FortiGate Hardware End-of-Life: Every Model, Every Date (2026–2031)

Every FortiGate hardware end-of-life date in one sortable reference: EOO, LSED and EOS per model, plus what to do when your appliance's date nears.
IT engineer inspecting rack-mounted network firewall appliances in a dimly lit server room, checking a device label

As of 17 August 2026, the FortiGate 80E and FortiGate 100E are out of support. Fortinet no longer ships security patches for them, no longer answers support tickets about them, and no longer replaces failed units. They join a list that grew fast this summer: the 30E, 61E, 70E, 101E, 300E and 500E all crossed the same line in July. Before the year is out, the FortiGate 50E, 81E, 60E and 1500D follow.

Every FortiGate appliance has a date on it. This page collects all of them: every published end-of-order and end-of-support date across the C-, D-, E- and F-series, what each milestone actually changes, and what your options are once your model shows up in the tables below. We maintain this page as a living reference and update it whenever Fortinet publishes new dates.

One scope note: this article covers hardware lifecycles only. The separate deprecation of the SSL VPN feature in FortiOS, which follows its own timeline across firmware versions, is covered in our SSL VPN deprecation timeline for every vendor.

What end of order, LSED and end of support actually mean

Fortinet’s hardware lifecycle runs through three fixed milestones, and the maths between them is mechanical.

End of order (EOO) is the last day a model can be purchased through authorised channels. Fortinet commits to announcing it at least 90 days in advance. Manufacturing stops after this date; resellers may still sell remaining stock.

Last service extension date (LSED) falls exactly 12 months before end of support. It is the last day you can renew or extend FortiCare support and FortiGuard subscriptions on the device. Miss it, and your existing contract simply runs out with no way to extend. The FortiGate 60E, for example, passed its LSED on 29 December 2025: whatever contract you hold on a 60E today is the last one it will ever have.

End of support (EOS) arrives exactly 60 months after EOO. Past this date, everything stops at once: firmware fixes, security patches, FortiGuard threat intelligence ingestion, TAC ticket intake and hardware RMA replacement.

Software support runs on a parallel clock. Each FortiOS branch gets 36 months of engineering support after release, then an 18-month must-fix window for critical flaws only. In practice this bites earlier than the hardware dates suggest: D-series units cannot run FortiOS 7.x at all, and 2 GB RAM models lose proxy-based inspection features from FortiOS 7.4/7.6 onwards. A box can be years away from hardware EOS and still be stuck on firmware that no longer receives routine maintenance.

The FortiGate hardware end-of-support timeline

Last verified: August 2026.

Already past end of support

These models receive no patches, no support and no RMA service. If one of these still sits at your perimeter, treat it as an unmanaged risk, not as infrastructure.

Model End of support Designated successor
FortiGate 60C 15 Apr 2020 FG-60E / FG-60F
FortiGate 40C 1 Jul 2020 FG-30E / FG-40F
FortiGate 80C 21 Apr 2021 FG-80E / FG-80F
FortiGate 30D 30 Nov 2021 FG-40F
FortiGate 70D 16 Jul 2022 FG-60E / FG-60F
FortiGate 500D 8 May 2023 FG-500E / FG-600E
FortiGate 200D 22 May 2023 FG-200E / FG-200F
FortiGate 100D 26 Jul 2023 FG-100E / FG-100F
FortiGate 60D 23 Sep 2023 FG-60E / FG-60F
FortiGate 300D 11 Oct 2023 FG-300E / FG-400E
FortiGate 90D 14 Oct 2023 FG-80E / FG-80F
FortiGate 600D 14 Oct 2024 FG-600E / FG-600F
FortiGate 90E 14 Jan 2025 FG-80F / FG-90G
FortiGate 240D 13 Mar 2025 FG-200E / FG-200F
FortiGate 52E 15 Apr 2025 FG-60F / FG-70F
FortiGate 3800D 14 Jan 2026 FG-3700F / FG-4400F
FortiGate 1200D 16 Apr 2026 FG-1000F / FG-900G
FortiGate 30E 15 Jul 2026 FG-40F / FG-30G / FG-50G
FortiGate 61E 15 Jul 2026 FG-61F / FG-71F / FG-71G
FortiGate 70E 15 Jul 2026 FG-61F / FG-70G
FortiGate 101E 15 Jul 2026 FG-101F / FG-121G
FortiGate 300E / 301E 15 Jul 2026 FG-400F / FG-401F / FG-200G
FortiGate 500E / 501E 15 Jul 2026 FG-600F / FG-900G / FG-400F
FortiGate Rugged 60D 15 Jul 2026 FG-Rugged 60F / 70F
FortiGate 80E 17 Aug 2026 FG-80F / FG-90G
FortiGate 100E 17 Aug 2026 FG-100F / FG-90G / FG-120G

The next wave: end of support before 2028

Model End of order End of support Designated successor
FortiGate 50E 14 Nov 2021 14 Nov 2026 FG-60F / FG-50G / FG-70G
FortiGate 81E 14 Nov 2021 14 Nov 2026 FG-81F / FG-91G
FortiGate 60E 29 Dec 2021 29 Dec 2026 FG-60F / FG-70G
FortiGate 1500D / 1500DT 31 Dec 2021 31 Dec 2026 FG-1800F / FG-1801F
FortiGate 51E 15 Jul 2022 15 Jul 2027 FG-61F / FG-71F / FG-51G
FortiGate 80E-POE 15 Jul 2022 15 Jul 2027 FG-80F-POE
FortiGate 60E-POE 14 Oct 2022 14 Oct 2027 FG-80F-POE
FortiGate Rugged 30D 31 Dec 2022 31 Dec 2027 No direct successor

End of support 2028–2031

Model End of order End of support Designated successor
FortiGate 800D 16 Apr 2023 16 Apr 2028 FG-600F / FG-900G
FortiGate 900D 16 Apr 2023 16 Apr 2028 FG-601F / FG-900G / FG-901G
FortiGate 1000D 16 Apr 2023 16 Apr 2028 FG-1000F / FG-900G
FortiGate 3200D 16 Apr 2023 16 Apr 2028 FG-3001F / FG-3201F
FortiGate 3600E / 3601E 15 Apr 2024 15 Apr 2029 FG-3200F / FG-3700F
FortiGate 3400E / 3401E 16 Apr 2025 16 Apr 2030 FG-3000F / FG-3001F
FortiGate Rugged 35D 16 Apr 2025 16 Apr 2030 No direct successor
FortiGate 2000E 2 May 2025 2 May 2030 FG-1801F
FortiGate 200E / 201E 13 Oct 2025 13 Oct 2030 FG-200G / FG-201G
FortiGate 400E / 401E 13 Oct 2025 13 Oct 2030 FG-400F / FG-401F
FortiGate 6300F 13 Jan 2026 13 Jan 2031 FG-7000 series
FortiGate 200F / 201F 1 Mar 2026 1 Mar 2031 FG-200G / FG-201G
FortiGate 6500F 15 Apr 2026 15 Apr 2031 FG-7000 series
FortiGate 100F / 101F 16 Apr 2026 16 Apr 2031 FG-120G / FG-121G / FG-90G
FortiGate 600F / 601F 1 May 2026 1 May 2031 FG-700G / FG-900G
FortiGate 70F 17 May 2026 17 May 2031 FG-70G
FortiGate 1101E 30 Jul 2026 30 Jul 2031 FG-1001F / FG-1801F
FortiGate 1100E 13 Sep 2026 13 Sep 2031 FG-1000F / FG-1800F
FortiGate Rugged 60F 13 Oct 2026 13 Oct 2031 FG-Rugged 70F

Source for all dates: Fortinet’s official Product Life Cycle portal. A handful of models (FG-30E, FG-50E, FG-60D) show minor date variations between Fortinet’s factory milestones and regional distributor cut-offs; the table follows the official lifecycle records. Note that the 2026 F-series end-of-order wave has already begun: the popular FG-100F stopped being orderable on 16 April 2026, which started its five-year countdown. The FG-40F, FG-60F/61F, FG-80F/81F, FG-400F, FG-600E and the G-series have no announced dates yet.

What to do at each lifecycle stage

Model still active, no EOO announced. Nothing urgent, but note the firmware ceiling: 2 GB RAM models like the FG-40F and FG-60F already lose proxy features under FortiOS 7.4/7.6 and drop into conserve mode under load. The hardware date is not the real deadline for these units.

Between EOO and LSED. You can still renew support. This is the window to make an architecture decision rather than an emergency purchase. Diarise the LSED: it is the last exit with options.

Between LSED and EOS. No renewals possible; your contract runs down with the clock. Fortinet applies commercial pressure here as well, with renewal surcharges on retiring models and RMA fulfilment becoming dependent on remaining parts stock. Plan the replacement or migration now, not at EOS.

Past EOS. The device still routes packets, which is precisely the problem: it looks alive while receiving no patches for newly discovered flaws. Every CVE published from that day on is permanent. If decommissioning takes time, isolate the device from the internet-facing edge and put a migration date on paper; under NIS2, a documented plan is the minimum defensible position (our legacy VPN end-of-life watchlist covers the same logic for remote-access appliances).

The real risk of running past end of support

Perimeter appliances are the most attacked category of enterprise hardware, and Fortinet’s record illustrates why the patch supply matters. Over two dozen Fortinet vulnerabilities appear in CISA’s Known Exploited Vulnerabilities catalogue, and at least 13 of them have been used in ransomware operations. The pattern is consistent: authentication bypasses in the management plane (CVE-2022-40684, CVE-2024-55591) and pre-authentication memory corruption in edge daemons (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) that hand an unauthenticated attacker root on the device that terminates your VPN sessions and holds your routing table.

On a supported appliance, each of these gets an emergency patch. On a post-EOS appliance, none of them ever will. And because the firewall sits on the routing boundary itself, no internal segmentation protects it: compromise of the perimeter OS gives an attacker Layer 3 reach into every subnet behind it. That architectural exposure is the same story we documented when Fortinet deprecated its SSL VPN: the features change, the attack surface logic does not.

For European organisations there is a regulatory floor under this. NIS2’s Article 21 duty of care requires active vulnerability handling; Belgium’s CyFun framework classifies unsupported hardware without a documented exception as unauthorised. A perimeter firewall that can no longer be patched is difficult to defend in an audit and increasingly difficult to defend to a cyber insurer.

Successor appliance, or exit the refresh treadmill?

When your model’s date approaches, there are two honest paths.

Track one: buy the successor. Fortinet’s TradeUp programme discounts replacement hardware by typically 36–38% (promotions occasionally reach 50–55%) and lets you transfer remaining FortiCare/FortiGuard time, provided you buy the replacement as standalone hardware rather than a bundle. The trade-in permanently retires the old serial number. Budget-wise, branch-grade bundles such as an FG-60F with one year of UTP start around €1,490 ($1,600); a mid-market FG-120G runs roughly €1,490–€3,220 ($1,620–$3,500) for hardware alone and €4,140–€6,440 ($4,500–$7,000) with multi-year security bundles; campus-class units scale from €4,600 to over €13,800 ($5,000–$15,000) before high-availability pairing doubles the hardware.

The hidden costs sit outside the quote: FortiCare renewals on ageing models rise by double-digit percentages annually, cross-generation config migration via FortiConverter still demands manual remediation of interface mappings and deprecated proxy features, and the whole exercise repeats in five years. That is the treadmill.

Track two: move the functions, not the box. The jobs a FortiGate does at a mid-market perimeter (firewalling, secure remote access, web filtering, site-to-site connectivity) can move to a cloud-delivered SASE platform with ZTNA. That swaps open inbound listening ports for outbound-only connectors, network-level VPN access for per-application least privilege, and the five-year hardware cycle for a subscription with no appliance to patch. For teams weighing this against staying on FortiGate, we have laid out the comparison points in FortiGate WireGuard vs ZTNA and the cost mechanics in what FortiGate customers actually pay for FortiSASE.

Dimension Successor appliance Cloud-delivered SASE / ZTNA
Inbound attack surface Public IP with listening VPN/management daemons No inbound listening ports; outbound-only connectors
Access model Network-level tunnel, broad subnet reach Per-application, identity-gated least privilege
Patching burden Yours: firmware cycles, emergency CVE windows Vendor-managed cloud platform
Capacity Fixed RAM/throughput; conserve mode under load Elastic, no hardware ceiling
Lifecycle New EOO/EOS countdown every 3–5 years No appliance lifecycle

The honest case for just buying the next FortiGate

Plenty of capable admins will read the tables above and order an FG-90G before lunch, and their reasoning deserves a straight answer. The TradeUp discount is real and the remaining subscription time carries over. Your team knows FortiOS, your reseller relationship works, and the config migrates within the ecosystem. ASIC throughput on the new silicon is genuinely excellent for east-west traffic.

All true. What the like-for-like refresh does not change is the model itself. The new box has the same open listening ports facing the internet, the same emergency-patch obligation when the next KEV entry lands, the same fixed capacity, and its own EOO announcement already waiting somewhere in a future quarterly bulletin. Meanwhile most mid-market traffic now runs north-south to cloud applications, where hairpinning through an on-premise appliance adds latency rather than protection. If you have survived one forced Fortinet migration already, you know how much unplanned work the treadmill generates; we wrote up those lessons in you survived the Fortinet VPN migration, now what?. The refresh decision is really a decision about whether you want to be having this same conversation again in 2031.

Check your date, then choose your track

Find your model in the tables, note the LSED, and work backwards: a calm migration takes a quarter, an emergency one takes a weekend and a year of cleanup. If the date is close and you are weighing the treadmill against a platform approach, that is exactly the conversation we have daily with EU mid-market teams. Jimber delivers full SASE (ZTNA network isolation, secure web gateway, firewall-as-a-service and SD-WAN) from a single EU-sovereign platform at a predictable flat rate, with no appliance to patch and no end-of-support countdown. Book a demo and we will map your FortiGate estate’s dates against a concrete migration plan, or explore how the platform works first.

Frequently asked questions

When does the FortiGate 60E reach end of support?

The FortiGate 60E reached end of order on 29 December 2021 and reaches end of support on 29 December 2026. Its last service extension date passed on 29 December 2025, so existing support contracts can no longer be renewed or extended: whatever contract is active today is the final one.

Is the FortiGate 60F end of life?

No. Fortinet has not announced an end-of-order date for the FortiGate 60F, and once it does, hardware support continues for five years. The practical constraint arrives sooner: with 2 GB of RAM, the 60F loses proxy-based inspection features under FortiOS 7.4/7.6 and can drop into conserve mode under heavy load.

When does support end for the FortiGate 100E and 80E?

Both the FortiGate 100E and FortiGate 80E reached end of support on 17 August 2026, five years after their shared end-of-order date of 17 August 2021. Since that date Fortinet issues no security patches, provides no technical support and fulfils no RMA replacements for either model.

What is the difference between end of order and end of support?

End of order (EOO) is the last date an appliance can be bought new through authorised channels; Fortinet announces it at least 90 days ahead. End of support (EOS) falls exactly 60 months later and terminates everything at once: firmware patches, FortiGuard updates, technical assistance and hardware replacement.

Can I keep using a FortiGate after its end-of-support date?

The appliance keeps routing traffic, but every vulnerability discovered after EOS remains permanently unpatched on an internet-facing device. FortiGuard signature ingestion stops, and under NIS2 and Belgium’s CyFun framework an unsupported perimeter device without a documented exception is treated as unauthorised, which also weakens your cyber insurance position.

Can I transfer my FortiGuard licence through the TradeUp programme?

Yes. Remaining FortiCare and FortiGuard subscription time transfers to the replacement unit, but only if the new device is purchased as standalone hardware rather than a promotional bundle. The old serial number is permanently retired in FortiCloud and may not be redeployed in production.

Do I have to return the old firewall after a TradeUp?

No physical return is required. The traded-in serial number is permanently retired in Fortinet’s licensing systems, and the customer contractually agrees not to reuse, resell or redeploy the retired appliance in commercial production. Plan secure disposal, including wiping configurations and stored credentials.

Why is running an unsupported firewall a NIS2 problem?

NIS2 Article 21 requires active vulnerability handling and basic cyber hygiene. A post-EOS firewall cannot receive patches for new CVEs, so keeping it at the perimeter means knowingly operating an unpatchable system at your most exposed point. That is a duty-of-care failure for which management can be held personally accountable.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed