Twelve SonicWall models reach End of Support on 1 October 2026, after the TZ 400, TZ 600, NSA 3600 and NSa 3650 went on 1 August. Every Generation 6 and 6.5 appliance is permanently capped on SonicOS 6.5.4.x, because the processor architecture cannot run SonicOS 7. The full model tables, the firmware ceiling and the exploitation record are below.
If you are reading this because a renewal quote arrived with a surcharge on it, or because a support case was refused, the date you need is probably 1 October 2026. It takes twelve SonicWall models with it: the SOHO 250 and SOHO 250W, the TZ 350, TZ 500 and their wireless variants, the NSA 4600, 5600 and 6600, and the NSa 4650, 5650 and 6650. The wave before it has already landed — the TZ 400, the TZ 600 and the NSa 3650 reached End of Support on 1 August 2026.
Every reseller page will now offer you a successor SKU. What almost none of them explain is the second constraint, which for these appliances is more decisive than the date: the hardware cannot run the current operating system, and never will be able to. A Generation 6 firewall is not waiting for a firmware release. It is architecturally excluded from one. That distinction is what turns “buy the next box” from an administrative task into a decision worth ten minutes of thought.
This page publishes the complete model table, the SonicOS ceiling per generation, what actually stops at End of Support, and the exploitation record — stated as dates, without embellishment. Jimber sells an alternative to edge appliances, so read the last two sections with that in mind. The tables above them are SonicWall’s own figures.
What each SonicWall lifecycle milestone stops
SonicWall runs a five-stage retirement process, and the stage names are not self-explanatory. Last Order Day is the final date the model can be bought. Active Retirement Mode ends manufacturing but keeps support contracts orderable and bug fixes flowing. Limited Retirement Mode ends feature development, restricting code changes to critical bug fixes and high-severity security issues. End of Support ends technical support, firmware development and warranty replacement. A fifth stage, Deactivation, exists only for the SMA 100 series.
Two of these matter more than the others in practice.
Limited Retirement Mode is where an appliance stops improving. It begins two years after Active Retirement Mode and runs for three years. Everything in the Generation 6 and 6.5 estate that reaches End of Support in 2026 entered Limited Retirement Mode in 2023 or 2024. Those appliances have not received a functional change in years, and the code maintenance they do receive is restricted to critical issues only.
The 1-Year Support Last Order Day is the real deadline. It falls twelve months before End of Support and it is the last date a support contract can be bought at all. Once it passes, there is no mechanism to extend coverage, at any price. For the models retiring on 1 October 2026, that date was 30 September 2025 — it has already gone. If you did not buy the final contract then, the appliance is running uncovered now, not in October.
Every SonicWall TZ and SOHO model, with its dates
Sorted by End of Support, earliest first. Generation is listed explicitly because SonicWall’s model numbering repeats across generations: a TZ 300 and a TZ 370 are not the same product family, and a TZ 400 is not a smaller TZ 470.
Last verified: September 2026.
| Model | Gen | Last Order Day | 1-Year Support LOD | End of Support | Last supported SonicOS | Named successor |
|---|---|---|---|---|---|---|
| TZ 300 / TZ 300W | Gen 6 | 22 January 2020 | 22 January 2024 | 23 January 2025 | SonicOS 6.5.4.14 | TZ 370 / TZ 370W |
| SOHO | Gen 6 | 22 January 2020 | 15 April 2025 | 16 April 2026 | SonicOS 6.5.x | TZ 80 / TZ 280 |
| SOHOW | Gen 6 | 15 April 2022 | 15 April 2025 | 16 April 2026 | SonicOS 6.5.x | TZ 280W |
| TZ 300P | Gen 6 | 15 April 2022 | 15 April 2025 | 16 April 2026 | SonicOS 6.5.4.14 | TZ 280P / TZ 370 |
| TZ 400 | Gen 6 | 15 April 2022 | 31 July 2025 | 1 August 2026 | SonicOS 6.5.4.14 | TZ 470 / TZ 480 |
| TZ 400W | Gen 6 | 31 July 2021 | 31 July 2025 | 1 August 2026 | SonicOS 6.5.4.14 | TZ 470W / TZ 480W |
| TZ 600 / TZ 600P | Gen 6 | 15 April 2022 | 31 July 2025 | 1 August 2026 | SonicOS 6.5.4.14 | TZ 670 |
| SOHO 250 | Gen 6 | 31 July 2021 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.x | TZ 270 / TZ 280 |
| SOHO 250W | Gen 6 | 31 July 2021 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.x | TZ 270W / TZ 280W |
| TZ 350 / TZ 350W | Gen 6 | 15 April 2022 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.14 | TZ 370 / TZ 370W |
| TZ 500 / TZ 500W | Gen 6 | 15 April 2022 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.14 | TZ 570 / TZ 570W |
| TZ 270 / TZ 270W | Gen 7 | 30 June 2026 | Not announced | Not announced | SonicOS 7.x | TZ 280 / TZ 280W |
| TZ 470 / TZ 470W | Gen 7 | 30 June 2026 | Not announced | Not announced | SonicOS 7.x | TZ 480 / TZ 480W |
| TZ 370 / TZ 370W | Gen 7 | Active production | — | — | SonicOS 7.x | — |
| TZ 570 / TZ 570W / TZ 570P | Gen 7 | Active production | — | — | SonicOS 7.x | — |
| TZ 670 | Gen 7 | Active production | — | — | SonicOS 7.x | — |
Source: SonicWall Product Life Cycle Tables and the individual End of Support notifications on SonicWall’s product notification portal. The TZ 270 and TZ 470 Last Time Buy announcement followed the launch of the Generation 8 TZ 280 and TZ 480 in August 2025; SonicWall has published the Last Order Day for those two models but not the subsequent milestones, so those cells read “not announced” rather than carrying an estimate.
One correction worth making explicitly, because it circulates on reseller blogs: the TZ 370, TZ 570 and TZ 670 have not entered Last Time Buy. They remain in active distribution with active firmware development.
Every NSA, NSa, NSsp and SuperMassive model, with its dates
SonicWall’s mid-range and enterprise firewalls retire in five waves between February and October 2026. The SuperMassive 9200 to 9800 go first, then the NSa 9250, 9450 and 9650, the NSa 2650, the NSA 3600 and NSa 3650, and finally the NSA 4600 to 6600 with the NSa 4650 to 6650. Every one is capped on SonicOS 6.5.4.x.
Last verified: September 2026.
| Model | Gen | Last Order Day | 1-Year Support LOD | End of Support | Last supported SonicOS | Named successor |
|---|---|---|---|---|---|---|
| NSA 2600 | Gen 6 | 17 April 2018 | 17 April 2022 | 18 April 2023 | SonicOS 6.5.4.x | NSa 2650 / NSa 2700 |
| SuperMassive 9200 / 9400 / 9800 | Gen 6 | 19 February 2022 | 19 February 2025 | 20 February 2026 | SonicOS 6.5.4.x | NSsp 10700 / NSsp 11700 |
| NSa 9250 | Gen 6.5 | 15 April 2022 | 15 April 2025 | 16 April 2026 | SonicOS 6.5.4.13 | NSa 3800 / NSa 4800 |
| NSa 9450 | Gen 6.5 | 15 April 2022 | 15 April 2025 | 16 April 2026 | SonicOS 6.5.4.13 | NSa 4800 / NSa 5800 |
| NSa 9650 | Gen 6.5 | 15 April 2022 | 15 April 2025 | 16 April 2026 | SonicOS 6.5.4.13 | NSa 5800 / NSa 6800 |
| NSa 2650 | Gen 6.5 | 15 April 2022 | 30 April 2025 | 1 May 2026 | SonicOS 6.5.4.13 | NSa 2700 / NSa 2800 |
| NSA 3600 | Gen 6 | 2 March 2021 | 31 July 2025 | 1 August 2026 | SonicOS 6.5.4.x | NSa 3700 / NSa 3800 |
| NSa 3650 | Gen 6.5 | 15 April 2022 | 31 July 2025 | 1 August 2026 | SonicOS 6.5.4.13 | NSa 3700 / NSa 3800 |
| NSA 4600 | Gen 6 | 2 March 2021 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.x | NSa 4700 / NSa 4800 |
| NSA 5600 | Gen 6 | 2 March 2021 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.x | NSa 5700 / NSa 5800 |
| NSA 6600 | Gen 6 | 2 May 2021 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.x | NSa 6700 / NSa 6800 |
| NSa 4650 | Gen 6.5 | 15 April 2022 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.13 | NSa 4700 / NSa 4800 |
| NSa 5650 | Gen 6.5 | 15 April 2022 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.13 | NSa 5700 / NSa 5800 |
| NSa 6650 | Gen 6.5 | 15 April 2022 | 30 September 2025 | 1 October 2026 | SonicOS 6.5.4.13 | NSa 6700 / NSa 6800 |
| NSa 2700 | Gen 7 | 31 October 2025 | 31 October 2029 | 1 November 2030 | SonicOS 7.x | NSa 2800 |
| NSa 3700 | Gen 7 | 31 October 2025 | 31 October 2029 | 1 November 2030 | SonicOS 7.x | NSa 3800 |
| NSa 4700 | Gen 7 | Active production | — | — | SonicOS 7.x | NSa 4800 |
| NSa 5700 | Gen 7 | Active production | — | — | SonicOS 7.x | NSa 5800 |
| NSa 6700 | Gen 7 | Active production | — | — | SonicOS 7.x | NSa 6800 |
| NSsp 10700 / NSsp 11700 | Gen 7 | Active production | — | — | SonicOS 7.x | — |
| NSsp 13700 / NSsp 15700 | Gen 7 | Active production | — | — | SonicOS 7.x | — |
Note the NSA 3600 and the NSa 3650 in adjacent rows. They share an End of Support date and nothing else — different generation, different firmware branch number, different silicon. The same applies to the 4600/4650, 5600/5650 and 6600/6650 pairs. Reading the wrong row is the most common error on this table.
The SMA appliances, and the one that was switched off
SonicWall’s remote access line is in three states. The SMA 200 and SMA 400 ended support on 1 September 2021. The SMA 210, 410 and 500v were not merely retired but actively switched off on 31 October 2025. Only the SMA 1000 platform — the 6210, 7210 and 8200v — remains in production.
Last verified: September 2026.
| Model | Platform | Last Order Day | End of Support | Last supported OS | Named successor |
|---|---|---|---|---|---|
| SMA 200 / SMA 400 | Gen 5 | 31 August 2016 | 1 September 2021 | SMA OS 9.x | SMA 210 / SMA 410 |
| SMA 210 / SMA 410 / SMA 500v | Gen 7 | 31 October 2024 | 31 October 2025 (deactivated) | SMA OS 10.2.2.1 | Cloud Secure Edge |
| SMA 6200 / SMA 7200 | SMA 1000 | Retired | Retired | SMA OS 12.x | SMA 6210 / SMA 7210 |
| SMA 6210 / SMA 7210 / SMA 8200v | SMA 1000 | Active production | — | SMA OS 12.4+ | — |
The SMA 100 row is the only entry in this entire article where a vendor did not merely stop supporting a product but actively turned it off. SonicWall accelerated the End of Support date and enforced a shutdown through central licensing on 31 October 2025, after CVE-2025-40596 and CVE-2025-40597 established that the platform could not be reliably defended. We covered the consequences separately in the permanent deactivation of the SonicWall SMA 100 series.
Why a Generation 6 firewall can never run SonicOS 7
Generation 6 and 6.5 SonicWall appliances cannot be upgraded to SonicOS 7.x or 8.x, and no future release will change that. The constraint is the processor: SonicOS 6.5 runs on Cavium OCTEON network processors using the MIPS instruction set, while SonicOS 7 was rebuilt as a containerised Linux core for x86-64. The gap is architectural, not a matter of vendor policy.
This is the question the top search results do not answer, and it is the one that determines whether a refresh is a like-for-like swap or a change of architecture. Here is what the branches actually differ on.
| Attribute | SonicOS 6.5 | SonicOS 7.x | SonicOS 8.x |
|---|---|---|---|
| Hardware generations | Gen 5, Gen 6, Gen 6.5 | Gen 7 hardware and NSv | Gen 8 hardware (TZ 80/280/480, NSa 2800 and up) |
| Microarchitecture | 32-bit and 64-bit MIPS (Cavium OCTEON) | x86-64 multi-core with dedicated ASICs | Next-generation distributed x86-64 multi-core |
| Kernel | Proprietary real-time executive | Modular Linux-based core container | Hardened micro-kernel with isolated daemons |
| Firmware maintenance | Frozen in Limited Retirement Mode | Active feature and security maintenance | Active strategic engineering target |
| Policy model | Zone-to-zone matrix | Unified Policy Mode and Classic Mode | Unified contextual policy architecture |
| Identity | Legacy LDAP, RADIUS, static TOTP | Native SAML 2.0 from 7.2.0 | Native cloud identity, SAML 2.0, FIDO2 |
| Central management | Legacy GMS (support ends 30 September 2026) | NSM 3.0 / 4.x SaaS and on-premises | Cloud-native NSM Zero-Touch 2.0 |
Three consequences follow, and they are operational rather than theoretical.
No native SAML. SonicWall added native SAML 2.0 to SonicOS only in release 7.2.0. A Generation 6 or 6.5 firewall authenticating SSL VPN users has LDAP and RADIUS pass-through and nothing else, which means no conditional access and no modern identity provider policy on your remote access layer.
No management platform after 30 September 2026. SonicWall’s Global Management System entered Active Retirement Mode on 5 May 2025 and support ends on 30 September 2026. Analytics On-Prem follows, with Last Day of Order on 31 January 2026 and End of Support on 31 January 2028. The successor is Network Security Manager, which does manage Generation 6 devices, but zero-touch provisioning, contextual policy templates and full API management are Generation 7 and 8 only.
Patch backporting is discretionary. When a vulnerability lands in a shared component, the fix is built and validated for the active branches. Bringing it back to 6.5 requires dedicated engineering against deprecated toolchains. Critical items get that effort. High-risk logic flaws and regressions that fall short of critical frequently do not.
What actually happens to subscriptions, RMA and support after the date
Security services do not switch off on the End of Support date. As long as a licence is active, the appliance carries on downloading threat signatures. What ends is everything around them: technical support for the hardware and for the services running on it, firmware development, software hotfixes and Return Materials Authorization coverage.
The practical shape of that is worth stating plainly. If a signature update destabilises the inspection engine on an End of Support appliance — and signature updates do occasionally destabilise inspection engines — SonicWall will decline the case. The resolution offered is supported hardware, at your expense. You are running a device that still receives changes from the vendor but has no route to report a problem with them.
Unused entitlement time is generally transferable to a replacement unit on a 1:1 basis, but it is not automatic. The transfer has to be requested administratively and the serial numbers linked in MySonicWall. Community reports are consistent on this point: licences that were assumed to follow the hardware did not.
Cost has moved too. From 1 August 2024 SonicWall raised security service subscriptions — AGSS and EPSS — by up to 40% for Generation 6 firewalls, against up to 10% for Generation 7. Extending a legacy appliance is now deliberately more expensive than replacing it, which is the intended effect. If you are modelling the alternatives, the comparison belongs next to the figures in managed firewall pricing models and support surcharges.
The exploitation record, stated as dates
The following are the documented vulnerabilities affecting SonicWall edge services between 2024 and 2026, with CVSS scores, the vendor advisory identifier and the CISA Known Exploited Vulnerabilities listing date where one exists. They are listed because lifecycle decisions about internet-facing appliances should account for the exposure history of the service being exposed, and for no other reason.
| CVE | CVSS | Advisory | CISA KEV listing | Affected | Mechanism |
|---|---|---|---|---|---|
| CVE-2024-40766 | 9.3 (SonicWall) / 9.8 (NVD) | SNWLID-2024-0015 | 9 September 2024 | Gen 5 below 5.9.2.14-12o, Gen 6 below 6.5.4.14, Gen 7 below 7.0.1-5035 | Improper access control in SonicOS management and SSL VPN handlers |
| CVE-2024-40764 | 7.5 | SNWLID-2024-0012 | Not listed | Gen 6 NSv below 6.5.4.4-44v, Gen 7 below 7.0.1-5151 and 7.1.1-7051 | Heap buffer overflow in the IPsec tunnel daemon, denial of service |
| CVE-2024-12802 | 6.5 | SNWLID-2025-0001 | Not listed | Gen 7 on SonicOS 7.x with Active Directory | Multi-factor authentication bypass via UPN and SAM account parsing |
| CVE-2024-53704 | 8.2 (SonicWall) / 8.3 (NVD) | SNWLID-2025-0003 | 18 February 2025 | Gen 7 appliances and NSv on SonicOS 7.1.1-7058 and 7.1.2-7019 | Improper authentication enabling remote SSL VPN session hijacking |
| CVE-2025-40596 | 8.6 | SNWLID-2025-0012 | Product line deactivated | SMA 100 series on 10.2.2.1-89 and earlier | Stack buffer overflow in the SMA 100 API handler |
| CVE-2025-40597 | 8.6 | SNWLID-2025-0012 | Product line deactivated | SMA 100 series on 10.2.2.1-89 and earlier | Heap buffer overflow in the appliance management subsystem |
| CVE-2025-40600 | 7.5 | SNWLID-2025-0013 | Under review | Gen 7 appliances on active SonicOS 7.x firmware | Externally controlled format string in the SSL VPN listener |
Source: SonicWall PSIRT advisories and the CISA Known Exploited Vulnerabilities catalogue. Verify current status against both before acting on any row.
Two observations that the dates support, and nothing beyond them.
First, patching was not always sufficient. In the CVE-2024-40766 campaigns, Akira and Fog ransomware affiliates reached environments where firmware had been applied but local firewall accounts lacked multi-factor authentication or management remained bound to the WAN interface. Incident response reporting from Mandiant and Arctic Wolf places the window from initial access to domain compromise at 24 to 72 hours. Macnica and the SANS Internet Storm Center counted more than 48,900 exposed, unpatched SonicWall devices in December 2024.
Second, the newer generation is not exempt. CVE-2024-53704 affected Generation 7 appliances on current firmware, carried a public proof of concept, and entered the CISA catalogue on 18 February 2025. CVE-2025-40600 affects active SonicOS 7.x. This is a property of exposing an authentication service on a public interface, not a property of old hardware — which is precisely why the refresh question is not settled by the refresh.
Separately, SonicWall disclosed on 17 September 2025 that attackers had brute-forced the MySonicWall cloud backup repositories and harvested customer firewall configuration files, affecting roughly 5% of accounts. If your configuration backups lived there, treat the credentials and pre-shared keys in them accordingly. The pattern across all of it is documented more broadly in the systemic deprecation of perimeter SSL VPN.
The migration itself is a documented risk
One finding from 2025 remediation reviews deserves its own paragraph, because it inverts the intuition that new hardware ends the problem. Organisations that refreshed from Generation 6 to Generation 7 using SonicWall’s automated Configuration Migration Tool suffered intrusions despite running patched Generation 7 firmware.
The cause was configuration inheritance. The tool transferred local user databases and password hashes without forcing credential resets or multi-factor parity, and administrators importing old rule sets carried over policies that bypassed brute-force mitigations native to SonicOS 7.3. Attackers scanned exposed NetExtender endpoints and replayed credentials that had simply moved to a newer box.
Field consensus on r/sonicwall and r/msp is blunt about the tool for other reasons too: corrupted NAT policies, dropped application control rules, misconfigured zone boundaries, missing address objects. The recommendation that keeps recurring is to rebuild the configuration by hand. Budget for that. A manual rebuild is not a defect of the plan; on this transition it is the plan.
Deciding what replaces it
For a single site with local servers, VLAN segmentation that matters, and an existing SonicWall skill set, a trade-up to Generation 7 or 8 through Secure Upgrade Plus is a reasonable answer. It preserves the topology, transfers the remaining support balance 1:1, and gives you multi-gigabit inspection on hardware that is architecturally current. SonicProtect subscriptions, introduced in July 2024, are transferable across three and five-year terms, so a five-year subscription activated on a TZ 400 in 2024 covers it to the August 2026 date and then moves to the replacement.
Where the calculation changes is remote access. Every hardware firewall that terminates remote users requires an inbound listener on a public address, and that listener is what the last two years of advisories are about. Replacing the appliance replaces the hardware; it does not remove the listener. If the refresh is being driven by a date rather than by a capacity problem, it is worth asking whether the remote-access layer has to move with the hardware at all — a question we work through in migrating from SonicWall to cloud-native ZTNA.
The European regulatory position is straightforward enough to state in two sentences. NIS2 Article 21 requires vulnerability handling, supply chain security and multi-factor authentication as risk-management measures, and an appliance with no patch route does not satisfy the first of those. The Belgian CyFun framework requires verified asset tracking and the elimination of internet-facing management interfaces, which is an audit question with a yes-or-no answer about your current configuration. Financial entities have the same obligation under DORA Articles 6 and 24.
The 2026 concentration of dates across this estate is part of a wider pattern set out in the 2026 cliff for legacy network perimeter infrastructure, and if you also run WatchGuard hardware the equivalent table is in the full Firebox end-of-life dates.
Steelman: why the MSP with a hundred TZ units should trade up
If you run a managed firewall practice on SonicWall, the case for Secure Upgrade Plus is stronger than a vendor of the alternative will usually admit. Three arguments, taken seriously.
Your clients’ networks are not cloud-shaped. A manufacturing site with PLCs, a clinic moving imaging files to a local server, a branch that depends on Layer 2 discovery — these environments run on local topology. Trading up preserves it and raises throughput. Re-engineering them around a cloud-delivered architecture is a project per site, and you would be funding it out of margin on contracts that are already priced.
Operational standardisation is most of your gross margin. Your engineers know SonicOS. They build HA pairs without thinking, read the logs fluently, and resolve tickets at first contact. You run the fleet from NSM with templates, scheduled firmware rollouts and PSA integration. Introducing a second platform does not add a platform; it splits every runbook, every escalation path and every training plan in two, and it does so during the transition year when you can least afford the ticket time. Staying on one vendor protects the margin structure that the practice is built on.
Capital predictability. Secure Upgrade Plus is a discounted box, a transferred support balance and a fixed multi-year term. A per-user monthly subscription scales with your client’s headcount, which means your cost of delivery grows when their business grows — and on a fixed-fee managed contract, that is your problem rather than theirs until renewal. Some clients in manufacturing, logistics and healthcare also require hardware-enforced isolation between internal subnets and untrusted devices, and a physical firewall at the facility edge delivers that deterministically.
The honest counterweight is narrower than the argument against it. A trade-up starts another depreciation cycle on hardware that will itself reach Last Order Day inside five years — the NSa 2700 and NSa 3700, launched into this generation, already have theirs. It leaves the inbound listener in place. And it does not resolve the identity problem, only moves it to a platform where SAML is available if you then do the work.
None of that makes the trade-up wrong for a hundred-unit fleet. It does mean the decision should be made once, deliberately, rather than repeated as a default at every model’s End of Support date. If you are weighing how a service model changes rather than which box to buy, that is the subject of how MSPs deliver managed SASE without tool sprawl.
What to do this week
Pull the serial numbers, match them against the tables above, and separate the estate into three groups: past End of Support, reaching it on 1 October 2026, and still covered. For anything in the first two groups, check whether the 1-Year Support Last Order Day has passed, because that determines whether extending is even possible. Then check one thing on every remaining Generation 6 appliance: whether the management interface is reachable from the WAN. That is the control both the exploitation record and a CyFun assessment turn on, and it costs nothing to fix today.
For the appliances that need replacing, the useful question is not which successor SKU the table names. It is whether the remote-access layer should move onto the new appliance at all, or off the edge entirely. Jimber runs that layer as a single EU-sovereign platform with no inbound listener to expose. If you want to see what that looks like against your current topology, book a demo, or talk to us about the estate you are holding. The alternative-to-a-firewall case is set out at jimber.io/use-cases/firewall-alternative.
Frequently asked questions
When does the SonicWall TZ 400 reach end of life?
The TZ 400 and TZ 400W reached End of Support on 1 August 2026. Technical support, firmware security updates and RMA hardware replacement all ended on that date. The 1-Year Support Last Order Day was 31 July 2025, so no further support contract can be bought. SonicWall names the TZ 470 and the Generation 8 TZ 480 as successors.
Which SonicWall models reach end of support on 1 October 2026?
Twelve: the SOHO 250 and SOHO 250W, the TZ 350 and TZ 350W, the TZ 500 and TZ 500W, the NSA 4600, NSA 5600 and NSA 6600 from Generation 6, and the NSa 4650, NSa 5650 and NSa 6650 from Generation 6.5. Their final support contracts had to be purchased by 30 September 2025.
Can a SonicWall Generation 6 firewall be upgraded to SonicOS 7?
No, and no future release will change this. Generation 6 and 6.5 appliances run Cavium OCTEON processors on the MIPS instruction set, while SonicOS 7 is a containerised Linux core built for x86-64. The hardware lacks the memory, register architecture and virtualisation primitives the newer branch needs, so these models stay on SonicOS 6.5.4.x permanently.
Do security subscriptions stop working at end of support?
No. With an active licence the appliance continues downloading threat signatures past the date. What ends is technical support for the hardware and the services on it, firmware development, software hotfixes and RMA coverage. If a signature update destabilises the inspection engine, SonicWall will decline the case and direct you to supported hardware.
Why did SonicWall deactivate the SMA 100 series?
SonicWall accelerated the End of Support date and enforced a shutdown on 31 October 2025 after CVE-2025-40596 and CVE-2025-40597, two memory corruption flaws in the appliance API and management subsystem, established that the legacy codebase could not be reliably defended. Customers were directed to Cloud Secure Edge or SMA 1000 hardware.
Can I transfer remaining subscription time to a replacement firewall?
Generally yes, on a 1:1 basis, but not automatically. The transfer must be requested administratively and the original serial number linked to the replacement during registration in MySonicWall, or handled through the Secure Upgrade Plus workflow. Balances that are assumed to follow the hardware routinely do not.
Is the SonicWall Gen 6 to Gen 7 migration tool safe to use?
Remediation reviews in 2025 found organisations compromised on patched Generation 7 firmware because the tool transferred local user databases and password hashes without forcing credential resets or multi-factor parity. It also corrupts NAT policies, drops application control rules and omits address objects. Rebuilding the configuration manually is the recommended approach.
What replaces the SonicWall NSa 2650?
SonicWall names the NSa 2700 as the direct successor, with the Generation 8 NSa 2800 above it. The NSa 2650 reached End of Support on 1 May 2026 and its 1-Year Support Last Order Day was 30 April 2025, so it is now running without a route to coverage.
Does running an end-of-support firewall breach NIS2?
NIS2 Article 21 requires vulnerability handling, supply chain security and multi-factor authentication as risk-management measures. An appliance with no patch route cannot satisfy vulnerability handling, which makes it a documented gap at assessment. Belgian CyFun additionally requires the elimination of internet-facing management interfaces, and financial entities carry equivalent obligations under DORA.
Have the TZ 370, TZ 570 and TZ 670 gone end of life?
No. Those three remain in active distribution with active firmware development. The confusion comes from two sources: the Last Time Buy announced for the TZ 270 and TZ 470 on 30 June 2026, and SonicWall’s portal metadata, which labels individual retired firmware builds as “End of Support” and reads as though the hardware is obsolete.