← All blog articles

FortiGate 60F End of Life: The Real Ceiling Is Not a Date

Kristof Van Stappen
FortiGate 60F End of Life: The Real Ceiling Is Not a Date

The FortiGate 60F is not end of life. Fortinet has not published an End of Order date for the base model or its active variants, the appliance is still on distributor price lists, and under Fortinet’s own lifecycle policy End of Support falls sixty months after an End of Order announcement that has not been made yet. Buy one today and hardware support runs into 2031.

That answer is correct and it is also, for most people asking the question, not the answer they need. The 60F has a hard ceiling, and it is not a date. It is 2GB of RAM.

Fortinet has already begun removing functionality from 2GB appliances. Proxy-based inspection is restricted from FortiOS 7.4.4 onwards, and FortiOS 7.6 removes SSL VPN entirely, both tunnel mode and web mode, from every model with 2GB or less. The hardware is supported. The software has moved past it. Everything that follows is about that gap.

Where the 60F actually stands

Fortinet’s hardware lifecycle runs on three published milestones, and it is worth knowing what each one stops before reading anything into the absence of dates.

End of Order is the last date the appliance can be bought through authorised distribution. Fortinet commits to announcing it at least ninety days in advance. Last Service Extension Date is the final date on which you can extend or renew a FortiCare contract or FortiGuard subscription, and it falls exactly twelve months before End of Support. End of Support ends TAC assistance, bug fixes, security patching and hardware replacement, and it falls exactly sixty months after End of Order.

Model Key characteristics End of Order End of Support Highest viable FortiOS branch
FortiGate 60F Desktop, fanless, 10x GE RJ45, SOC4, 2GB RAM Not announced 60 months after EOO, so 2031 at the earliest 7.6, with SSL VPN removed
FortiGate 61F As 60F, plus 128GB onboard SSD Not announced 60 months after EOO 7.6, with SSL VPN removed
FortiWiFi 60F As 60F, plus 802.11ac radio Not announced 60 months after EOO 7.6, with SSL VPN removed
FortiWiFi 61F As 61F, plus 802.11ac radio Not announced 60 months after EOO 7.6, with SSL VPN removed
FortiGate Rugged 60F DIN-rail, redundant power, fanless Not announced 60 months after EOO 7.6, with SSL VPN removed
For comparison: FortiGate 60E Predecessor, SOC3, 2GB RAM 29 December 2021 29 December 2026 7.2 (branch ceiling)

Last verified: September 2026. Source: Fortinet Product Life Cycle, support.fortinet.com. The 60E row is included because it shows the pattern: End of Order December 2021, Last Service Extension December 2025, End of Support December 2026, and a firmware ceiling reached years before the hardware date.

The 60E line is the useful one. Its owners are finding out this year that hardware support running until December 2026 was never the constraint; the branch ceiling at 7.2 was. The 60F is on the same trajectory with more runway.

If you want the equivalent table for every other FortiGate model, we maintain it separately in the FortiGate hardware end-of-life timeline. For the software clock rather than the hardware one, this week’s piece on FortiOS 7.2 end of support covers which models can follow which branch.

The 2GB problem, in practice

Two separate things are happening on 2GB appliances, and they compound.

The first is memory conserve mode. Administrators report 60F units entering conserve mode at modest throughput, in the 50 to 100 Mbps range, on both FortiOS 7.2.x and 7.4.x. The cause is not bandwidth. It is memory overhead from the WAD daemon combined with the compilation of current FortiGuard IPS signature databases inside a 2GB envelope. The workarounds are real but they cost you something: setting set cp-accel-mode none under config ips global, scheduling service restarts, or moving signature updates to off-peak hours all reduce inspection efficiency or add maintenance work.

The second is feature removal. From FortiOS 7.4.4, proxy-based security features operate under restrictions on these devices. From FortiOS 7.6, SSL VPN web mode and tunnel mode are gone entirely on 2GB hardware, and Fortinet names the 40F, 60F, 61F and FortiGate Rugged 60F explicitly. Fortinet’s release note adds the sentence that matters most: settings are not upgraded from previous versions. The configuration does not convert.

You can confirm whether a specific unit falls under the rule with one command. Run diagnose hardware sysinfo conserve and check total RAM; below 2000MB and the removal applies.

The practical consequence is a fork. A 60F doing remote access can stay on 7.2 or 7.4 and keep SSL VPN, accepting an ageing branch and conserve mode. Or it can move to 7.6 and lose remote access on that box. There is no version where it keeps both. We covered the wider vendor context in Fortinet’s SSL VPN deprecation, and the technical alternative in WireGuard versus ZTNA for FortiGate administrators.

The successor, with the regressions included

Fortinet positions the FortiGate 70F as the direct drop-in and the 70G as the next-generation option. The 70F shares the SOC4 silicon and the identical ten-port layout, and doubles memory to 4GB. The 70G moves to the SP5 architecture.

Most comparisons stop at “more memory, more throughput”. The datasheets say something more interesting.

Datasheet metric FortiGate 60F FortiGate 70F FortiGate 70G
Processing ASIC SOC4 (CP9 + NP6XLite) SOC4 (CP9 + NP6XLite) SOC5 / SP5
System memory 2GB 4GB 4GB
Firewall throughput (1518/512/64B) 10 / 10 / 6 Gbps 10 / 10 / 6 Gbps 10 / 10 / 10 Gbps
Firewall packets per second 9 Mpps 9 Mpps 15 Mpps
Threat protection throughput 700 Mbps 800 Mbps 1.3 Gbps
IPS throughput (enterprise mix) 1.4 Gbps 1.4 Gbps 2.5 Gbps
NGFW throughput (enterprise mix) 1 Gbps 1 Gbps 1.5 Gbps
IPsec VPN throughput (512B) 6.5 Gbps 6.1 Gbps 9.0 Gbps
SSL VPN throughput 900 Mbps 405 Mbps Not published
SSL inspection throughput 630 Mbps 700 Mbps 1.2 Gbps
Concurrent TCP sessions 700,000 1,500,000 1,400,000
Physical interfaces 10x GE RJ45 10x GE RJ45 10x GE RJ45, PoE variants available

Figures taken from Fortinet datasheets using enterprise traffic mix benchmarks. Compare like with like: Fortinet publishes throughput under several test profiles, and numbers from different profiles are not interchangeable.

Three things stand out. On identical silicon, the 70F delivers parity rather than an upgrade on IPS and NGFW throughput; what you are buying is the 4GB. Published IPsec VPN throughput goes down, from 6.5 to 6.1 Gbps. And SSL VPN throughput drops by more than half, from 900 to 405 Mbps, which reads oddly until you remember that Fortinet is retiring SSL VPN as a feature and has no reason to optimise for it.

The 70G is the genuine generational step: full line rate on 64-byte packets, two thirds more packet processing, nearly double the threat protection throughput. The trade-off is firmware maturity. Early 70G deployments ran on specialised non-converged branches, so a branch network that values a settled firmware baseline may prefer the 70F.

What another year on the 60F costs

European reseller pricing, quoted in euro as listed, gives a reasonably clear picture.

Option Part number Cost (EUR, net) Covers
60F support renewal only FC-10-0060F-247-02-12 €140.00 to €231.59 1 year FortiCare Premium
60F security bundle renewal FC-10-0060F-950-02-12 €550.00 to €650.00 1 year FortiCare plus UTP bundle
70F hardware only FG-70F €742.00 to €856.43 Appliance
70F hardware plus bundle FG-70F-BDL-950-12 €933.36 to €1,270.00 Appliance plus 1 year UTP
70F bundle renewal, year 2 onwards FC-10-0070F-950-02-12 €568.00 to €739.66 1 year FortiCare plus UTP

Reseller list pricing gathered from European distributors during 2025 and 2026, quoted in the original euro. Your partner pricing will differ.

Read across the rows and the capital delta is smaller than it looks. Renewing UTP on an existing 60F costs €550 to €650 a year. Replacing it with a 70F including a year of UTP costs roughly €1,100 to €1,270. The one-off difference is somewhere around €500 to €620 per site, and from year two the renewal costs are broadly comparable.

Two costs sit outside that table. Conserve mode triage is engineering time: writing CLI cron triggers to cycle the WAD daemon, rescheduling IPS updates, disabling heuristic scanning. Across twenty or fifty branch sites, that maintenance overhead reaches the cost of the refresh faster than most teams expect. And keeping units on an older branch to preserve SSL VPN means running a wider attack surface with features disabled to save memory, which is exactly the configuration a NIS2 or CyFun assessment asks you to justify in writing.

When the box is the right answer, and when it is not

A hardware refresh to the 70F or 70G is straightforward and correct in several situations.

Sites where most traffic stays local benefit from local inspection: manufacturing plants, healthcare facilities and logistics centres with industrial devices or local server rooms. Sending that east-west traffic to a cloud inspection point adds latency for no gain. Sites built on the Fortinet Security Fabric, where FortiSwitch and FortiAP are managed directly from the firewall through FortiLink, would need the local switching and wireless control plane redesigned if the appliance left. And sites on constrained WAN uplinks, satellite links or low-bandwidth connections cannot route everything out for inspection.

The picture changes where the branch looks different. When most traffic is bound for Microsoft 365, Salesforce or public cloud, routing it through a local appliance for inspection puts a bottleneck in the middle of the path rather than security at the edge. When remote access matters and the appliance is a 2GB model, FortiOS 7.6 has already taken that function away, so you are rebuilding it regardless. And under NIS2, tracking firmware and lifecycle across dozens of edge appliances is audit work that centralised policy simply does not generate.

Replace with 70F or 70G Cloud-delivered platform with the 60F as a thin edge router
Capital cost per site €1,100 to €1,600 for hardware and first-year bundle None; the existing 60F is retained
Ongoing cost Annual licence renewal, patching, appliance maintenance Per-user platform subscription, no local policy overhead
Remote access Requires 4GB hardware to keep native VPN Identity-based access with no inbound listener at the edge
Memory pressure Resolved by 4GB Eliminated; UTM profiles come off the box entirely
NIS2 audit scope Every appliance tracked for lifecycle and firmware Policy managed centrally

That last row in the right-hand column deserves spelling out, because it is the option nobody selling hardware will mention. A 60F does not have to be discarded. Turn off the compute-heavy UTM features, which is what triggers conserve mode in the first place, and the unit runs cleanly as an SD-WAN transport and IPsec termination router. Inspection, web security, isolation and identity-aware access move to the platform. The appliance stops being a security device and becomes a router, which is a job it does perfectly well on 2GB.

Jimber is built for that shape of deployment across EU mid-market networks: ZTNA and network isolation, secure web gateway, firewall-as-a-service and web application isolation on one platform, with EU-sovereign data handling. If you want the cost comparison against Fortinet’s own cloud offering, we set out the published numbers in what FortiGate customers actually pay for FortiSASE in 2026, and the capability comparison in FortiSASE versus Jimber.

Practical notes before you move anything

Configuration portability. 60F to 70F is straightforward: identical ten-port architecture, so a configuration backup with the system header adjusted usually transfers, or you can use FortiConverter. Moving to the G-series is a different job, requiring interface remapping and syntax adjustments.

Licences do not move by hand. Fortinet does not permit manual transfer of active FortiCare or FortiGuard keys between serial numbers. Remaining subscription value moves through the TradeUp programme, and a traded-up device is permanently decommissioned from support: it forfeits RMA eligibility and cannot be resold or redeployed.

Refurbished units carry a specific risk. Licensing, firmware download entitlement and RMA are bound to the registered FortiCloud account. If the previous owner has not formally released the serial number in Fortinet’s Asset Management portal, customer service will decline the ownership transfer and the new owner cannot apply support contracts or download patches.

The case for just buying the 70F

An IT manager with forty small sites will say, reasonably, that this is a solved problem: the 70F is a drop-in, the cabling is identical, the configuration transfers, the delta is roughly €500 a site, and none of that requires a project. That is true, and for a fabric-managed branch with local switching and wireless it is very likely the right call.

Two things sit against it. The first is that the 70F is parity silicon, so you are spending capital to buy memory headroom rather than capability; if the site needed more inspection throughput, the honest comparison is against the 70G, not the 60F. The second is that on a 2GB estate the remote access question is already forced, and answering it by buying 4GB appliances at every site solves it once, per site, per refresh cycle. Whether that is the right shape depends on what your branches actually do, which is why the fit questions above matter more than the price delta.

What to check this week

Pull the RAM figure and the running firmware from every 60F you manage. Note which of them terminate remote access. Those two facts sort your estate into units that can carry on as they are, units that need a decision about 7.6, and units where the decision has effectively already been made for you.

If the second list is longer than you expected, we are happy to go through it with you and be straight about which sites should simply get a 70F. Book a demo or get in touch.

Frequently asked questions

Is the FortiGate 60F end of life?

No. Fortinet has not published an End of Order date for the FortiGate 60F, and under its lifecycle policy End of Support falls sixty months after that announcement. Hardware support therefore continues into 2031 at the earliest. The practical limit is the appliance’s 2GB memory rather than any published date.

When is the FortiGate 60F end of support?

There is no official End of Support date. Under Fortinet’s policy, End of Support occurs exactly sixty months after End of Order, and the Last Service Extension Date falls twelve months before that. Because the 60F remains orderable, support will extend through at least 2031.

What is the direct replacement for the FortiGate 60F?

The FortiGate 70F is Fortinet’s direct replacement. It uses the same SOC4 processor and identical ten-port layout while doubling memory to 4GB, which removes the conserve mode problem. The FortiGate 70G is the next-generation option, built on SP5 silicon with substantially higher throughput.

Why did FortiOS 7.6 remove SSL VPN on the FortiGate 60F?

FortiOS 7.6 removes SSL VPN tunnel and web mode from all models with 2GB RAM or less, including the 60F, 61F, 40F and Rugged 60F. A 2GB memory footprint cannot sustain modern cryptographic workloads alongside current inspection engines without triggering conserve mode. Settings are not carried over during upgrade.

What is the difference between the FortiGate 60F and 70F?

Both use the SOC4 ASIC and the same ten-port physical layout. The 70F doubles system memory to 4GB, which resolves conserve mode and preserves SSL VPN under FortiOS 7.6. Threat protection throughput rises modestly from 700 to 800 Mbps; IPS and NGFW throughput are identical.

Can I run FortiOS 7.4 or 7.6 on a FortiGate 60F?

Yes, with constraints. FortiOS 7.4 can trigger memory conserve mode under heavy inspection loads, and proxy-based features are restricted from 7.4.4 onwards. FortiOS 7.6 runs but removes SSL VPN entirely on 2GB hardware, so remote access has to move elsewhere first.

Why does my FortiGate 60F keep going into conserve mode?

Conserve mode on the 60F is usually caused by WAD daemon memory overhead and the compilation of current FortiGuard IPS signature databases within 2GB, rather than by traffic volume. Administrators report it at 50 to 100 Mbps. Workarounds reduce inspection efficiency or add scheduled maintenance.

How much does it cost to renew support on a FortiGate 60F?

European reseller listings show FortiCare Premium support alone at roughly €140 to €232 net per year, and the full FortiCare plus UTP bundle at €550 to €650 net per year. A replacement 70F with a year of UTP included runs about €1,100 to €1,270 net.

Can I move my FortiGate 60F licences to a new appliance?

Not manually. Fortinet does not permit direct transfer of active FortiCare or FortiGuard keys between serial numbers. Remaining subscription value moves through the TradeUp programme, after which the traded-up device is permanently decommissioned, forfeits RMA eligibility and cannot be resold or redeployed.

Is it safe to buy a refurbished FortiGate 60F?

Only if the serial number has been released. Licensing, firmware downloads and RMA are bound to the registered FortiCloud account. If the previous owner has not formally released the appliance in Fortinet’s Asset Management portal, the new owner cannot apply support contracts or download security patches.