed modules cannot be replaced. A vulnerability disclosed after this date is permanent.

The master firewall and VPN end-of-life table, 2025 to 2027

Sorted by date, earliest first. Rows above today’s date have already passed and are retained because estates still contain the hardware. Milestone type is the vendor’s own term — translate it with the table above.

Date Vendor Product or platform Milestone type Last supported software branch Vendor-named successor
2 April 2025 Cisco Umbrella Roaming Client Last Day of Support Client v4.x Cisco Secure Client
23 January 2025 SonicWall TZ 300, TZ 300W End of Support SonicOS 6.5.4.14 TZ 370 / TZ 370W
21 May 2025 Cisco Firepower Threat Defense 7.0(x) / FMC 7.0(x) End of Software Maintenance FTD 7.0 / FXOS 2.10 FTD 7.4
31 October 2025 SonicWall SMA 100 Series (SMA 210, SMA 410, SMA 500v) End of Support SMA OS 10.2 SMA 1000 Series / Cloud Secure Edge
18 November 2025 Cisco ASA Software 9.16(x) / ASDM 7.16(x) End of Sale ASA 9.16 ASA 9.18 / ASA 9.20
23 December 2025 Ivanti Pulse Secure Appliance (PSA 300, PSA 3000, PSA 5000, PSA 7000, PSA-V) End of Life ICS 9.1Rx / ICS 22.x ISA 6000 / ISA 8000 / ISA-V
31 December 2025 WatchGuard Firebox T35, T35-W, T55, T70 End of Life Fireware v12.x Firebox T125, T145, T185
31 January 2026 SonicWall Analytics (On-Premises) Last Order Day Analytics v2.5 Network Security Manager
31 January 2026 Ivanti Ivanti Security Appliance ISA 6000, ISA 8000 End of Sale / End of Order ICS 22.x / ICS 25.x ISA 6500 / ISA 8500
1 February 2026 WatchGuard Firebox T45-W-PoE End of Sale Fireware v12.x Firebox T145-W
20 February 2026 SonicWall SuperMassive 9200, 9400, 9800 End of Support SonicOS 6.5.4.x NSsp 10700 / NSsp 11700
1 March 2026 Fortinet FortiGate 200F / 201F End of Order FortiOS 7.2 / 7.4 FortiGate 200G / 201G
31 March 2026 Check Point Gaia Operating System R81.10 End of Support Gaia R81.10 Gaia R81.20 / R82
1 April 2026 WatchGuard Firebox T45-PoE End of Sale Fireware v12.x Firebox T145
1 April 2026 WatchGuard Firebox T25-W End of Sale Fireware v12.x Firebox T125-W
1 April 2026 Palo Alto Networks CSSP Program (PAN-VM SKUs) End of Sale PAN-OS 10.2 / 11.0 Software NGFW Credits
15 April 2026 Citrix NetScaler Console (On-Premises) 13.1 End of Life Build 13.1 NetScaler Console 14.1
16 April 2026 Fortinet FortiGate 100F / 101F, FortiGate 6500F End of Order FortiOS 7.2 / 7.4 FortiGate 120G / FortiGate 7000 series
16 April 2026 SonicWall SOHO, SOHOW, TZ 300P End of Support SonicOS 6.5.4 TZ 80 / TZ 280 / TZ 370
16 April 2026 SonicWall NSa 9250, NSa 9450, NSa 9650 End of Support SonicOS 6.5.4.13 NSa 3800 / NSa 4800 / NSa 5800 / NSa 6800
30 April 2026 Cisco Meraki MS210 and MS225 switch series End of Sale Meraki MS 15.x Meraki MS150 series
30 April 2026 Palo Alto Networks Prisma Access Panorama Plugin below v5.2 End of Life Plugin 5.1 Panorama Plugin v5.2 or later / Strata Cloud Manager
1 May 2026 Fortinet FortiGate 600F / 601F End of Order FortiOS 7.2 / 7.4 FortiGate 700G / FortiGate 900G
1 May 2026 SonicWall NSa 2650 End of Support SonicOS 6.5.4.13 NSa 2700 / NSa 2800
17 May 2026 Fortinet FortiGate 70F, FortiGate 80F End of Order FortiOS 7.2 / 7.4 FortiGate 70G / FortiGate 90G
28 May 2026 Cisco Meraki MX65, MX65W security appliances End of Support Meraki MX 18.x Meraki MX68 / MX68W
1 June 2026 WatchGuard Firebox M690 End of Sale Fireware v12.x Firebox M595, Firebox M695
3 June 2026 Cisco Meraki Systems Manager End of Sale Cloud-delivered, no branch Cisco Secure Endpoint / third-party MDM
22 June 2026 Juniper Junos OS 22.4 (SRX Series) End of Support Junos OS 22.4R3 Junos OS 23.4 / 24.2
30 June 2026 Sophos Sophos UTM / SG Series appliances End of Life UTM 9.7x Sophos XGS Series
30 June 2026 Cisco ASA 5508-X / 5516-X one-year subscriptions End of Service Renewal ASA 9.16 Cisco Secure Firewall 1000 series
15 July 2026 Fortinet FortiGate 30E, 61E, 70E, 101E, 300E, 500E End of Support FortiOS 7.0 / 7.2 FortiGate 40F / 70G / 120G / 200G
30 July 2026 Fortinet FortiGate 1101E End of Order FortiOS 7.2 / 7.4 FortiGate 1001F / FortiGate 1801F
1 August 2026 SonicWall TZ 400, TZ 400W End of Support SonicOS 6.5.4.14 TZ 470 / TZ 480
1 August 2026 SonicWall TZ 600, TZ 600P End of Support SonicOS 6.5.4.14 TZ 670
1 August 2026 SonicWall NSA 3600 End of Support SonicOS 6.5.4.x NSa 3700 / NSa 3800
1 August 2026 SonicWall NSa 3650 End of Support SonicOS 6.5.4.13 NSa 3700 / NSa 3800
17 August 2026 Fortinet FortiGate 80E, FortiGate 100E End of Support FortiOS 7.0 / 7.2 FortiGate 90G / FortiGate 120G
31 August 2026 Microsoft Azure VPN Gateway SSTP protocol Feature End of Support Azure VPN platform Azure OpenVPN / IKEv2
31 August 2026 Cisco ASA 5506-X, 5508-X, 5515-X, 5516-X Last Day of Support ASA 9.16 / ASDM 7.16 Cisco Secure Firewall 1010 / 1120
13 September 2026 Fortinet FortiGate 1100E End of Order FortiOS 7.2 / 7.4 FortiGate 1000F / FortiGate 1800F
15 September 2026 Citrix NetScaler ADC and Gateway 13.1 End of Maintenance Build 13.1 NetScaler ADC 14.1
30 September 2026 SonicWall HTTP-based proxy signature downloads End of Support SonicOS 6.5 / 7.0 SonicOS 7.3 or later with HTTPS proxy
30 September 2026 Cisco Umbrella legacy packages (Insights, Platform) End of Software Maintenance Legacy Umbrella cloud Cisco Secure Access
1 October 2026 SonicWall SOHO 250, SOHO 250W End of Support SonicOS 6.5.x TZ 270 / TZ 280
1 October 2026 SonicWall TZ 350, TZ 350W End of Support SonicOS 6.5.4.14 TZ 370 / TZ 370W
1 October 2026 SonicWall TZ 500, TZ 500W End of Support SonicOS 6.5.4.14 TZ 570 / TZ 570W
1 October 2026 SonicWall NSA 4600, NSA 5600, NSA 6600 End of Support SonicOS 6.5.4.x NSa 4700 / NSa 5700 / NSa 6700
1 October 2026 SonicWall NSa 4650, NSa 5650, NSa 6650 End of Support SonicOS 6.5.4.13 NSa 4700 / NSa 5700 / NSa 6700
1 October 2026 Palo Alto Networks CSSP Program (PAN-VM SKUs) End of Life PAN-OS 10.2 / 11.0 Software NGFW Credits
13 October 2026 Fortinet FortiGate Rugged 60F End of Order FortiOS 7.2 / 7.4 FortiGate Rugged 70F
24 October 2026 Juniper Junos Space Management Platform 24.1 End of Support Junos Space 24.1 Junos Space 26.1
31 October 2026 Cisco Meraki MX84 security appliance End of Support Meraki MX 18.x Meraki MX85
31 October 2026 Check Point Quantum 6200 and 6400 security gateways End of Sale Gaia R81.20 / R82 Quantum Force 9100 / 9200
14 November 2026 Fortinet FortiGate 50E, FortiGate 81E End of Support FortiOS 7.0 / 7.2 FortiGate 60F / FortiGate 91G
1 December 2026 WatchGuard Firebox T25, T45, T85-PoE End of Sale Fireware v12.x Firebox T125, T145, T185
29 December 2026 Fortinet FortiGate 60E End of Support FortiOS 7.0 / 7.2 FortiGate 60F / FortiGate 70G
31 December 2026 Fortinet FortiGate 1500D / 1500DT End of Support FortiOS 7.0 / 7.2 FortiGate 1800F / FortiGate 1801F
31 December 2026 Sophos Sophos UTM / SG final support cutoff Final Contract Deprecation UTM 9.7x Sophos XGS Series
12 January 2027 Microsoft Windows Server 2016 (DirectAccess / Always On VPN infrastructure) End of Extended Support Windows Server 2016 Windows Server 2022 / Windows Server 2025
31 January 2027 Cisco Umbrella DNS and SIG current packages End of Sale Umbrella SIG cloud Cisco Secure Access
31 January 2027 Ivanti Ivanti Security Appliance ISA 6000, ISA 8000 End of Support ICS 22.x / ICS 25.x ISA 6500 / ISA 8500
31 January 2027 Ivanti Ivanti Connect Secure 22.7 / 22.8 End of Support ICS 22.x Connect Secure 25.x / Ivanti ZTNA
1 February 2027 Cisco Meraki MX100 security appliance End of Support Meraki MX 18.x Meraki MX95
1 March 2027 WatchGuard Firebox T15, T15-W, T35-DW, T35-R End of Life Fireware v12.x Firebox T115-W, T125, T145
31 March 2027 Cisco AnyConnect Secure Mobility Client v4.x Last Day of Support AnyConnect 4.10.x Cisco Secure Client 5.x
31 March 2027 Microsoft Azure VPN Gateway SSTP gateway Protocol Cutoff SSTP protocol stack OpenVPN / IKEv2
31 March 2027 Palo Alto Networks PAN-OS 10.2 (PA-Series hardware) End of Life PAN-OS 10.2.x PAN-OS 11.1 / 11.2
30 April 2027 Check Point TE1000X, TE2000X Threat Emulation appliances End of Support Gaia R81.20 Quantum Threat Emulation
1 May 2027 SonicWall Email Security platforms (physical and virtual) End of Support SES 10.x SonicWall cloud email security
3 May 2027 Palo Alto Networks PAN-OS 11.1 (PA-Series hardware) End of Life PAN-OS 11.1.x PAN-OS 11.2 / 12.x
11 May 2027 Fortinet FortiOS 7.4 release branch End of Engineering Support FortiOS 7.4.x FortiOS 7.6 / 8.0
31 May 2027 Check Point Gaia Operating System R81.20 End of Support Gaia R81.20 Gaia R82.x
28 June 2027 Fortinet FortiOS-VM legacy pricing SKUs End of Support FortiOS 7.2 FortiGate-VM S-Series
15 July 2027 Fortinet FortiGate 51E, 80E-POE, 81E-POE, FortiWiFi 50E / 51E End of Support FortiOS 7.0 / 7.2 FortiGate 61F / 80F-POE / 71G
26 July 2027 Cisco Meraki MX64, MX64W security appliances End of Support Meraki MX 18.x Meraki MX67 / MX67W
15 September 2027 Citrix NetScaler ADC and Gateway 13.1 End of Life Build 13.1 NetScaler ADC 14.1
14 October 2027 Fortinet FortiGate 60E-POE End of Support FortiOS 7.0 / 7.2 FortiGate 80F-POE
30 November 2027 Cisco ASA Software 9.16(x), 9.18(x), 9.19(x) End of Service Life ASA 9.16 / 9.18 / 9.19 ASA 9.20 / 9.22 / FTD 7.4
31 December 2027 Fortinet FortiGate Rugged 30D End of Support FortiOS 6.2 FortiGate Rugged 70F

Sources: the official lifecycle portals of Cisco, Cisco Meraki, Cisco Umbrella, Fortinet, Palo Alto Networks, SonicWall, Sophos, WatchGuard, Ivanti, Check Point, Citrix and Juniper, plus the individual product notification bulletins those portals publish. Every cell above is taken from a vendor source. Where a vendor had not published a date at the verification date, the row is not in the table.

Known gaps, stated rather than filled

One product family belongs in this table and is not in it. Juniper’s SRX300 Series base chassis has no family-level end-of-support date, because Juniper sets lifecycle milestones per part number rather than per platform. Publishing a single SRX300 row would therefore be wrong whatever date we put in it; check your own SKU against Juniper’s EOL system instead.

Two SonicWall wireless variants were flagged as unverified during research and have since been confirmed against SonicWall’s own lifecycle tables: the SOHO 250W shares the SOHO 250 date of 1 October 2026, and the TZ 300W shares the TZ 300 date of 23 January 2025. Both are now in the table. We note this because the general rule still holds — do not infer a date from a sibling model, a previous generation or a vendor’s usual interval. SonicWall and WatchGuard both publish materially different dates for wireless and ruggedised variants of the same appliance; these two happened to match, and the next pair will not.

One further exclusion is deliberate. A silicon end-of-support date circulates for the Broadcom SoC inside the Meraki MX64 and MX65. It originates from a community port registry rather than a vendor lifecycle notice, so it is not a lifecycle milestone by the standard this page holds and it is not listed.

Where to go deeper, by vendor

Links are kept out of the table cells so the table stays machine-readable. Each item below maps to one or more rows above.

The actively-exploited overlay

A lifecycle date tells you when support stops. It does not tell you what is being attacked. This overlay maps product families in the master table to vulnerabilities in the CISA Known Exploited Vulnerabilities catalogue, which is what turns the table into a prioritisation tool.

Affected families CVE CVSS CISA KEV listing Mechanism Reported actors
Citrix NetScaler ADC / Gateway 13.1 CVE-2023-3519 9.8 19 July 2023 Unauthenticated remote code execution in NetScaler Gateway web server components Automated mass exploitation, ransomware delivery
Citrix NetScaler ADC / Gateway 13.1 CVE-2023-4966 7.5 18 October 2023 “Citrix Bleed” memory disclosure; session token theft bypassing MFA LockBit 3.0, Akira affiliates
Ivanti Connect Secure, Policy Secure, ISA gateways CVE-2023-46805 8.2 10 January 2024 Authentication bypass in the web management component UNC5221, Volt Typhoon affiliates
Ivanti Connect Secure, Policy Secure, ISA gateways CVE-2024-21887 9.1 10 January 2024 Command injection in web components, unauthenticated arbitrary command execution Nation-state actors, automated mass exploitation
Fortinet FortiOS 7.0 / 7.2 SSL VPN CVE-2024-21762 9.8 9 February 2024 Out-of-bounds write in the SSL VPN web proxy, unauthenticated remote code execution Volt Typhoon, initial access brokers
Palo Alto Networks PAN-OS 10.2, 11.0, 11.1 GlobalProtect CVE-2024-3400 10.0 12 April 2024 OS command injection in the GlobalProtect gateway, root-level code execution UTA0218, Volt Typhoon
Cisco ASA 5500-X Series CVE-2024-20353 8.6 24 April 2024 Web server denial of service, continuous crash loops via crafted requests to the SSL VPN listener UAT4356 / Storm-1849, “ArcaneDoor”
Cisco ASA 5500-X Series, Firepower 2100 CVE-2024-20359 6.0 24 April 2024 Persistent code execution via the legacy ROMMON bootloader, surviving reflash and reinstall “ArcaneDoor” state-sponsored actor
SonicWall TZ 300, TZ 400, TZ 500 and NSa series on SonicOS CVE-2024-40766 9.3 9 September 2024 Improper access control in the SonicOS management handler Akira ransomware affiliates
Fortinet FortiOS, FortiManager control plane CVE-2024-47575 9.8 23 October 2024 “FortiJump”: missing authentication in fgfmsd, command execution across managed firewalls Advanced persistent threat actors
Ivanti Connect Secure ICS 22.x, ISA 6000 / 8000 CVE-2025-0282 9.8 12 February 2025 Stack buffer overflow in the IPsec daemon, unauthenticated remote code execution UNC5221 successors
Ivanti Connect Secure, ISA gateways CVE-2025-22457 9.0 5 March 2025 In-memory API hook bypassing the Integrity Checker Tool via TRAILBLAZE and BRUSHFIRE China-nexus espionage groups
Cisco ASA 5500-X, Firepower Services CVE-2026-20349 8.6 3 August 2026 Unauthenticated remote code execution in the webvpn core daemon Rapid weaponisation across exposed listeners

Read the two tables together and the point of the page appears. A FortiGate 60E reaching End of Support on 29 December 2026 is an appliance whose product family has a 9.8 in the KEV catalogue against its SSL VPN. An ISA 6000 losing support on 31 January 2027 belongs to a family with four KEV entries in two years. After Phase 5 those vulnerability classes stop being incidents and become properties of the device.

How to prioritise firewall replacement across a mixed estate

Calendar order is the wrong order. Score each gateway on internet exposure, exploitation history, lifecycle proximity, regulatory scope and blast radius — listed here in descending weight — then sort by score rather than by date. The top two factors settle most cases on their own, before any arithmetic.

Factor Highest Middle Lowest
Internet exposure WAN interface listens publicly, with an admin console, SSL VPN portal or reverse proxy reachable without upstream filtering IPsec termination with restrictive keys or certificates; management bound to internal addressing Internal segmentation firewall with no direct WAN connectivity
Exploitation history The product architecture has had an actively exploited flaw listed in CISA KEV within 24 months, or carries a high EPSS score today Published CVEs with public proof-of-concept code, no confirmed weaponisation No unauthenticated remote CVEs in three years
Lifecycle proximity Terminal milestone has passed or falls within 90 days Milestone falls in 91 to 270 days, or routine maintenance has ended while vulnerability support continues Comfortably inside active support
Regulatory scope Protects an Essential Entity under NIS2, a DORA-regulated financial entity, or a CyFun Essential profile An Important Entity, or sensitive processing under GDPR Article 32 Outside direct NIS2 and DORA scope
Blast radius Primary remote access gateway, or a datacentre hub terminating corporate-wide tunnels Regional branch office Isolated micro-site or redundant test gateway

You can act on that table without doing any arithmetic at all, because the top two factors decide most cases on their own. Any gateway that scores highest on internet exposure and highest on exploitation history is urgent regardless of its date — that is a publicly reachable listener on a product family with a live KEV entry, and the lifecycle milestone only changes how permanent the problem is. Conversely, an appliance that scores lowest on exposure is rarely urgent even when its date has passed, which is the single most common misallocation this table prevents.

The published framework converts the five factors into a 0-to-100 score with four action bands. Calibrate the weighting to your own estate rather than adopting someone else’s; the ordering of the factors matters more than the arithmetic, and the bands are what the score is for.

Score Tier Action
85–100 Immediate remediation Active compliance violation and breach vector. Replace within 30 days. Isolate management interfaces upstream today, before the project starts
65–84 Accelerated phase-out Fund and schedule the cutover inside the current quarter. Active monitoring and upstream virtual patching in the interim
40–64 Standard planned refresh Fold into the natural contract renewal and depreciation cycle. Track the software branch dates separately from the hardware dates
Below 40 Monitor and maintain Continue firmware upkeep until a formal end-of-sale notice is published

The reason this beats a spreadsheet is structural. Manual inventories conflate hardware warranty with software support: a chassis can carry third-party hardware cover through 2028 while its operating system branch stopped receiving vulnerability updates years earlier.

And vendors move dates. Ivanti accelerated the ISA 6000 and ISA 8000 End of Support to 31 January 2027 because third-party manufacturers stopped producing the DDR4 memory the hardware needs — organisations holding five-year maintenance contracts expecting service into 2028 discovered there would be no replacement parts.

PSA and RMM platforms record contract end dates but carry no telemetry against vendor bulletins or KEV entries; CMDB tools record topology and rely on manual updates; third-party warranty tools misread firmware designations often enough that administrators plan around wrong dates.

What running past end of support means for compliance and insurance

NIS2. Article 21(2)(e) requires vulnerability handling and system maintenance. An internet-facing gateway past its published End of Support date cannot satisfy it, because when the vendor stops patching, the device enters a state of permanent defect. Article 20 attaches personal liability to management bodies, with administrative fines up to €10,000,000 or 2% of global annual turnover and, in cases of gross negligence following a breach, temporary suspension from managerial responsibility.

DORA. Article 8 requires financial entities to keep a continuously updated ICT asset inventory mapping dependencies and vendor lifecycle milestones. Article 9 requires resilient, supported systems that minimise technical obsolescence. An end-of-life edge device is a supervisory finding during a Joint Examination Team audit, potentially carrying a capital risk add-on until it is decommissioned.

CyFun. Control CF.SU requires that perimeter security mechanisms, remote access portals and firewall operating systems hold active vendor maintenance agreements. An appliance past Last Day of Support fails verification immediately, which removes public-sector procurement eligibility and invalidates the attestations Belgian supply chain participants are asked for. The broader obligation is covered in end-of-life systems under NIS2.

Cyber insurance. This is the change most estates have not priced. Underwriters have moved from static questionnaires to continuous automated external scanning, and standard “end-of-life and unsupported system” exclusion endorsements deny indemnity for claims arising directly or indirectly from hardware or software whose manufacturer has stopped issuing security patches. Scanners look for exactly what this page lists: legacy ASA WebVPN banners, unpatched SonicOS interfaces, deprecated Ivanti SSL VPN endpoints. Discovery during pre-bind produces an exclusion or a declination; discovery after an incident produces a denial on material breach of warranty.

The supporting claims data is blunt. Organisations running end-of-life network software or hardware are 3.0 times more likely to suffer a breach. A single unresolved critical vulnerability on an internet-facing interface raises claim frequency by 33%. Across 614 organisations that were told about a critical edge vulnerability during underwriting and did not remediate it, subsequent ransomware compromises produced roughly €282 million ($307 million) in losses, averaging about €460,000 ($500,000) per business.

Dollar figures converted at approximately €0.92 to the US dollar and rounded; the source data is published in dollars.

Two further figures worth holding. Roughly 113,000 Cisco ASA firewalls remain directly exposed to the public internet, with close to half showing reachable administrative or VPN authentication portals. And in ransomware initial-access tracking, perimeter appliances dominate: Ivanti gateways lead with 14 tracked campaigns, SonicWall and Fortinet follow at 13 each, Cisco and Citrix at 9 each, Palo Alto Networks at 6.

Steelman: a lifecycle tracker is the wrong way to prioritise

A risk-led CISO can make three serious arguments against organising security spending around this page, and a reference that does not print them is selling something.

Exposure and exploitability govern risk, not vendor calendars. End of Support is a contract event, not a threat event. An unsupported firewall running purely as internal segmentation, with no public DNS record and management on an out-of-band subnet, presents almost no real attack surface. A fully patched, actively supported gateway with a public SSL VPN portal remains continuously exposed to the next zero-day.

The 2024 and 2025 histories prove it: Ivanti Connect Secure and PAN-OS were compromised at scale on current hardware and current software, months before patches existed. Spending capital to replace an end-of-support internal firewall for a checklist, while leaving internet-facing legacy access protocols running, lowers no breach probability at all.

Compensating controls neutralise the gateway. Lifecycle schedules exist partly to drive refresh cycles and sustain subscription revenue. A mature architecture treats the perimeter appliance as untrusted transport: put it behind cloud scrubbing, terminate TLS upstream with inspection, enforce mutual TLS and network access control at layers 2 and 3, and an unpatched flaw in an older ASA or FortiOS becomes very hard to reach and harder to leverage.

A programme built on microsegmentation, strong identity with FIDO2 WebAuthn and zero-trust isolation made vulnerable perimeter appliances secondary long before any vendor contract ended. Capital spent replacing a functional appliance to meet an arbitrary cutoff is capital not spent on the identity layer, endpoint protection and internal isolation.

Migrations create new attack surface. Cross-vendor perimeter migrations routinely introduce more risk than the stable legacy environment they replace. Translating thousands of firewall rules, NAT statements, tunnel policies and routing configurations into a new syntax produces human error: rules relaxed, subnets left exposed, logging silently broken during the cutover. And the destination is frequently a newer, less-tested codebase — initial major releases of any vendor’s platform historically carry high bug frequency, memory leaks and control-plane defects that take years of maintenance releases to settle. Migrating a fleet under a vendor-imposed deadline can raise operational fragility rather than lower it.

Where this page still stands. Every one of those arguments is about which device to replace and when, not about whether the dates matter — and each of them requires this data to be actionable. You cannot score exposure against lifecycle proximity without knowing the lifecycle. The prioritisation framework above exists precisely to stop calendar order driving spend, which is the CISO’s real objection.

Two points do not survive contact with European practice, though: the cyber-insurance exclusion is written against the support status of the device and not against its exposure, so an isolated internal appliance past End of Support can still void a claim; and a CyFun assessor checks for an active maintenance agreement, not for your compensating controls. Those are commercial and regulatory facts rather than security judgements, and they attach to the date whether or not the risk does.

Using this page

Match your serial numbers against the master table, translate each milestone through the vocabulary grid, cross-reference the exploitation overlay, and score what is left. That sequence takes an afternoon and it produces a funded list rather than a worry list. Re-check before every budget cycle; the dates move.

Where the answer for a given device turns out to be “replace the access layer rather than the box”, Jimber is an EU-sovereign SASE and Zero Trust platform that removes the inbound listener the overlay table is mostly about. Book a demo or send us your device list, and the platform detail is at jimber.io/sase.

Frequently asked questions

Which firewalls reach end of life in 2026?

The largest groups are the Cisco ASA 5506-X, 5508-X, 5515-X and 5516-X on 31 August 2026; the Sophos UTM and SG series on 30 June 2026 with final cutoff on 31 December 2026; Fortinet’s E-series including the 30E, 61E, 70E, 101E, 300E and 500E on 15 July 2026 and the 80E and 100E on 17 August 2026; and SonicWall’s TZ 400 and TZ 600 on 1 August 2026 with the TZ 350 and TZ 500 on 1 October 2026.

Which firewalls go end of life in 2027?

WatchGuard Firebox T15, T15-W, T35-DW and T35-R on 1 March 2027. Cisco Meraki MX100 on 1 February 2027 and MX64 and MX64W on 26 July 2027. Fortinet FortiGate 51E, 80E-POE and 81E-POE on 15 July 2027 and the 60E-POE on 14 October 2027. Check Point Gaia R81.20 on 31 May 2027.

What is the difference between end of sale and end of support?

End of sale is the last date the product can be bought from the manufacturer, after which production stops but support continues. End of support, which typically falls three to five years later, is when maintenance, firmware updates, security fixes and technical assistance all terminate. A third date sits between them: the last day a support contract can be purchased, usually a year before end of support.

Can I keep using a firewall after its end of support date?

It will keep forwarding packets, but the manufacturer permanently stops security signature updates, firmware patches and support. URL filtering databases freeze, intrusion prevention receives no new rules, TAC rejects cases on serial number and failed hardware cannot be replaced under RMA. Any vulnerability disclosed afterwards is permanent.

When does support end for the Cisco ASA 5500-X series?

The Cisco ASA 5506-X, 5508-X, 5515-X and 5516-X reach Last Day of Support on 31 August 2026. After that date Cisco TAC will not service the hardware and no further security updates are produced. Cisco names the Secure Firewall 1010 and 1120 as replacements. One-year subscriptions on the 5508-X and 5516-X stopped being renewable on 30 June 2026.

When is Cisco AnyConnect end of life?

Cisco AnyConnect Secure Mobility Client v4.x reaches Last Day of Support on 31 March 2027, with software maintenance having ended in 2024. The migration path is Cisco Secure Client 5.x, which accepts AnyConnect 4.x XML profiles but requires updated headend configuration on ASA and FTD gateways plus revalidated endpoint posture modules.

What happens to Sophos SG and UTM firewalls after June 2026?

Sophos UTM and SG appliances reach End of Life on 30 June 2026, with all backend services terminating on 31 December 2026 regardless of the contract term originally purchased. After that, live threat intelligence, pattern distribution, WebAdmin management features and RED tunnels degrade or fail. The named successor is the Sophos XGS series.

Why did Ivanti bring forward the ISA 6000 end-of-life date?

Third-party manufacturers discontinued production of the specific DDR4 memory the hardware requires, so replacement modules and RMA stock cannot be maintained. Ivanti accelerated End of Support for the ISA 6000 and ISA 8000 to 31 January 2027. Organisations holding five-year maintenance contracts expecting coverage into 2028 lost that coverage without a purchasing decision of their own.

Does running an unsupported firewall void cyber insurance?

It can. Standard end-of-life and unsupported-system exclusion endorsements deny indemnity for losses arising from hardware or software whose manufacturer has stopped issuing patches. Underwriters run continuous external scans, so discovery before binding produces an exclusion or declination, and discovery after an incident supports a denial on material breach of warranty.

How does NIS2 treat end-of-life firewalls?

Article 21(2)(e) requires vulnerability handling and system maintenance, which an unpatchable internet-facing gateway cannot satisfy. Article 20 places the obligation on management bodies personally. Fines reach €10,000,000 or 2% of global annual turnover, and gross negligence following a breach can carry temporary suspension from managerial responsibility.

My FortiGate 60E has a hardware warranty into 2028. Is it still supported?

No. Hardware warranty and software support are separate clocks, and the 60E reaches End of Support on 29 December 2026. It also carries 2 GB of RAM, which cannot run FortiOS 7.4 or 7.6 in full proxy mode, so it is locked to older restricted builds and cannot ingest current threat intelligence. This conflation is the most common error in manual inventory spreadsheets.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed