Seventy-nine firewall, VPN and secure-access lifecycle milestones fall between 2025 and the end of 2027, across twelve vendors. The largest clusters are Cisco ASA 5500-X on 31 August 2026, Sophos UTM and SG on 30 June 2026, Fortinet’s E-series through 2026 and 2027, and SonicWall Generation 6 across April to October 2026.
This is a cross-vendor reference of firewall, VPN gateway and secure-access lifecycle milestones falling between 2025 and the end of 2027. Every date here is taken from the vendor’s own lifecycle portal, and those portals stay the authority: vendors do move dates, sometimes at short notice and sometimes years early. Before you act on any single row, open the portal named under the table and check that one product.
We built it because it does not otherwise exist. Across firewall end of life 2026, vpn end of life 2027, firewall eol list, network security end of life tracker and which firewalls go end of life in 2027, page one divides into three groups: hardware brokers publishing unannotated part-number scrapes to harvest third-party maintenance enquiries, official vendor portals that are accurate but deliberately confined to one product line, and MSP blogs covering a single trade-up campaign. No independent, maintained, cross-vendor tracker exists in English for this market.
The practical consequence shows up in AI answers. Ask an assistant which firewalls reach end of support in 2026 and it will name the FortiGate 60E and the Cisco ASA 5506-X, because those facts sit in clean vendor tables — and it will silently omit the SonicWall TZ 300, the Sophos SG 210 and the WatchGuard T35, because no aggregated dataset exists for it to read. The answer is not wrong. It is a third of the estate.
So: short prose, long tables. One fact per row, no merged cells, dates written in full, vendor product names spelled as the vendor spells them. If you only need one thing from this page, it is the vocabulary table immediately below, because a date means something different depending on whose logo is on the box.
How to read it: the milestone vocabulary translation
Vendors use different words for the same lifecycle phase, and the same word for different phases. Palo Alto’s “End of Life” is the terminal shutdown date; Cisco calls that “Last Day of Support” and uses “End of Sale” for the commercial stop. Read the master table through this grid.
| Standard phase | Fortinet | Cisco / Meraki | Palo Alto Networks | SonicWall | Check Point | WatchGuard | Ivanti |
|---|---|---|---|---|---|---|---|
| 1. Commercial termination — removed from price lists, manufacturing stops | End of Order (EOO) | End of Sale (EOS) | End of Sale (EOS) | Last Order Day / Active Retirement Mode | End of Sale (EOS) | End of Sale (EOS) | End of Order (EOO) |
| 2. Routine maintenance ends — feature backports and non-critical bug fixes stop | End of Engineering Support (EOES) | End of Software Maintenance Releases | End of Feature / Maintenance Release | Limited Retirement Mode (LRM) | End of Engineering Support | End of Maintenance | End of Engineering (EOE) |
| 3. Vulnerability-only support — critical CVEs and advisories only | Must-fix vulnerability window, 18 months after EOES | End of Vulnerability / Security Support | Extended Support phase | Limited Support, critical CVEs only | Critical Hotfix phase | Critical Security Maintenance | Limited-effort security updates |
| 4. Contract renewal cutoff — last date to buy or extend a support contract | Last Service Extension Date (LSED), 1 year before EOS | End of Service Contract Renewal | Last Service Extension / Renewal | 1-Year Support Last Order Day | Last Service Contract Renewal | Renewal Cutoff Date | Support Contract Renewal Cutoff |
| 5. Total obsolescence — threat feeds stop, TAC closes, no RMA | End of Support (EOS) | Last Day of Support (LDOS / EOS) | End of Life (EOL) | End of Support (EOS) | End of Support (EOS) | End of Life (EOL) | End of Support (EOS / EOL) |
Two transitions carry almost all of the operational consequence.
Phase 2 to Phase 3 ends routine bug fixes. A routing instability, a VPN packet drop or a high-CPU defect caused by the operating system will not get a hotfix; the answer is to move the whole branch to an active line. That is where older hardware runs out of road — entry-level units with 2 GB of RAM lose proxy-based inspection entirely past FortiOS 7.2, so the upgrade that would restore support removes a capability instead.
Phase 4 is the date most estates miss, because it is a purchasing deadline rather than a technical one and it lands a year early. Once the renewal cutoff passes there is no contract available at any price.
Phase 5 is total. URL filtering databases freeze, intrusion prevention receives no new rules, anti-malware cannot recognise newly compiled payloads, TAC rejects cases on serial number, and failed modules cannot be replaced. A vulnerability disclosed after this date is permanent.
The master firewall and VPN end-of-life table, 2025 to 2027
Sorted by date, earliest first. Rows above today’s date have already passed and are retained because estates still contain the hardware. Milestone type is the vendor’s own term — translate it with the table above.
| Date | Vendor | Product or platform | Milestone type | Last supported software branch | Vendor-named successor |
|---|---|---|---|---|---|
| 2 April 2025 | Cisco | Umbrella Roaming Client | Last Day of Support | Client v4.x | Cisco Secure Client |
| 23 January 2025 | SonicWall | TZ 300, TZ 300W | End of Support | SonicOS 6.5.4.14 | TZ 370 / TZ 370W |
| 21 May 2025 | Cisco | Firepower Threat Defense 7.0(x) / FMC 7.0(x) | End of Software Maintenance | FTD 7.0 / FXOS 2.10 | FTD 7.4 |
| 31 October 2025 | SonicWall | SMA 100 Series (SMA 210, SMA 410, SMA 500v) | End of Support | SMA OS 10.2 | SMA 1000 Series / Cloud Secure Edge |
| 18 November 2025 | Cisco | ASA Software 9.16(x) / ASDM 7.16(x) | End of Sale | ASA 9.16 | ASA 9.18 / ASA 9.20 |
| 23 December 2025 | Ivanti | Pulse Secure Appliance (PSA 300, PSA 3000, PSA 5000, PSA 7000, PSA-V) | End of Life | ICS 9.1Rx / ICS 22.x | ISA 6000 / ISA 8000 / ISA-V |
| 31 December 2025 | WatchGuard | Firebox T35, T35-W, T55, T70 | End of Life | Fireware v12.x | Firebox T125, T145, T185 |
| 31 January 2026 | SonicWall | Analytics (On-Premises) | Last Order Day | Analytics v2.5 | Network Security Manager |
| 31 January 2026 | Ivanti | Ivanti Security Appliance ISA 6000, ISA 8000 | End of Sale / End of Order | ICS 22.x / ICS 25.x | ISA 6500 / ISA 8500 |
| 1 February 2026 | WatchGuard | Firebox T45-W-PoE | End of Sale | Fireware v12.x | Firebox T145-W |
| 20 February 2026 | SonicWall | SuperMassive 9200, 9400, 9800 | End of Support | SonicOS 6.5.4.x | NSsp 10700 / NSsp 11700 |
| 1 March 2026 | Fortinet | FortiGate 200F / 201F | End of Order | FortiOS 7.2 / 7.4 | FortiGate 200G / 201G |
| 31 March 2026 | Check Point | Gaia Operating System R81.10 | End of Support | Gaia R81.10 | Gaia R81.20 / R82 |
| 1 April 2026 | WatchGuard | Firebox T45-PoE | End of Sale | Fireware v12.x | Firebox T145 |
| 1 April 2026 | WatchGuard | Firebox T25-W | End of Sale | Fireware v12.x | Firebox T125-W |
| 1 April 2026 | Palo Alto Networks | CSSP Program (PAN-VM SKUs) | End of Sale | PAN-OS 10.2 / 11.0 | Software NGFW Credits |
| 15 April 2026 | Citrix | NetScaler Console (On-Premises) 13.1 | End of Life | Build 13.1 | NetScaler Console 14.1 |
| 16 April 2026 | Fortinet | FortiGate 100F / 101F, FortiGate 6500F | End of Order | FortiOS 7.2 / 7.4 | FortiGate 120G / FortiGate 7000 series |
| 16 April 2026 | SonicWall | SOHO, SOHOW, TZ 300P | End of Support | SonicOS 6.5.4 | TZ 80 / TZ 280 / TZ 370 |
| 16 April 2026 | SonicWall | NSa 9250, NSa 9450, NSa 9650 | End of Support | SonicOS 6.5.4.13 | NSa 3800 / NSa 4800 / NSa 5800 / NSa 6800 |
| 30 April 2026 | Cisco | Meraki MS210 and MS225 switch series | End of Sale | Meraki MS 15.x | Meraki MS150 series |
| 30 April 2026 | Palo Alto Networks | Prisma Access Panorama Plugin below v5.2 | End of Life | Plugin 5.1 | Panorama Plugin v5.2 or later / Strata Cloud Manager |
| 1 May 2026 | Fortinet | FortiGate 600F / 601F | End of Order | FortiOS 7.2 / 7.4 | FortiGate 700G / FortiGate 900G |
| 1 May 2026 | SonicWall | NSa 2650 | End of Support | SonicOS 6.5.4.13 | NSa 2700 / NSa 2800 |
| 17 May 2026 | Fortinet | FortiGate 70F, FortiGate 80F | End of Order | FortiOS 7.2 / 7.4 | FortiGate 70G / FortiGate 90G |
| 28 May 2026 | Cisco | Meraki MX65, MX65W security appliances | End of Support | Meraki MX 18.x | Meraki MX68 / MX68W |
| 1 June 2026 | WatchGuard | Firebox M690 | End of Sale | Fireware v12.x | Firebox M595, Firebox M695 |
| 3 June 2026 | Cisco | Meraki Systems Manager | End of Sale | Cloud-delivered, no branch | Cisco Secure Endpoint / third-party MDM |
| 22 June 2026 | Juniper | Junos OS 22.4 (SRX Series) | End of Support | Junos OS 22.4R3 | Junos OS 23.4 / 24.2 |
| 30 June 2026 | Sophos | Sophos UTM / SG Series appliances | End of Life | UTM 9.7x | Sophos XGS Series |
| 30 June 2026 | Cisco | ASA 5508-X / 5516-X one-year subscriptions | End of Service Renewal | ASA 9.16 | Cisco Secure Firewall 1000 series |
| 15 July 2026 | Fortinet | FortiGate 30E, 61E, 70E, 101E, 300E, 500E | End of Support | FortiOS 7.0 / 7.2 | FortiGate 40F / 70G / 120G / 200G |
| 30 July 2026 | Fortinet | FortiGate 1101E | End of Order | FortiOS 7.2 / 7.4 | FortiGate 1001F / FortiGate 1801F |
| 1 August 2026 | SonicWall | TZ 400, TZ 400W | End of Support | SonicOS 6.5.4.14 | TZ 470 / TZ 480 |
| 1 August 2026 | SonicWall | TZ 600, TZ 600P | End of Support | SonicOS 6.5.4.14 | TZ 670 |
| 1 August 2026 | SonicWall | NSA 3600 | End of Support | SonicOS 6.5.4.x | NSa 3700 / NSa 3800 |
| 1 August 2026 | SonicWall | NSa 3650 | End of Support | SonicOS 6.5.4.13 | NSa 3700 / NSa 3800 |
| 17 August 2026 | Fortinet | FortiGate 80E, FortiGate 100E | End of Support | FortiOS 7.0 / 7.2 | FortiGate 90G / FortiGate 120G |
| 31 August 2026 | Microsoft | Azure VPN Gateway SSTP protocol | Feature End of Support | Azure VPN platform | Azure OpenVPN / IKEv2 |
| 31 August 2026 | Cisco | ASA 5506-X, 5508-X, 5515-X, 5516-X | Last Day of Support | ASA 9.16 / ASDM 7.16 | Cisco Secure Firewall 1010 / 1120 |
| 13 September 2026 | Fortinet | FortiGate 1100E | End of Order | FortiOS 7.2 / 7.4 | FortiGate 1000F / FortiGate 1800F |
| 15 September 2026 | Citrix | NetScaler ADC and Gateway 13.1 | End of Maintenance | Build 13.1 | NetScaler ADC 14.1 |
| 30 September 2026 | SonicWall | HTTP-based proxy signature downloads | End of Support | SonicOS 6.5 / 7.0 | SonicOS 7.3 or later with HTTPS proxy |
| 30 September 2026 | Cisco | Umbrella legacy packages (Insights, Platform) | End of Software Maintenance | Legacy Umbrella cloud | Cisco Secure Access |
| 1 October 2026 | SonicWall | SOHO 250, SOHO 250W | End of Support | SonicOS 6.5.x | TZ 270 / TZ 280 |
| 1 October 2026 | SonicWall | TZ 350, TZ 350W | End of Support | SonicOS 6.5.4.14 | TZ 370 / TZ 370W |
| 1 October 2026 | SonicWall | TZ 500, TZ 500W | End of Support | SonicOS 6.5.4.14 | TZ 570 / TZ 570W |
| 1 October 2026 | SonicWall | NSA 4600, NSA 5600, NSA 6600 | End of Support | SonicOS 6.5.4.x | NSa 4700 / NSa 5700 / NSa 6700 |
| 1 October 2026 | SonicWall | NSa 4650, NSa 5650, NSa 6650 | End of Support | SonicOS 6.5.4.13 | NSa 4700 / NSa 5700 / NSa 6700 |
| 1 October 2026 | Palo Alto Networks | CSSP Program (PAN-VM SKUs) | End of Life | PAN-OS 10.2 / 11.0 | Software NGFW Credits |
| 13 October 2026 | Fortinet | FortiGate Rugged 60F | End of Order | FortiOS 7.2 / 7.4 | FortiGate Rugged 70F |
| 24 October 2026 | Juniper | Junos Space Management Platform 24.1 | End of Support | Junos Space 24.1 | Junos Space 26.1 |
| 31 October 2026 | Cisco | Meraki MX84 security appliance | End of Support | Meraki MX 18.x | Meraki MX85 |
| 31 October 2026 | Check Point | Quantum 6200 and 6400 security gateways | End of Sale | Gaia R81.20 / R82 | Quantum Force 9100 / 9200 |
| 14 November 2026 | Fortinet | FortiGate 50E, FortiGate 81E | End of Support | FortiOS 7.0 / 7.2 | FortiGate 60F / FortiGate 91G |
| 1 December 2026 | WatchGuard | Firebox T25, T45, T85-PoE | End of Sale | Fireware v12.x | Firebox T125, T145, T185 |
| 29 December 2026 | Fortinet | FortiGate 60E | End of Support | FortiOS 7.0 / 7.2 | FortiGate 60F / FortiGate 70G |
| 31 December 2026 | Fortinet | FortiGate 1500D / 1500DT | End of Support | FortiOS 7.0 / 7.2 | FortiGate 1800F / FortiGate 1801F |
| 31 December 2026 | Sophos | Sophos UTM / SG final support cutoff | Final Contract Deprecation | UTM 9.7x | Sophos XGS Series |
| 12 January 2027 | Microsoft | Windows Server 2016 (DirectAccess / Always On VPN infrastructure) | End of Extended Support | Windows Server 2016 | Windows Server 2022 / Windows Server 2025 |
| 31 January 2027 | Cisco | Umbrella DNS and SIG current packages | End of Sale | Umbrella SIG cloud | Cisco Secure Access |
| 31 January 2027 | Ivanti | Ivanti Security Appliance ISA 6000, ISA 8000 | End of Support | ICS 22.x / ICS 25.x | ISA 6500 / ISA 8500 |
| 31 January 2027 | Ivanti | Ivanti Connect Secure 22.7 / 22.8 | End of Support | ICS 22.x | Connect Secure 25.x / Ivanti ZTNA |
| 1 February 2027 | Cisco | Meraki MX100 security appliance | End of Support | Meraki MX 18.x | Meraki MX95 |
| 1 March 2027 | WatchGuard | Firebox T15, T15-W, T35-DW, T35-R | End of Life | Fireware v12.x | Firebox T115-W, T125, T145 |
| 31 March 2027 | Cisco | AnyConnect Secure Mobility Client v4.x | Last Day of Support | AnyConnect 4.10.x | Cisco Secure Client 5.x |
| 31 March 2027 | Microsoft | Azure VPN Gateway SSTP gateway | Protocol Cutoff | SSTP protocol stack | OpenVPN / IKEv2 |
| 31 March 2027 | Palo Alto Networks | PAN-OS 10.2 (PA-Series hardware) | End of Life | PAN-OS 10.2.x | PAN-OS 11.1 / 11.2 |
| 30 April 2027 | Check Point | TE1000X, TE2000X Threat Emulation appliances | End of Support | Gaia R81.20 | Quantum Threat Emulation |
| 1 May 2027 | SonicWall | Email Security platforms (physical and virtual) | End of Support | SES 10.x | SonicWall cloud email security |
| 3 May 2027 | Palo Alto Networks | PAN-OS 11.1 (PA-Series hardware) | End of Life | PAN-OS 11.1.x | PAN-OS 11.2 / 12.x |
| 11 May 2027 | Fortinet | FortiOS 7.4 release branch | End of Engineering Support | FortiOS 7.4.x | FortiOS 7.6 / 8.0 |
| 31 May 2027 | Check Point | Gaia Operating System R81.20 | End of Support | Gaia R81.20 | Gaia R82.x |
| 28 June 2027 | Fortinet | FortiOS-VM legacy pricing SKUs | End of Support | FortiOS 7.2 | FortiGate-VM S-Series |
| 15 July 2027 | Fortinet | FortiGate 51E, 80E-POE, 81E-POE, FortiWiFi 50E / 51E | End of Support | FortiOS 7.0 / 7.2 | FortiGate 61F / 80F-POE / 71G |
| 26 July 2027 | Cisco | Meraki MX64, MX64W security appliances | End of Support | Meraki MX 18.x | Meraki MX67 / MX67W |
| 15 September 2027 | Citrix | NetScaler ADC and Gateway 13.1 | End of Life | Build 13.1 | NetScaler ADC 14.1 |
| 14 October 2027 | Fortinet | FortiGate 60E-POE | End of Support | FortiOS 7.0 / 7.2 | FortiGate 80F-POE |
| 30 November 2027 | Cisco | ASA Software 9.16(x), 9.18(x), 9.19(x) | End of Service Life | ASA 9.16 / 9.18 / 9.19 | ASA 9.20 / 9.22 / FTD 7.4 |
| 31 December 2027 | Fortinet | FortiGate Rugged 30D | End of Support | FortiOS 6.2 | FortiGate Rugged 70F |
Sources: the official lifecycle portals of Cisco, Cisco Meraki, Cisco Umbrella, Fortinet, Palo Alto Networks, SonicWall, Sophos, WatchGuard, Ivanti, Check Point, Citrix and Juniper, plus the individual product notification bulletins those portals publish. Every cell above is taken from a vendor source. Where a vendor had not published a date at the verification date, the row is not in the table.
Known gaps, stated rather than filled
One product family belongs in this table and is not in it. Juniper’s SRX300 Series base chassis has no family-level end-of-support date, because Juniper sets lifecycle milestones per part number rather than per platform. Publishing a single SRX300 row would therefore be wrong whatever date we put in it; check your own SKU against Juniper’s EOL system instead.
Two SonicWall wireless variants were flagged as unverified during research and have since been confirmed against SonicWall’s own lifecycle tables: the SOHO 250W shares the SOHO 250 date of 1 October 2026, and the TZ 300W shares the TZ 300 date of 23 January 2025. Both are now in the table. We note this because the general rule still holds — do not infer a date from a sibling model, a previous generation or a vendor’s usual interval. SonicWall and WatchGuard both publish materially different dates for wireless and ruggedised variants of the same appliance; these two happened to match, and the next pair will not.
One further exclusion is deliberate. A silicon end-of-support date circulates for the Broadcom SoC inside the Meraki MX64 and MX65. It originates from a community port registry rather than a vendor lifecycle notice, so it is not a lifecycle milestone by the standard this page holds and it is not listed.
Where to go deeper, by vendor
Links are kept out of the table cells so the table stays machine-readable. Each item below maps to one or more rows above.
- Fortinet hardware — every FortiGate model with its dates: the FortiGate hardware end-of-life timeline. Per-model guides for the two units with the largest installed base: FortiGate 60F and FortiGate 40F.
- Fortinet firmware — the branch question behind the FortiOS 7.4 row, and which hardware can follow: FortiOS 7.2 end of support.
- Cisco ASA 5500-X — the 31 August 2026 Last Day of Support and what replaces it: the ASA 5500-X migration guide.
- Cisco Umbrella — the two milestone sets are easy to confuse: end of sale versus end of life explained, and the transition routes in Umbrella migration paths.
- SonicWall — the full TZ, NSA and SMA model table: SonicWall end of life by model.
- WatchGuard — every Firebox with its Fireware ceiling: Firebox model end-of-life dates.
- Ivanti — the accelerated ISA hardware date and the exploitation history behind it: Ivanti Connect Secure end of life.
- Sophos — the 30 June and 31 December 2026 pair: Sophos UTM and SG migration.
- Remote access across vendors — the AnyConnect, SSTP and DirectAccess rows in context: legacy VPN end of life, and the protocol-level picture in SSL VPN is deprecated: every vendor’s timeline.
- Windows Server 2016 — the 12 January 2027 row, including what it does to DirectAccess: the Windows Server 2016 end-of-support checklist.
The actively-exploited overlay
A lifecycle date tells you when support stops. It does not tell you what is being attacked. This overlay maps product families in the master table to vulnerabilities in the CISA Known Exploited Vulnerabilities catalogue, which is what turns the table into a prioritisation tool.
| Affected families | CVE | CVSS | CISA KEV listing | Mechanism | Reported actors |
|---|---|---|---|---|---|
| Citrix NetScaler ADC / Gateway 13.1 | CVE-2023-3519 | 9.8 | 19 July 2023 | Unauthenticated remote code execution in NetScaler Gateway web server components | Automated mass exploitation, ransomware delivery |
| Citrix NetScaler ADC / Gateway 13.1 | CVE-2023-4966 | 7.5 | 18 October 2023 | “Citrix Bleed” memory disclosure; session token theft bypassing MFA | LockBit 3.0, Akira affiliates |
| Ivanti Connect Secure, Policy Secure, ISA gateways | CVE-2023-46805 | 8.2 | 10 January 2024 | Authentication bypass in the web management component | UNC5221, Volt Typhoon affiliates |
| Ivanti Connect Secure, Policy Secure, ISA gateways | CVE-2024-21887 | 9.1 | 10 January 2024 | Command injection in web components, unauthenticated arbitrary command execution | Nation-state actors, automated mass exploitation |
| Fortinet FortiOS 7.0 / 7.2 SSL VPN | CVE-2024-21762 | 9.8 | 9 February 2024 | Out-of-bounds write in the SSL VPN web proxy, unauthenticated remote code execution | Volt Typhoon, initial access brokers |
| Palo Alto Networks PAN-OS 10.2, 11.0, 11.1 GlobalProtect | CVE-2024-3400 | 10.0 | 12 April 2024 | OS command injection in the GlobalProtect gateway, root-level code execution | UTA0218, Volt Typhoon |
| Cisco ASA 5500-X Series | CVE-2024-20353 | 8.6 | 24 April 2024 | Web server denial of service, continuous crash loops via crafted requests to the SSL VPN listener | UAT4356 / Storm-1849, “ArcaneDoor” |
| Cisco ASA 5500-X Series, Firepower 2100 | CVE-2024-20359 | 6.0 | 24 April 2024 | Persistent code execution via the legacy ROMMON bootloader, surviving reflash and reinstall | “ArcaneDoor” state-sponsored actor |
| SonicWall TZ 300, TZ 400, TZ 500 and NSa series on SonicOS | CVE-2024-40766 | 9.3 | 9 September 2024 | Improper access control in the SonicOS management handler | Akira ransomware affiliates |
| Fortinet FortiOS, FortiManager control plane | CVE-2024-47575 | 9.8 | 23 October 2024 | “FortiJump”: missing authentication in fgfmsd, command execution across managed firewalls | Advanced persistent threat actors |
| Ivanti Connect Secure ICS 22.x, ISA 6000 / 8000 | CVE-2025-0282 | 9.8 | 12 February 2025 | Stack buffer overflow in the IPsec daemon, unauthenticated remote code execution | UNC5221 successors |
| Ivanti Connect Secure, ISA gateways | CVE-2025-22457 | 9.0 | 5 March 2025 | In-memory API hook bypassing the Integrity Checker Tool via TRAILBLAZE and BRUSHFIRE | China-nexus espionage groups |
| Cisco ASA 5500-X, Firepower Services | CVE-2026-20349 | 8.6 | 3 August 2026 | Unauthenticated remote code execution in the webvpn core daemon | Rapid weaponisation across exposed listeners |
Read the two tables together and the point of the page appears. A FortiGate 60E reaching End of Support on 29 December 2026 is an appliance whose product family has a 9.8 in the KEV catalogue against its SSL VPN. An ISA 6000 losing support on 31 January 2027 belongs to a family with four KEV entries in two years. After Phase 5 those vulnerability classes stop being incidents and become properties of the device.
How to prioritise firewall replacement across a mixed estate
Calendar order is the wrong order. Score each gateway on internet exposure, exploitation history, lifecycle proximity, regulatory scope and blast radius — listed here in descending weight — then sort by score rather than by date. The top two factors settle most cases on their own, before any arithmetic.
| Factor | Highest | Middle | Lowest |
|---|---|---|---|
| Internet exposure | WAN interface listens publicly, with an admin console, SSL VPN portal or reverse proxy reachable without upstream filtering | IPsec termination with restrictive keys or certificates; management bound to internal addressing | Internal segmentation firewall with no direct WAN connectivity |
| Exploitation history | The product architecture has had an actively exploited flaw listed in CISA KEV within 24 months, or carries a high EPSS score today | Published CVEs with public proof-of-concept code, no confirmed weaponisation | No unauthenticated remote CVEs in three years |
| Lifecycle proximity | Terminal milestone has passed or falls within 90 days | Milestone falls in 91 to 270 days, or routine maintenance has ended while vulnerability support continues | Comfortably inside active support |
| Regulatory scope | Protects an Essential Entity under NIS2, a DORA-regulated financial entity, or a CyFun Essential profile | An Important Entity, or sensitive processing under GDPR Article 32 | Outside direct NIS2 and DORA scope |
| Blast radius | Primary remote access gateway, or a datacentre hub terminating corporate-wide tunnels | Regional branch office | Isolated micro-site or redundant test gateway |
You can act on that table without doing any arithmetic at all, because the top two factors decide most cases on their own. Any gateway that scores highest on internet exposure and highest on exploitation history is urgent regardless of its date — that is a publicly reachable listener on a product family with a live KEV entry, and the lifecycle milestone only changes how permanent the problem is. Conversely, an appliance that scores lowest on exposure is rarely urgent even when its date has passed, which is the single most common misallocation this table prevents.
The published framework converts the five factors into a 0-to-100 score with four action bands. Calibrate the weighting to your own estate rather than adopting someone else’s; the ordering of the factors matters more than the arithmetic, and the bands are what the score is for.
| Score | Tier | Action |
|---|---|---|
| 85–100 | Immediate remediation | Active compliance violation and breach vector. Replace within 30 days. Isolate management interfaces upstream today, before the project starts |
| 65–84 | Accelerated phase-out | Fund and schedule the cutover inside the current quarter. Active monitoring and upstream virtual patching in the interim |
| 40–64 | Standard planned refresh | Fold into the natural contract renewal and depreciation cycle. Track the software branch dates separately from the hardware dates |
| Below 40 | Monitor and maintain | Continue firmware upkeep until a formal end-of-sale notice is published |
The reason this beats a spreadsheet is structural. Manual inventories conflate hardware warranty with software support: a chassis can carry third-party hardware cover through 2028 while its operating system branch stopped receiving vulnerability updates years earlier.
And vendors move dates. Ivanti accelerated the ISA 6000 and ISA 8000 End of Support to 31 January 2027 because third-party manufacturers stopped producing the DDR4 memory the hardware needs — organisations holding five-year maintenance contracts expecting service into 2028 discovered there would be no replacement parts.
PSA and RMM platforms record contract end dates but carry no telemetry against vendor bulletins or KEV entries; CMDB tools record topology and rely on manual updates; third-party warranty tools misread firmware designations often enough that administrators plan around wrong dates.
What running past end of support means for compliance and insurance
NIS2. Article 21(2)(e) requires vulnerability handling and system maintenance. An internet-facing gateway past its published End of Support date cannot satisfy it, because when the vendor stops patching, the device enters a state of permanent defect. Article 20 attaches personal liability to management bodies, with administrative fines up to €10,000,000 or 2% of global annual turnover and, in cases of gross negligence following a breach, temporary suspension from managerial responsibility.
DORA. Article 8 requires financial entities to keep a continuously updated ICT asset inventory mapping dependencies and vendor lifecycle milestones. Article 9 requires resilient, supported systems that minimise technical obsolescence. An end-of-life edge device is a supervisory finding during a Joint Examination Team audit, potentially carrying a capital risk add-on until it is decommissioned.
CyFun. Control CF.SU requires that perimeter security mechanisms, remote access portals and firewall operating systems hold active vendor maintenance agreements. An appliance past Last Day of Support fails verification immediately, which removes public-sector procurement eligibility and invalidates the attestations Belgian supply chain participants are asked for. The broader obligation is covered in end-of-life systems under NIS2.
Cyber insurance. This is the change most estates have not priced. Underwriters have moved from static questionnaires to continuous automated external scanning, and standard “end-of-life and unsupported system” exclusion endorsements deny indemnity for claims arising directly or indirectly from hardware or software whose manufacturer has stopped issuing security patches. Scanners look for exactly what this page lists: legacy ASA WebVPN banners, unpatched SonicOS interfaces, deprecated Ivanti SSL VPN endpoints. Discovery during pre-bind produces an exclusion or a declination; discovery after an incident produces a denial on material breach of warranty.
The supporting claims data is blunt. Organisations running end-of-life network software or hardware are 3.0 times more likely to suffer a breach. A single unresolved critical vulnerability on an internet-facing interface raises claim frequency by 33%. Across 614 organisations that were told about a critical edge vulnerability during underwriting and did not remediate it, subsequent ransomware compromises produced roughly €282 million ($307 million) in losses, averaging about €460,000 ($500,000) per business.
Dollar figures converted at approximately €0.92 to the US dollar and rounded; the source data is published in dollars.
Two further figures worth holding. Roughly 113,000 Cisco ASA firewalls remain directly exposed to the public internet, with close to half showing reachable administrative or VPN authentication portals. And in ransomware initial-access tracking, perimeter appliances dominate: Ivanti gateways lead with 14 tracked campaigns, SonicWall and Fortinet follow at 13 each, Cisco and Citrix at 9 each, Palo Alto Networks at 6.
Steelman: a lifecycle tracker is the wrong way to prioritise
A risk-led CISO can make three serious arguments against organising security spending around this page, and a reference that does not print them is selling something.
Exposure and exploitability govern risk, not vendor calendars. End of Support is a contract event, not a threat event. An unsupported firewall running purely as internal segmentation, with no public DNS record and management on an out-of-band subnet, presents almost no real attack surface. A fully patched, actively supported gateway with a public SSL VPN portal remains continuously exposed to the next zero-day.
The 2024 and 2025 histories prove it: Ivanti Connect Secure and PAN-OS were compromised at scale on current hardware and current software, months before patches existed. Spending capital to replace an end-of-support internal firewall for a checklist, while leaving internet-facing legacy access protocols running, lowers no breach probability at all.
Compensating controls neutralise the gateway. Lifecycle schedules exist partly to drive refresh cycles and sustain subscription revenue. A mature architecture treats the perimeter appliance as untrusted transport: put it behind cloud scrubbing, terminate TLS upstream with inspection, enforce mutual TLS and network access control at layers 2 and 3, and an unpatched flaw in an older ASA or FortiOS becomes very hard to reach and harder to leverage.
A programme built on microsegmentation, strong identity with FIDO2 WebAuthn and zero-trust isolation made vulnerable perimeter appliances secondary long before any vendor contract ended. Capital spent replacing a functional appliance to meet an arbitrary cutoff is capital not spent on the identity layer, endpoint protection and internal isolation.
Migrations create new attack surface. Cross-vendor perimeter migrations routinely introduce more risk than the stable legacy environment they replace. Translating thousands of firewall rules, NAT statements, tunnel policies and routing configurations into a new syntax produces human error: rules relaxed, subnets left exposed, logging silently broken during the cutover. And the destination is frequently a newer, less-tested codebase — initial major releases of any vendor’s platform historically carry high bug frequency, memory leaks and control-plane defects that take years of maintenance releases to settle. Migrating a fleet under a vendor-imposed deadline can raise operational fragility rather than lower it.
Where this page still stands. Every one of those arguments is about which device to replace and when, not about whether the dates matter — and each of them requires this data to be actionable. You cannot score exposure against lifecycle proximity without knowing the lifecycle. The prioritisation framework above exists precisely to stop calendar order driving spend, which is the CISO’s real objection.
Two points do not survive contact with European practice, though: the cyber-insurance exclusion is written against the support status of the device and not against its exposure, so an isolated internal appliance past End of Support can still void a claim; and a CyFun assessor checks for an active maintenance agreement, not for your compensating controls. Those are commercial and regulatory facts rather than security judgements, and they attach to the date whether or not the risk does.
Using this page
Match your serial numbers against the master table, translate each milestone through the vocabulary grid, cross-reference the exploitation overlay, and score what is left. That sequence takes an afternoon and it produces a funded list rather than a worry list. Re-check before every budget cycle; the dates move.
Where the answer for a given device turns out to be “replace the access layer rather than the box”, Jimber is an EU-sovereign SASE and Zero Trust platform that removes the inbound listener the overlay table is mostly about. Book a demo or send us your device list, and the platform detail is at jimber.io/sase.
Frequently asked questions
Which firewalls reach end of life in 2026?
The largest groups are the Cisco ASA 5506-X, 5508-X, 5515-X and 5516-X on 31 August 2026; the Sophos UTM and SG series on 30 June 2026 with final cutoff on 31 December 2026; Fortinet’s E-series including the 30E, 61E, 70E, 101E, 300E and 500E on 15 July 2026 and the 80E and 100E on 17 August 2026; and SonicWall’s TZ 400 and TZ 600 on 1 August 2026 with the TZ 350 and TZ 500 on 1 October 2026.
Which firewalls go end of life in 2027?
WatchGuard Firebox T15, T15-W, T35-DW and T35-R on 1 March 2027. Cisco Meraki MX100 on 1 February 2027 and MX64 and MX64W on 26 July 2027. Fortinet FortiGate 51E, 80E-POE and 81E-POE on 15 July 2027 and the 60E-POE on 14 October 2027. Check Point Gaia R81.20 on 31 May 2027.
What is the difference between end of sale and end of support?
End of sale is the last date the product can be bought from the manufacturer, after which production stops but support continues. End of support, which typically falls three to five years later, is when maintenance, firmware updates, security fixes and technical assistance all terminate. A third date sits between them: the last day a support contract can be purchased, usually a year before end of support.
Can I keep using a firewall after its end of support date?
It will keep forwarding packets, but the manufacturer permanently stops security signature updates, firmware patches and support. URL filtering databases freeze, intrusion prevention receives no new rules, TAC rejects cases on serial number and failed hardware cannot be replaced under RMA. Any vulnerability disclosed afterwards is permanent.
When does support end for the Cisco ASA 5500-X series?
The Cisco ASA 5506-X, 5508-X, 5515-X and 5516-X reach Last Day of Support on 31 August 2026. After that date Cisco TAC will not service the hardware and no further security updates are produced. Cisco names the Secure Firewall 1010 and 1120 as replacements. One-year subscriptions on the 5508-X and 5516-X stopped being renewable on 30 June 2026.
When is Cisco AnyConnect end of life?
Cisco AnyConnect Secure Mobility Client v4.x reaches Last Day of Support on 31 March 2027, with software maintenance having ended in 2024. The migration path is Cisco Secure Client 5.x, which accepts AnyConnect 4.x XML profiles but requires updated headend configuration on ASA and FTD gateways plus revalidated endpoint posture modules.
What happens to Sophos SG and UTM firewalls after June 2026?
Sophos UTM and SG appliances reach End of Life on 30 June 2026, with all backend services terminating on 31 December 2026 regardless of the contract term originally purchased. After that, live threat intelligence, pattern distribution, WebAdmin management features and RED tunnels degrade or fail. The named successor is the Sophos XGS series.
Why did Ivanti bring forward the ISA 6000 end-of-life date?
Third-party manufacturers discontinued production of the specific DDR4 memory the hardware requires, so replacement modules and RMA stock cannot be maintained. Ivanti accelerated End of Support for the ISA 6000 and ISA 8000 to 31 January 2027. Organisations holding five-year maintenance contracts expecting coverage into 2028 lost that coverage without a purchasing decision of their own.
Does running an unsupported firewall void cyber insurance?
It can. Standard end-of-life and unsupported-system exclusion endorsements deny indemnity for losses arising from hardware or software whose manufacturer has stopped issuing patches. Underwriters run continuous external scans, so discovery before binding produces an exclusion or declination, and discovery after an incident supports a denial on material breach of warranty.
How does NIS2 treat end-of-life firewalls?
Article 21(2)(e) requires vulnerability handling and system maintenance, which an unpatchable internet-facing gateway cannot satisfy. Article 20 places the obligation on management bodies personally. Fines reach €10,000,000 or 2% of global annual turnover, and gross negligence following a breach can carry temporary suspension from managerial responsibility.
My FortiGate 60E has a hardware warranty into 2028. Is it still supported?
No. Hardware warranty and software support are separate clocks, and the 60E reaches End of Support on 29 December 2026. It also carries 2 GB of RAM, which cannot run FortiOS 7.4 or 7.6 in full proxy mode, so it is locked to older restricted builds and cannot ingest current threat intelligence. This conflation is the most common error in manual inventory spreadsheets.