As of 17 August 2026, the FortiGate 80E and FortiGate 100E are out of support. Fortinet no longer ships security patches for them, no longer answers support tickets about them, and no longer replaces failed units. They join a list that grew fast this summer: the 30E, 61E, 70E, 101E, 300E and 500E all crossed the same line in July. Before the year is out, the FortiGate 50E, 81E, 60E and 1500D follow.
Every FortiGate appliance has a date on it. This page collects all of them: every published end-of-order and end-of-support date across the C-, D-, E- and F-series, what each milestone actually changes, and what your options are once your model shows up in the tables below. We maintain this page as a living reference and update it whenever Fortinet publishes new dates.
One scope note: this article covers hardware lifecycles only. The separate deprecation of the SSL VPN feature in FortiOS, which follows its own timeline across firmware versions, is covered in our SSL VPN deprecation timeline for every vendor.
What end of order, LSED and end of support actually mean
Fortinet’s hardware lifecycle runs through three fixed milestones, and the maths between them is mechanical.
End of order (EOO) is the last day a model can be purchased through authorised channels. Fortinet commits to announcing it at least 90 days in advance. Manufacturing stops after this date; resellers may still sell remaining stock.
Last service extension date (LSED) falls exactly 12 months before end of support. It is the last day you can renew or extend FortiCare support and FortiGuard subscriptions on the device. Miss it, and your existing contract simply runs out with no way to extend. The FortiGate 60E, for example, passed its LSED on 29 December 2025: whatever contract you hold on a 60E today is the last one it will ever have.
End of support (EOS) arrives exactly 60 months after EOO. Past this date, everything stops at once: firmware fixes, security patches, FortiGuard threat intelligence ingestion, TAC ticket intake and hardware RMA replacement.
Software support runs on a parallel clock. Each FortiOS branch gets 36 months of engineering support after release, then an 18-month must-fix window for critical flaws only. In practice this bites earlier than the hardware dates suggest: D-series units cannot run FortiOS 7.x at all, and 2 GB RAM models lose proxy-based inspection features from FortiOS 7.4/7.6 onwards. A box can be years away from hardware EOS and still be stuck on firmware that no longer receives routine maintenance.
The FortiGate hardware end-of-support timeline
Last verified: August 2026.
Already past end of support
These models receive no patches, no support and no RMA service. If one of these still sits at your perimeter, treat it as an unmanaged risk, not as infrastructure.
| Model | End of support | Designated successor |
|---|---|---|
| FortiGate 60C | 15 Apr 2020 | FG-60E / FG-60F |
| FortiGate 40C | 1 Jul 2020 | FG-30E / FG-40F |
| FortiGate 80C | 21 Apr 2021 | FG-80E / FG-80F |
| FortiGate 30D | 30 Nov 2021 | FG-40F |
| FortiGate 70D | 16 Jul 2022 | FG-60E / FG-60F |
| FortiGate 500D | 8 May 2023 | FG-500E / FG-600E |
| FortiGate 200D | 22 May 2023 | FG-200E / FG-200F |
| FortiGate 100D | 26 Jul 2023 | FG-100E / FG-100F |
| FortiGate 60D | 23 Sep 2023 | FG-60E / FG-60F |
| FortiGate 300D | 11 Oct 2023 | FG-300E / FG-400E |
| FortiGate 90D | 14 Oct 2023 | FG-80E / FG-80F |
| FortiGate 600D | 14 Oct 2024 | FG-600E / FG-600F |
| FortiGate 90E | 14 Jan 2025 | FG-80F / FG-90G |
| FortiGate 240D | 13 Mar 2025 | FG-200E / FG-200F |
| FortiGate 52E | 15 Apr 2025 | FG-60F / FG-70F |
| FortiGate 3800D | 14 Jan 2026 | FG-3700F / FG-4400F |
| FortiGate 1200D | 16 Apr 2026 | FG-1000F / FG-900G |
| FortiGate 30E | 15 Jul 2026 | FG-40F / FG-30G / FG-50G |
| FortiGate 61E | 15 Jul 2026 | FG-61F / FG-71F / FG-71G |
| FortiGate 70E | 15 Jul 2026 | FG-61F / FG-70G |
| FortiGate 101E | 15 Jul 2026 | FG-101F / FG-121G |
| FortiGate 300E / 301E | 15 Jul 2026 | FG-400F / FG-401F / FG-200G |
| FortiGate 500E / 501E | 15 Jul 2026 | FG-600F / FG-900G / FG-400F |
| FortiGate Rugged 60D | 15 Jul 2026 | FG-Rugged 60F / 70F |
| FortiGate 80E | 17 Aug 2026 | FG-80F / FG-90G |
| FortiGate 100E | 17 Aug 2026 | FG-100F / FG-90G / FG-120G |
The next wave: end of support before 2028
| Model | End of order | End of support | Designated successor |
|---|---|---|---|
| FortiGate 50E | 14 Nov 2021 | 14 Nov 2026 | FG-60F / FG-50G / FG-70G |
| FortiGate 81E | 14 Nov 2021 | 14 Nov 2026 | FG-81F / FG-91G |
| FortiGate 60E | 29 Dec 2021 | 29 Dec 2026 | FG-60F / FG-70G |
| FortiGate 1500D / 1500DT | 31 Dec 2021 | 31 Dec 2026 | FG-1800F / FG-1801F |
| FortiGate 51E | 15 Jul 2022 | 15 Jul 2027 | FG-61F / FG-71F / FG-51G |
| FortiGate 80E-POE | 15 Jul 2022 | 15 Jul 2027 | FG-80F-POE |
| FortiGate 60E-POE | 14 Oct 2022 | 14 Oct 2027 | FG-80F-POE |
| FortiGate Rugged 30D | 31 Dec 2022 | 31 Dec 2027 | No direct successor |
End of support 2028–2031
| Model | End of order | End of support | Designated successor |
|---|---|---|---|
| FortiGate 800D | 16 Apr 2023 | 16 Apr 2028 | FG-600F / FG-900G |
| FortiGate 900D | 16 Apr 2023 | 16 Apr 2028 | FG-601F / FG-900G / FG-901G |
| FortiGate 1000D | 16 Apr 2023 | 16 Apr 2028 | FG-1000F / FG-900G |
| FortiGate 3200D | 16 Apr 2023 | 16 Apr 2028 | FG-3001F / FG-3201F |
| FortiGate 3600E / 3601E | 15 Apr 2024 | 15 Apr 2029 | FG-3200F / FG-3700F |
| FortiGate 3400E / 3401E | 16 Apr 2025 | 16 Apr 2030 | FG-3000F / FG-3001F |
| FortiGate Rugged 35D | 16 Apr 2025 | 16 Apr 2030 | No direct successor |
| FortiGate 2000E | 2 May 2025 | 2 May 2030 | FG-1801F |
| FortiGate 200E / 201E | 13 Oct 2025 | 13 Oct 2030 | FG-200G / FG-201G |
| FortiGate 400E / 401E | 13 Oct 2025 | 13 Oct 2030 | FG-400F / FG-401F |
| FortiGate 6300F | 13 Jan 2026 | 13 Jan 2031 | FG-7000 series |
| FortiGate 200F / 201F | 1 Mar 2026 | 1 Mar 2031 | FG-200G / FG-201G |
| FortiGate 6500F | 15 Apr 2026 | 15 Apr 2031 | FG-7000 series |
| FortiGate 100F / 101F | 16 Apr 2026 | 16 Apr 2031 | FG-120G / FG-121G / FG-90G |
| FortiGate 600F / 601F | 1 May 2026 | 1 May 2031 | FG-700G / FG-900G |
| FortiGate 70F | 17 May 2026 | 17 May 2031 | FG-70G |
| FortiGate 1101E | 30 Jul 2026 | 30 Jul 2031 | FG-1001F / FG-1801F |
| FortiGate 1100E | 13 Sep 2026 | 13 Sep 2031 | FG-1000F / FG-1800F |
| FortiGate Rugged 60F | 13 Oct 2026 | 13 Oct 2031 | FG-Rugged 70F |
Source for all dates: Fortinet’s official Product Life Cycle portal. A handful of models (FG-30E, FG-50E, FG-60D) show minor date variations between Fortinet’s factory milestones and regional distributor cut-offs; the table follows the official lifecycle records. Note that the 2026 F-series end-of-order wave has already begun: the popular FG-100F stopped being orderable on 16 April 2026, which started its five-year countdown. The FG-40F, FG-60F/61F, FG-80F/81F, FG-400F, FG-600E and the G-series have no announced dates yet.
What to do at each lifecycle stage
Model still active, no EOO announced. Nothing urgent, but note the firmware ceiling: 2 GB RAM models like the FG-40F and FG-60F already lose proxy features under FortiOS 7.4/7.6 and drop into conserve mode under load. The hardware date is not the real deadline for these units.
Between EOO and LSED. You can still renew support. This is the window to make an architecture decision rather than an emergency purchase. Diarise the LSED: it is the last exit with options.
Between LSED and EOS. No renewals possible; your contract runs down with the clock. Fortinet applies commercial pressure here as well, with renewal surcharges on retiring models and RMA fulfilment becoming dependent on remaining parts stock. Plan the replacement or migration now, not at EOS.
Past EOS. The device still routes packets, which is precisely the problem: it looks alive while receiving no patches for newly discovered flaws. Every CVE published from that day on is permanent. If decommissioning takes time, isolate the device from the internet-facing edge and put a migration date on paper; under NIS2, a documented plan is the minimum defensible position (our legacy VPN end-of-life watchlist covers the same logic for remote-access appliances).
The real risk of running past end of support
Perimeter appliances are the most attacked category of enterprise hardware, and Fortinet’s record illustrates why the patch supply matters. Over two dozen Fortinet vulnerabilities appear in CISA’s Known Exploited Vulnerabilities catalogue, and at least 13 of them have been used in ransomware operations. The pattern is consistent: authentication bypasses in the management plane (CVE-2022-40684, CVE-2024-55591) and pre-authentication memory corruption in edge daemons (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) that hand an unauthenticated attacker root on the device that terminates your VPN sessions and holds your routing table.
On a supported appliance, each of these gets an emergency patch. On a post-EOS appliance, none of them ever will. And because the firewall sits on the routing boundary itself, no internal segmentation protects it: compromise of the perimeter OS gives an attacker Layer 3 reach into every subnet behind it. That architectural exposure is the same story we documented when Fortinet deprecated its SSL VPN: the features change, the attack surface logic does not.
For European organisations there is a regulatory floor under this. NIS2’s Article 21 duty of care requires active vulnerability handling; Belgium’s CyFun framework classifies unsupported hardware without a documented exception as unauthorised. A perimeter firewall that can no longer be patched is difficult to defend in an audit and increasingly difficult to defend to a cyber insurer.
Successor appliance, or exit the refresh treadmill?
When your model’s date approaches, there are two honest paths.
Track one: buy the successor. Fortinet’s TradeUp programme discounts replacement hardware by typically 36–38% (promotions occasionally reach 50–55%) and lets you transfer remaining FortiCare/FortiGuard time, provided you buy the replacement as standalone hardware rather than a bundle. The trade-in permanently retires the old serial number. Budget-wise, branch-grade bundles such as an FG-60F with one year of UTP start around €1,490 ($1,600); a mid-market FG-120G runs roughly €1,490–€3,220 ($1,620–$3,500) for hardware alone and €4,140–€6,440 ($4,500–$7,000) with multi-year security bundles; campus-class units scale from €4,600 to over €13,800 ($5,000–$15,000) before high-availability pairing doubles the hardware.
The hidden costs sit outside the quote: FortiCare renewals on ageing models rise by double-digit percentages annually, cross-generation config migration via FortiConverter still demands manual remediation of interface mappings and deprecated proxy features, and the whole exercise repeats in five years. That is the treadmill.
Track two: move the functions, not the box. The jobs a FortiGate does at a mid-market perimeter (firewalling, secure remote access, web filtering, site-to-site connectivity) can move to a cloud-delivered SASE platform with ZTNA. That swaps open inbound listening ports for outbound-only connectors, network-level VPN access for per-application least privilege, and the five-year hardware cycle for a subscription with no appliance to patch. For teams weighing this against staying on FortiGate, we have laid out the comparison points in FortiGate WireGuard vs ZTNA and the cost mechanics in what FortiGate customers actually pay for FortiSASE.
| Dimension | Successor appliance | Cloud-delivered SASE / ZTNA |
|---|---|---|
| Inbound attack surface | Public IP with listening VPN/management daemons | No inbound listening ports; outbound-only connectors |
| Access model | Network-level tunnel, broad subnet reach | Per-application, identity-gated least privilege |
| Patching burden | Yours: firmware cycles, emergency CVE windows | Vendor-managed cloud platform |
| Capacity | Fixed RAM/throughput; conserve mode under load | Elastic, no hardware ceiling |
| Lifecycle | New EOO/EOS countdown every 3–5 years | No appliance lifecycle |
The honest case for just buying the next FortiGate
Plenty of capable admins will read the tables above and order an FG-90G before lunch, and their reasoning deserves a straight answer. The TradeUp discount is real and the remaining subscription time carries over. Your team knows FortiOS, your reseller relationship works, and the config migrates within the ecosystem. ASIC throughput on the new silicon is genuinely excellent for east-west traffic.
All true. What the like-for-like refresh does not change is the model itself. The new box has the same open listening ports facing the internet, the same emergency-patch obligation when the next KEV entry lands, the same fixed capacity, and its own EOO announcement already waiting somewhere in a future quarterly bulletin. Meanwhile most mid-market traffic now runs north-south to cloud applications, where hairpinning through an on-premise appliance adds latency rather than protection. If you have survived one forced Fortinet migration already, you know how much unplanned work the treadmill generates; we wrote up those lessons in you survived the Fortinet VPN migration, now what?. The refresh decision is really a decision about whether you want to be having this same conversation again in 2031.
Check your date, then choose your track
Find your model in the tables, note the LSED, and work backwards: a calm migration takes a quarter, an emergency one takes a weekend and a year of cleanup. If the date is close and you are weighing the treadmill against a platform approach, that is exactly the conversation we have daily with EU mid-market teams. Jimber delivers full SASE (ZTNA network isolation, secure web gateway, firewall-as-a-service and SD-WAN) from a single EU-sovereign platform at a predictable flat rate, with no appliance to patch and no end-of-support countdown. Book a demo and we will map your FortiGate estate’s dates against a concrete migration plan, or explore how the platform works first.
Frequently asked questions
When does the FortiGate 60E reach end of support?
The FortiGate 60E reached end of order on 29 December 2021 and reaches end of support on 29 December 2026. Its last service extension date passed on 29 December 2025, so existing support contracts can no longer be renewed or extended: whatever contract is active today is the final one.
Is the FortiGate 60F end of life?
No. Fortinet has not announced an end-of-order date for the FortiGate 60F, and once it does, hardware support continues for five years. The practical constraint arrives sooner: with 2 GB of RAM, the 60F loses proxy-based inspection features under FortiOS 7.4/7.6 and can drop into conserve mode under heavy load.
When does support end for the FortiGate 100E and 80E?
Both the FortiGate 100E and FortiGate 80E reached end of support on 17 August 2026, five years after their shared end-of-order date of 17 August 2021. Since that date Fortinet issues no security patches, provides no technical support and fulfils no RMA replacements for either model.
What is the difference between end of order and end of support?
End of order (EOO) is the last date an appliance can be bought new through authorised channels; Fortinet announces it at least 90 days ahead. End of support (EOS) falls exactly 60 months later and terminates everything at once: firmware patches, FortiGuard updates, technical assistance and hardware replacement.
Can I keep using a FortiGate after its end-of-support date?
The appliance keeps routing traffic, but every vulnerability discovered after EOS remains permanently unpatched on an internet-facing device. FortiGuard signature ingestion stops, and under NIS2 and Belgium’s CyFun framework an unsupported perimeter device without a documented exception is treated as unauthorised, which also weakens your cyber insurance position.
Can I transfer my FortiGuard licence through the TradeUp programme?
Yes. Remaining FortiCare and FortiGuard subscription time transfers to the replacement unit, but only if the new device is purchased as standalone hardware rather than a promotional bundle. The old serial number is permanently retired in FortiCloud and may not be redeployed in production.
Do I have to return the old firewall after a TradeUp?
No physical return is required. The traded-in serial number is permanently retired in Fortinet’s licensing systems, and the customer contractually agrees not to reuse, resell or redeploy the retired appliance in commercial production. Plan secure disposal, including wiping configurations and stored credentials.
Why is running an unsupported firewall a NIS2 problem?
NIS2 Article 21 requires active vulnerability handling and basic cyber hygiene. A post-EOS firewall cannot receive patches for new CVEs, so keeping it at the perimeter means knowingly operating an unpatchable system at your most exposed point. That is a duty-of-care failure for which management can be held personally accountable.