The base FortiGate 40F is not end of life. Fortinet has not announced an End of Order date for the desktop model, and it is still in active production. Two variants have moved, though: the cellular 40F-3G4G passed End of Order on 13 August 2025 with support running to 13 August 2030, and the FortiWiFi 40F passed End of Order on 1 May 2026 with support to 1 May 2031.
So the dates are not your problem. The successor choice is. Your distributor will quote the FortiGate 50G, because it sits at the same price point and the naming suggests continuity. The 50G has 2GB of RAM, exactly like the 40F, and no SSL-VPN server at all. Nobody has published the comparison that actually decides this purchase, so that is what the middle of this article is.
What each Fortinet milestone stops
Fortinet runs four milestones and the gaps between them are long, which is why reseller pressure and manufacturer reality often disagree by years.
- End-of-Life Announcement. Advance notice. Nothing changes.
- End of Order, also called End of Sale. Last date to buy through authorised channels. Manufacturing stops. Everything you own keeps working with full support.
- Last Service Extension Date. Falls 48 months after End of Order, twelve months before the end. This is the final opportunity to extend or renew a FortiCare or FortiGuard contract. Miss it and you cannot buy support for that unit again, even though support has not technically ended.
- End of Support, also called End of Service Life. Sixty months after End of Order. Technical assistance, firmware security patches, dynamic threat feeds and hardware replacement all terminate.
The one that catches people is the Last Service Extension Date, because it is silent. Nothing fails on that day; you simply lose the ability to keep the unit covered for its final year.
FortiGate 40F family lifecycle
Last verified: September 2026.
| Model | EOL announcement | End of Order | Last Service Extension | End of Support | Status |
|---|---|---|---|---|---|
| FortiGate 40F (base desktop) | Not announced | Not announced | Not published | Not published | Active production |
| FortiWiFi 40F | 31 Jan 2026 | 1 May 2026 | 1 May 2030 | 1 May 2031 | End of Order reached |
| FortiGate 40F-3G4G | 15 May 2025 | 13 Aug 2025 | 13 Aug 2029 | 13 Aug 2030 | End of Order reached |
| FortiWiFi 40F-3G4G | 15 May 2025 | 13 Aug 2025 | 13 Aug 2029 | 13 Aug 2030 | End of Order reached |
Source: Fortinet’s Product Life Cycle portal, which requires a support login. Verify there before acting on any date. Two notes on reading this table. The base 40F rows say “not published” rather than a projected date: because no End of Order has been announced, the 48-month and 60-month milestones have nothing to count from, and any specific year you see quoted elsewhere is arithmetic rather than a Fortinet commitment. And there is no FortiGate 40F-POE. It was never released as a SKU, so if a reseller is quoting you a lifecycle date for one, something is wrong with the quote.
This is also where most of the confusion in the market comes from. Lifecycle aggregators scrape these tables and routinely apply the cellular or wireless variant dates to the whole family, which is why AI summaries for this query sometimes state that the 40F reached End of Sale in 2025 or 2026. It did not. The base desktop unit is still orderable.
The real clock is FortiOS, not the hardware
Hardware support running to roughly 2031 sounds comfortable until you look at what the software has already removed from 2GB appliances.
| FortiOS branch | End of Engineering Support | End of Support | What it means on a 2GB unit like the 40F |
|---|---|---|---|
| 7.2 | 31 Mar 2025 | 30 Sep 2026 | Full feature set, but PSIRT security fixes stop at the end of this month |
| 7.4 | 11 May 2027 | 11 Nov 2028 | From 7.4.4, proxy-based inspection is disabled on 2GB models |
| 7.6 | 25 Jul 2028 | 25 Jan 2030 | SSL-VPN server daemon removed entirely, tunnel and web mode; Security Fabric root function removed; downstream authorisations capped at five devices |
| 8.0 | 21 Apr 2029 | 21 Oct 2030 | Impractical: baseline system daemons consume 70% to 75% of available RAM before any inspected user traffic |
Read that top row again if you are still on 7.2. End of Support is 30 September 2026, which is seventeen days from publication. After that the branch receives no further security fixes. We covered the version lifecycle and the upgrade path per hardware generation in the FortiOS 7.2 end-of-support guide, and the hardware dates for every other model in the FortiGate hardware timeline.
50G or 70G: the comparison your distributor will not send you
| Specification | FortiGate 40F | FortiGate 50G | FortiGate 70G |
|---|---|---|---|
| Security processor | SOC4 (NP6xlite + CP9lite) | SP5 | SP5 |
| System memory | 2GB | 2GB | 4GB |
| Firewall throughput (UDP 1518 / 512 / 64B) | 5 / 5 / 5 Gbps | 5 / 5 / 4 Gbps | 10 / 10 / 10 Gbps |
| Packets per second | 7.5 Mpps | 6.0 Mpps | 14.8 Mpps |
| IPS throughput (Enterprise Traffic Mix) | 1.0 Gbps | 2.25 Gbps | 2.5 Gbps |
| NGFW throughput (Enterprise Traffic Mix) | 800 Mbps | 1.25 Gbps | 1.5 Gbps |
| Threat Protection (full Enterprise Mix) | 600 Mbps | 1.1 Gbps | 1.3 Gbps |
| SSL inspection (IPS, average HTTPS) | 310 Mbps | 1.3 Gbps | 1.4 Gbps |
| SSL inspection concurrent sessions | 55,000 | 74,000 | 140,000 |
| IPsec VPN throughput (512B) | 4.4 Gbps | 4.5 Gbps | 7.1 Gbps |
| Concurrent TCP sessions | 700,000 | 720,000 | 1,400,000 |
| New sessions per second | 35,000 | 85,000 | 100,000 |
| Physical interfaces | 5x GE (1 WAN, 1 FortiLink, 3 LAN) | 5x GE (1 WAN, 1 FortiLink, 3 LAN) | 10x GE (2 WAN, 2 FortiLink, 6 LAN) |
| SSL-VPN server | Present in 7.2, removed in 7.6 | Never supported | Present in 7.2, removed from 7.4.8 |
| Power draw (average / max) | 7.74W / 9.46W | 8.3W / 8.9W | 12.3W / 12.8W |
Each figure comes from Fortinet’s published datasheets under its own test methodology, and the methodologies are not interchangeable. Firewall throughput is UDP at fixed frame sizes under RFC 2544. IPS throughput uses an Enterprise Traffic Mix under continuous inline attack traffic. NGFW runs firewall, IPS and Application Control in parallel. Threat Protection adds Advanced Malware Protection and full session logging. SSL inspection is decrypted HTTPS with IPS applied to the payload. Comparing a 5 Gbps firewall number against a 600 Mbps Threat Protection number is the single most common sizing error in this class of appliance, and it is how a 40F ends up on a 1 Gbps circuit.
The row that decides the purchase is memory. The 50G moves to the SP5 processor and roughly doubles inspected throughput on paper, and it keeps 2GB of RAM. That is the same constraint that produced conserve mode on the 40F, on the same firmware branches that will be current for the next five years.
The sizing rule
| Parameter | 50G is enough | 70G is required | Why |
|---|---|---|---|
| Concurrent users | 1 to 10 | 15 or more | 2GB RAM hits conserve mode during session surges |
| Sustained WAN bandwidth | Under 600 Mbps inspected | 600 Mbps to 1 Gbps symmetrical | TLS 1.3 handshakes saturate CPU on encrypted streams |
| Inspection profile | Flow-based AV, DNS, Application Control | Deep SSL/TLS inspection plus IPS plus ISDB | 2GB models drop proxy features and hit memory limits |
| WAN resilience | Single uplink | Dual active WAN | The 50G has to sacrifice a LAN port to get a second WAN |
| Remote access | Site-to-site IPsec backhaul only | Local ZTNA or FortiClient IPsec termination | The 50G has no SSL-VPN server at all |
Stated as a rule: the 50G is a spoke-site appliance for under ten people with inspection handled somewhere else. Anything above roughly fifteen users, a gigabit circuit, local deep inspection or a second WAN link needs the 70G.
Three mechanics sit underneath that. First, decryption and circuit saturation. The 40F does 600 Mbps Threat Protection and 310 Mbps SSL inspection, so on a symmetrical gigabit fibre line it throttles inspected traffic by roughly 40% to 70%. The 50G looks much better on paper, but with mixed payload sizes and bidirectional IPsec running alongside deep inspection it approaches its compute ceiling somewhere around 600 to 700 Mbps of real traffic. The 70G handles a full gigabit with deep packet inspection on.
Second, the memory arithmetic. On a 2GB unit under FortiOS 7.4, 7.6 or 8.0, the core daemons — wad, ipsengine, miglogd — take 1.3GB to 1.5GB just holding routing and session tables. Automated FortiGuard signature and Internet Service Database updates spike memory by 10% to 20%. On an appliance already sitting at a 68% to 72% baseline, that update breaches the default 88% conserve threshold and the unit enters conserve mode, which drops new connections, stops session logging or passes traffic uninspected depending on your fail mode. The usual workaround is disabling IPS acceleration from the CLI with set cp-accel-mode none, which trades inspection efficiency for stability. The 70G’s 4GB sits at a 35% to 42% baseline and has room for the update.
Third, ports and user density. A modern knowledge worker running SaaS, a browser and unified communications holds roughly 80 to 120 concurrent TCP connections. Fifteen to twenty users is 4,000 to 6,000 active flows, which the 50G routes fine at Layer 4 and struggles to inspect. And the 50G’s five ports are one WAN, one FortiLink and three LAN. A dual-homed branch has to convert a LAN port into a second WAN, leaving two ports for everything local. The 70G gives you two dedicated WAN ports, two FortiLink and six internal, which is enough for SD-WAN across two providers plus a server and an access point without adding a switch.
What it costs, and what staying costs
European reseller listings, excluding VAT, recorded in early 2026. These are reseller prices, not Fortinet list prices, and they move.
| Model | Hardware only | 1-year UTP bundle | 3-year UTP bundle | 5-year UTP bundle | 1-year renewal |
|---|---|---|---|---|---|
| FortiGate 40F (installed base) | €410 – €440 | Legacy SKU | Legacy SKU | Legacy SKU | €380 – €420 |
| FortiGate 50G | €935 | €1,560 | €1,950 | €2,450 | €625 |
| FortiGate 50G-5G | €2,030 | €3,060 | €3,980 | €4,950 | €1,030 |
| FortiGate 70G | €1,330 | €1,796 | €2,420 | €3,210 | €466 (ATP) / €881 (EP) |
| FortiGate 71G (onboard storage) | €1,550 | €2,120 | €2,890 | €3,780 | €570 / €1,050 |
| FortiWiFi 70G | €1,760 | €2,390 | €3,250 | €4,290 | €630 / €1,180 |
Three-year positions per site: keeping the 40F on annual UTP renewals is roughly €1,140 to €1,260. A 50G with a three-year bundle is about €1,950. A 70G with a three-year bundle is about €2,420.
The number worth putting in front of whoever signs the purchase order is the delta. Over three years the 70G costs about €470 more per branch than the 50G, which is roughly €13 per site per month. Across forty sites that is €78,000 versus €96,800. For that difference you get twice the RAM, ten ports instead of five, native dual WAN, and you stop inheriting the constraint you are replacing. It is unusual for a sizing argument to be this cheap to win.
What the migration actually involves
A 40F configuration will not restore onto a 50G or 70G through the interface. The port naming differs across all three generations.
| 40F interface | 50G | 70G | What has to be remapped |
|---|---|---|---|
| port1 (WAN) | wan | wan1 | Static routes and SD-WAN zone members |
| port2 (FortiLink) | fortilink | fortilink1 / fortilink2 | FortiSwitch management interfaces |
| internal1 | lan1 | internal1 | Firewall policies and DHCP server bindings |
| internal2 | lan2 | internal2 | References inside local software switches |
| internal3 | lan3 | internal3 | References inside local software switches |
| No second WAN | Repurpose lan3 | wan2, native | The 70G gives dual WAN without losing a LAN port |
Manual migration means editing the model identifier in the configuration header from #build: 40F to the target model and doing a global find-and-replace on interface names. Fortinet’s FortiConverter service does the remapping and strips deprecated syntax for roughly €51.80 per device translation, which is cheap against the engineer hours if you have more than a handful of sites.
Two things break quietly. Firmware schema: early SP5 hardware shipped on hardware-specific FortiOS builds rather than the mainline branch, so restoring a config from mainline 7.4.7 onto a 70G running an early 7.2.11 build fails on schema mismatch. Align both units on a mature universal release — 7.4.9 or later, or 7.6.4 or later — before importing anything. And remote access: if your 40F config contains config vpn ssl web or config vpn ssl settings, the G-series CLI parser flags those commands as invalid and discards them. Your remote access configuration disappears without an error anyone reads. Move users to IPsec via FortiClient or to ZTNA before you migrate the hardware, not after. The WireGuard and ZTNA options for FortiGate estates are covered in this comparison.
Finally, licensing is bound to the serial number. Buying replacement hardware does not move an active FortiCare or FortiGuard balance; that requires an authorised trade-in through the Fortinet TradeUp Programme.
Does the site need a box at all
Field reports put 40F units in three roles, and only one of them clearly justifies a next-generation firewall.
As an IPsec spoke for three to ten people, with local breakout disabled and all inspection handled at a central cluster, the appliance is doing routing and crypto. Paying €600 or more a year for local FortiGuard signatures that never inspect anything is hard to defend; a reliable edge router does this job.
As a retail or kiosk gateway for one to five people using only cloud applications, the maths is worse. Hardware and subscription run past €1,500 per site, plus firmware cycles and RMA handling, to protect traffic that is going straight to SaaS. A commodity router for NAT and routing, with endpoints running a lightweight agent to an EU-based inspection point, removes the appliance from the risk register entirely.
As a complex branch with fifteen to fifty users, local servers, VLANs and internal switching, the answer is genuinely the 70G. Cloud inspection does not do local Layer 2 and 3 segmentation, DHCP or physical port switching, and pretending otherwise creates a worse design than the one you started with.
The compliance angle sharpens the first two cases. NIS2 and DORA expect inspection across encrypted web traffic to be demonstrable, and a 2GB appliance that enters conserve mode during a signature update cannot demonstrate that reliably. Running that inspection on an EU-hosted platform and leaving a plain router on site removes a per-branch patching liability from the audit scope. That is the honest architectural question here, and for sites in the first two profiles it deserves answering before the hardware budget is signed. Jimber runs exactly that split: inspection and application access in one EU-sovereign platform, the branch hardware reduced to transport.
The case for buying the cheapest successor
An IT manager with forty small sites has a real argument for ordering forty 50Gs and moving on, and it is not laziness.
Fleet uniformity has genuine operational value: one model, one firmware baseline, one spares shelf, one runbook, one line in the budget. Per-site sizing conversations across forty locations cost engineer time that nobody has, and the €78,000 outlay is already a difficult ask. Most of those sites genuinely are small. And the 50G is a real improvement on the 40F — SP5 silicon, roughly double the inspected throughput, better session handling.
The counter is that uniformity is exactly what makes the memory decision expensive. Standardising on a 2GB platform means standardising on the constraint across all forty sites for the next five years, and the sites that outgrow it will not announce themselves — they will show up as intermittent conserve mode, dropped sessions and an engineer disabling IPS acceleration to keep a branch stable. At €13 per site per month, the 70G buys uniformity at a specification that does not need managing around. If the budget genuinely will not stretch, the defensible version is a split by profile rather than a split by site: 50Gs where inspection is backhauled, 70Gs where it is local. What does not work is choosing the 50G because it is what the quote said.
Where to start
Check two things this week. Whether any of your 40F units are cellular or wireless variants, because those have live End of Order dates and a Last Service Extension deadline in 2029 or 2030. And what FortiOS branch each unit runs, because 7.2 stops receiving security fixes on 30 September 2026.
Then, before you accept a 50G quote, count the users and the circuit speed at each site. Under ten people with inspection elsewhere, the 50G is the right box. Fifteen or more, a gigabit line, or local deep inspection, and it is not. For the sites where the honest answer is that nothing local needs inspecting, book a demo and we will walk through what moves off the box, or get in touch with your site list. The wider cost picture for that kind of move is in SASE migration hidden costs, and the FortiSASE comparison in what FortiGate customers actually pay.
Frequently asked questions
Is the FortiGate 40F end of life?
The base desktop 40F is not. Fortinet has announced no End of Order date and it remains in active production. The cellular 40F-3G4G reached End of Order on 13 August 2025 and the FortiWiFi 40F on 1 May 2026. Lifecycle aggregators frequently apply those variant dates to the whole family.
What is the direct replacement for a FortiGate 40F?
Fortinet and distributors position the FortiGate 50G as the price-point successor. Technically it is only suitable for sites under ten users with inspection handled elsewhere, because it carries the same 2GB of RAM. For fifteen or more users, gigabit circuits or local deep inspection, the 70G is the correct replacement.
Why are features missing on my FortiGate 40F?
The 40F has 2GB of RAM, and modern FortiOS overhead exceeds what that allows. From FortiOS 7.4.4 Fortinet disabled proxy-based inspection on 2GB models, and FortiOS 7.6 removes the SSL-VPN server daemon entirely in both tunnel and web mode. These are deliberate removals to prevent memory exhaustion.
Does the FortiGate 50G support SSL-VPN?
No. The 50G launched without an SSL-VPN server and never had one. The 70G had SSL-VPN removed from FortiOS 7.4.8 onwards. Remote users on a G-series branch appliance need IPsec via FortiClient or a ZTNA approach instead.
What is the RAM difference between the 50G and 70G?
The 50G has 2GB, the 70G has 4GB. On 2GB, core daemons consume 1.3GB to 1.5GB at rest and FortiGuard signature updates spike usage by 10% to 20%, which breaches the 88% conserve threshold. The 70G sits at a 35% to 42% baseline with headroom for updates.
Can I restore a 40F configuration onto a 70G?
Not directly. The 40F uses port1, port2 and internal1 to internal3; the 70G uses wan1, wan2, fortilink1, fortilink2 and internal1 to internal6. You must edit the model identifier in the configuration header and remap interfaces manually, or use FortiConverter, which costs roughly €51.80 per device translation.
What is the Threat Protection throughput of the FortiGate 70G?
1.3 Gbps, measured with firewall, IPS, Application Control and Advanced Malware Protection active and session logging enabled. It also delivers 1.4 Gbps of SSL inspection throughput and tracks 1.4 million concurrent TCP sessions. The 50G reaches 1.1 Gbps Threat Protection and 1.3 Gbps SSL inspection.
Can a FortiGate 40F handle a 1 Gbps internet connection?
Not with inspection enabled. It delivers 600 Mbps of Threat Protection and 310 Mbps of SSL inspection, so running deep inspection on a symmetrical gigabit circuit throttles usable bandwidth by roughly 40% to 70%. It routes a gigabit fine; it cannot inspect one.
Do my FortiCare and FortiGuard licences transfer to the new appliance?
Not automatically. Subscriptions are bound to the physical device serial number, and buying replacement hardware does not move a remaining balance. Transferring it requires an authorised trade-in processed through the Fortinet TradeUp Programme with a partner.
Should I wait before deploying new G-series hardware?
Practitioners commonly suggest six to twelve months after a platform launch. Early SP5 appliances shipped on hardware-specific FortiOS builds rather than the mainline branch, which caused configuration schema mismatches and FortiManager synchronisation problems in mixed F-series and G-series estates.