WatchGuard Firebox End of Life: Every T-Series and M-Series Date, and the Fireware Ceiling

If your Firebox model has just turned up on an end-of-life list, the date you need is probably one of three. Most of WatchGuard’s mainstream fleet — the T20, T40, T80, M270, M370, M470, M570 and M670 — reaches End-of-Life on 1 July 2028. A smaller group, the T15 and the T35 variants, stops on 1 March 2027. And the T35, T55 and T70 are already past it: their End-of-Life was 31 December 2025.
That is the part every page publishes. What none of them publish is the second clock, which for several of these appliances has already run out. A Firebox can be years away from End-of-Life and still be permanently locked out of the current Fireware branch, which means locked out of current security engines. The date tells you when support stops. The Fireware ceiling tells you what you are actually running until then.
What End-of-Sale and End-of-Life each stop
WatchGuard defines End-of-Sale as the last date distribution partners can purchase an appliance, and it falls up to five years before End-of-Life. End-of-Life is the absolute conclusion of technical support, software bug fixes, dynamic security signature updates and hardware warranty replacement. Active subscriptions are supported only until the End-of-Life milestone.
The practical difference matters more than the definitions suggest. Between the two dates nothing changes operationally: you keep getting firmware, you keep getting signatures, you can still open a case and you can still get an RMA. You simply cannot buy another one. After End-of-Life, the appliance keeps routing packets — the kernel does not stop — but every service that depends on a cloud feed stops with it.
What halts at End-of-Life, specifically:
- Gateway AntiVirus, Intrusion Prevention Service, WebBlocker, spamBlocker and botnet detection stop receiving definition updates. The appliance is deregistered from the update distribution network and the signature databases freeze on the day.
- Proxy policies configured with inspection actions start failing unpredictably. Depending on the proxy action, traffic through an expired engine either bypasses inspection entirely or drops legitimate sessions.
- Operating system hotfixes end, so a newly disclosed remote code execution flaw stays unpatched regardless of severity.
- RMA eligibility ends permanently, including for units with an active cold spare or unexpired service days.
- Access to software downloads on the WatchGuard portal is revoked.
- Firmware Vulnerability Alerts in WatchGuard Cloud, which flag active CVEs against your running build, are explicitly unsupported past End-of-Life.
That last one deserves attention. The tool that would tell you that your unsupported appliance has a critical vulnerability is switched off at exactly the moment the appliance becomes unpatchable.
Every Firebox model, with its dates
Sorted by End-of-Life date, earliest first. Tabletop and rugged models first, rackmount second.
Last verified: September 2026.
| Model | End-of-Sale | End-of-Life | Terminal Fireware branch | Successor |
|---|---|---|---|---|
| T10 / T10-W | 1 Apr 2020 | 30 Jun 2023 | v12.5.x (terminated) | T115-W |
| T30 / T30-W | 1 Apr 2020 | 30 Jun 2023 | v12.5.x (terminated) | Contact sales |
| T50 / T50-W | 1 Nov 2019 | 30 Jun 2023 | v12.5.x (terminated) | Contact sales |
| T10-D | 1 Nov 2019 | 1 Nov 2024 | v12.5.x (terminated) | T115-W |
| T35 / T35-W | 17 Jul 2021 / 31 Dec 2020 | 31 Dec 2025 | v12.5.x (terminated) | T125, T145 / T125-W, T145-W |
| T55 / T55-W | 31 Dec 2020 / 30 Sep 2021 | 31 Dec 2025 | v12.10.x / v12.12.x | T125, T145 / T125-W, T145-W |
| T70 | 30 Sep 2021 | 31 Dec 2025 | v12.10.x / v12.12.x | T145, T185 |
| T15 / T15-W | 1 Mar 2022 | 1 Mar 2027 | v12.5.x (capped) | T115-W |
| T35-DW | 1 Jul 2023 | 1 Mar 2027 | v12.5.x (capped) | T125-W, T145-W |
| T35-R (rugged) | 1 Jul 2023 | 1 Mar 2027 | v12.5.x (capped) | T125, T145 |
| T20 / T20-W | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | T115-W, T125 / T125-W |
| T40 / T40-W | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | T125, T145 / T125-W, T145-W |
| T80 | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | T145, T185 |
| T85-PoE | 1 Oct 2025 | 1 Jul 2031 (see note) | Fireware 2026.x / v12.12.x | T185 |
| T45 | 1 Apr 2025 | 1 Jul 2031 (see note) | Fireware 2026.x / v12.12.x | T145 |
| T45-W-PoE | 1 Feb 2026 | 1 Jul 2031 | Fireware 2026.x / v12.12.x | T145-W |
| T45-PoE | 1 Apr 2026 | 1 Jul 2031 | Fireware 2026.x / v12.12.x | T145 |
| T25 / T25-W | 1 Dec 2025 / 1 Apr 2026 | 1 Jul 2031 | Fireware 2026.x / v12.12.x | T125 / T125-W |
| Model | End-of-Sale | End-of-Life | Terminal Fireware branch | Successor |
|---|---|---|---|---|
| M200 / M300 | 1 Apr 2020 | 30 Jun 2023 | v12.5.x (terminated) | Contact sales |
| M400 / M500 | 1 Apr 2020 | 30 Jun 2023 | v12.5.x (terminated) | Contact sales |
| M440 | 1 Nov 2019 | 1 Nov 2024 | v12.10.x (terminated) | Contact sales |
| M4600 | 1 May 2023 | 1 May 2028 | Fireware 2026.x / v12.12.x | M695, M4850 |
| M5600 | 1 Jun 2025 | 1 May 2028 | Fireware 2026.x / v12.12.x | M4850, M5850 |
| M270 | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | M295 |
| M370 | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | M295, M395 |
| M470 | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | M395, M495 |
| M570 | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | M495, M595 |
| M670 | 1 Jul 2023 | 1 Jul 2028 | Fireware 2026.x / v12.12.x | M595, M695 |
| M590 | 1 Jun 2026 | 1 Jul 2031 | Fireware 2026.x / v12.12.x | M495 |
| M690 | 1 Jun 2026 | 1 Jul 2031 | Fireware 2026.x / v12.12.x | M595, M695 |
| M290 | 1 Aug 2026 | 1 Jul 2031 | Fireware 2026.x / v12.12.x | M295 |
| M390 | Not announced | Not announced | Fireware 2026.x / v12.12.x | M395 |
| Firebox Cloud / FireboxV | Continuous lifecycle | Continuous lifecycle | Fireware 2026.x / v12.12.x | Not applicable |
| Legacy XTM series (all) | Concluded | All past End-of-Life | v12.1.3 / v11.12.x (terminated) | Contact sales |
Source: WatchGuard Trust Center End-of-Life Policy, plus the individual End-of-Sale bulletins on the WatchGuard corporate blog. Verify against the Trust Center before acting on any date here.
A documented discrepancy worth knowing about. For two models, WatchGuard’s own sources disagree. The Trust Center lists the T45 at 1 July 2031, while the End-of-Sale bulletin for that model gives 1 January 2031. The Trust Center lists the T85-PoE at 1 July 2031, while its bulletin gives 31 December 2030. If you are building a compliance roadmap rather than a budget forecast, use the earlier date from the bulletin. Six months of assumed support is not a margin you want to discover you did not have during an audit.
The Fireware ceiling: the second clock nobody publishes
Six Firebox models are permanently capped on the Fireware v12.5.x maintenance branch and cannot run v12.6 or anything later: the T15, T15-W, T35, T35-W, T35-R and T35-DW. The cap is architectural, not commercial. These units run 32-bit ARM silicon or carry 1GB to 2GB of memory, and the mainline branch requires 64-bit multi-core hardware.
WatchGuard still supports the T15 and the T35-R to 1 March 2027, which reads on the Trust Center like ordinary support. It is not ordinary. Capped appliances receive only sporadic maintenance builds — v12.5.14, v12.5.16, v12.5.20 — whose purpose is to backport critical vulnerability fixes. Nothing else arrives.
What that costs you in practice:
- No modern cryptography or protocol work. New cipher suites and the TLS 1.3 offloading improvements built into mainline Fireware are absent from the v12.5.x kernel.
- No current telemetry. WatchGuard retired its TDR host-sensor ecosystem on 30 September 2023. Mainline devices moved to ThreatSync+ network detection and WatchGuard Cloud MDR integrations. Capped appliances lack the memory to run the local aggregation agents, so they moved nowhere.
- Orphaned DLP rules. WatchGuard deprecated the Fireware Data Loss Prevention service across all models on 26 February 2025, after its third-party scanning engine licence ended. On mainline releases the configuration panels were cleanly removed. On capped appliances the old DLP rules stay in the configuration store, producing silent proxy errors that look like faults and are not.
The reason this matters more than the End-of-Life date: a T35-R bought for a rugged site in 2023 has a support date in 2027 and a security posture from 2020. Nothing on WatchGuard’s lifecycle page tells you that, because lifecycle pages record support status, not capability.
Successor deltas: what you actually gain and lose
Three migrations cover most of the installed base. In each case the successor is a genuine improvement on throughput and a genuine change in hardware behaviour, and the second half is the part that breaks weekend cutovers.
T40 to T145
WatchGuard introduced the T45 as an interim model, but the non-PoE T45 reached End-of-Sale on 1 April 2025. The long-term successor to the T40 is the T145.
| Parameter | T40 | T45 (interim) | T145 |
|---|---|---|---|
| Firewall throughput (UDP 1518) | 3.40 Gbps | 3.94 Gbps | 3.90 Gbps |
| UTM full scan | 300 Mbps | 557 Mbps | ~650 Mbps (estimated) |
| VPN throughput (UDP 1518) | 880 Mbps | 1.58 Gbps | 1.80 Gbps |
| VPN throughput (IMIX) | 272 Mbps | 460 Mbps | 520 Mbps |
| Gateway AntiVirus | 586 Mbps | 874 Mbps | 1.10 Gbps |
| IPS (full scan) | 444 Mbps | 716 Mbps | 850 Mbps |
| Interfaces | 5 x 1GbE, PoE+ out on port 1 | 5 x 1GbE, PoE+ on PoE SKU only | 1 x 2.5GbE, 4 x 1GbE, 1 x SFP/SFP+ |
| VLANs | 30 | 30 | 50 |
The number that matters is 300 Mbps. That is the T40’s full UTM scan throughput, and it is below the speed of an ordinary European business fibre circuit. A site on 500 Mbps or 1 Gbps cannot run full inspection without throttling its own bandwidth, which is why a good many T40s are quietly running with inspection profiles switched off.
Two things to budget for. The base T40 shipped with 802.3at PoE+ on port 1 and could power an access point or camera directly; the base T45 removed power sourcing entirely and needs the separate T45-PoE SKU. And because the T145 changes interface naming and port layout, a T40 XML configuration will not restore cleanly — interfaces have to be remapped by hand.
M370 to M395
| Parameter | M370 | M390 | M395 |
|---|---|---|---|
| Firewall throughput (UDP 1518) | 8.0 Gbps | 18.0 Gbps | 20.0 Gbps |
| UTM full scan | 1.7 Gbps | 2.4 Gbps | 3.3 Gbps |
| VPN throughput (IMIX) | 1.4 Gbps | 1.8 Gbps | 2.2 Gbps |
| HTTPS content inspection | 662 Mbps | 1.32 Gbps | 1.90 Gbps |
| Interfaces | 8 x 1GbE fixed | 8 x 1GbE + module bay | 8 x 1GbE + module bay |
| Processor | Multi-core x86 | NXP LS2084A ARM | Multi-core ARM |
| Memory | 4GB non-ECC | 8GB ECC | 8GB+ ECC |
| VLANs | 200 | 250 | 300 |
This is the cleanest upgrade of the three, and the module bay is the real gain: the M370’s eight fixed copper ports could not terminate fibre without a media converter, while the M390 and M395 accept 4 x 1Gb copper, 4 x 1Gb SFP, 2 x 10Gb SFP+ or multi-speed modules. Two line items people forget on the purchase order: the modules are sold separately and the bay ships with a blank faceplate, and WatchGuard’s current rackmount chassis do not include regional AC power cords.
M270 to M295
| Parameter | M270 | M290 | M295 |
|---|---|---|---|
| Firewall throughput (UDP 1518) | 4.90 Gbps | 5.80 Gbps | 8.50 Gbps |
| UTM full scan | 800 Mbps | 1.18 Gbps | 1.80 Gbps |
| Gateway AntiVirus | 2.10 Gbps | 1.47 Gbps | 2.60 Gbps |
| HTTPS content inspection | 642 Mbps | 696 Mbps | 950 Mbps |
| Processor | Intel Atom C3000 x86 | NXP LS1046A quad-core ARM | Multi-core ARM |
| Memory | 4GB non-ECC | 4GB ECC | 8GB ECC |
| Concurrent connections | 2,000,000 | 3,500,000 | 4,000,000 |
Note the Gateway AntiVirus row. Moving from the M270 to the M290 drops single-engine AV throughput from 2.10 Gbps to 1.47 Gbps, a consequence of the shift from x86 to ARM silicon. Everything else went up. If your site leans on AV scanning specifically, the M290 is a downgrade on that axis and the M295 is the model that fixes it. This is the kind of thing that does not appear in a reseller comparison, because a reseller comparison shows the rows where the new box wins.
All throughput figures above come from WatchGuard’s published datasheets. Compare like with like: full-scan UTM figures and IMIX VPN figures are not interchangeable with UDP 1518 headline numbers.
What happens to your subscription, your RMA and your trade-up
If a three-year or five-year Total Security Suite contract runs past the hardware’s End-of-Life date, WatchGuard does not issue a refund and does not migrate the balance automatically. The remaining prorated days can be transferred, but only through a formal Customer Care case quoting the retired serial number, the new serial number and the active feature key details. Support validates the balance and issues an updated feature key that co-terms the remainder onto the replacement appliance. Nobody does this for you, and nobody reminds you.
On hardware replacement, three rules apply. Advance replacement is available for appliances under active Standard Support, Basic Security or Total Security, shipping next business day within the EU; the failed unit must return within 15 calendar days or the full list price of the replacement is invoiced and the account goes on credit hold. If your model is out of stock, WatchGuard may substitute an equivalent or superior chassis and transfer the feature keys itself — an M270 failure can be fulfilled with an M290. And RMA stops dead at End-of-Life, with no exception for cold spares or unexpired service days.
The trade-up programme is genuinely attractive and carries a condition worth reading. On a standard three-year Total Security Suite trade-up bundle through distribution, the chassis is effectively subsidised to nominal cost. In exchange the displaced appliance cannot remain in service: activating the new serial number automatically retires the old one in WatchGuard Cloud, and for competitive trade-ins a signed Certificate of Destruction must be returned within 60 calendar days. Miss that window, or keep running the retired serial, and WatchGuard has the contractual right to deactivate your new firewall remotely.
That mechanism has a side effect on the secondary market. Fireboxes retired through trade-up are permanently deactivated in WatchGuard’s licensing database. A unit bought cheaply on a marketplace may be unregisterable, which means no feature keys, no subscription services and no firmware downloads. Check the serial with WatchGuard before money changes hands, not after.
Refresh the box, or move the function
The whole search results page for these queries assumes you are buying another appliance. Sometimes that is right.
Keep the box where local traffic is the point. Manufacturing plants, warehouses and healthcare sites push heavy east-west traffic between VLANs, and sending multi-gigabit internal traffic to a cloud inspection point wastes WAN bandwidth and adds latency for no benefit. Keep it where the uplink is unreliable: a physical Firebox keeps routing, NATing and enforcing basic policy through a total internet outage. And keep it where integrated PoE is doing real work powering access points or handsets, because removing the appliance means replacing that too.
The case for moving the function is strongest on remote access. A T40 delivers 272 Mbps of VPN throughput under an IMIX profile, and when remote users backhaul SaaS traffic through the branch to reach Microsoft 365 the box becomes the bottleneck for work that never needed to touch it. The wider problem is exposure: terminating VPN tunnels and hosting an administrative portal means publishing listening services to the internet, which is precisely the surface that campaigns such as Cyclops Blink went after. Identity-based access keeps those ports closed and the internal network unadvertised. We covered the industry-wide retreat from SSL VPN portals in our vendor-by-vendor timeline, and the regulatory side of running unpatched edge gateways in the legacy VPN end-of-life report.
For a service provider the arithmetic is different again, and it is not mainly about technology. Hardware resale margin typically sits between 10 and 20 percent, with the profit in the bundled suites; recurring software delivery runs materially higher. The operational drag is the bigger number: site visits, rack mounting, RMA logistics and out-of-hours firmware reboots do not scale, and every three to five years the refresh cycle forces a fresh budget conversation with each client. Our piece on managed SASE delivery goes into how partners structure that shift, and managed firewall pricing gives the baseline figures.
The case for simply trading up
An MSP with forty Fireboxes under management has a strong argument for buying forty replacements, and it deserves stating properly rather than dismissed.
The trade-up programme subsidises the chassis to nearly nothing on a three-year suite, so the capital cost of staying is genuinely low. The team knows Fireware, WatchGuard Cloud is already the monitoring plane, the billing is established and the client relationships are built on a known quantity. Swapping architecture means retraining engineers, rebuilding runbooks, renegotiating contracts and absorbing a transition year of thinner margins — against a platform change the client did not ask for. Two years of comfortable renewals beats a difficult migration that ends in the same place.
That is all true, and it is an argument for timing rather than for direction. The July 2028 fleet date is a single event across your entire installed base: T20, T40, T80, M270, M370, M470, M570 and M670 all stop on the same day. Trading up now resets that clock to the early 2030s and hands you the identical decision again, with the same forty sites and the same conversation. The version of this that works is not a switch but a split — new sites and genuine replacements go to the new model, existing hardware runs out its supported life, and the transition year is spread across three rather than concentrated into one. What you should not do is let 1 July 2028 arrive without having decided which way each site goes.
Where to start
Pull your serial numbers and match them against the tables above. Three questions decide the next step for each site. Is the model past End-of-Life already, in which case it is running frozen signatures today. Is it capped on Fireware v12.5.x, in which case the support date is misleading and the real ceiling arrived years ago. And does the site’s traffic genuinely need local inspection, or is it a handful of people reaching Microsoft 365 through a box that exists because it has always existed.
For the migration sequence itself, our WatchGuard migration guide walks through the planning steps in order. If you are weighing the same question across several vendors at once, the FortiGate hardware timeline covers the equivalent Fortinet dates.
If the answer for some of your sites is that the branch does not need an appliance doing inspection at all, that is worth an hour of conversation before the refresh budget is committed. Book a demo and we will walk through what moves to the cloud and what genuinely has to stay on site, or get in touch if you would rather start with the estate list.
Frequently asked questions
When does the WatchGuard Firebox T40 reach end of life?
The Firebox T40 reached End-of-Sale on 1 July 2023 and reaches End-of-Life on 1 July 2028. After that date technical support, Fireware updates and security signature updates stop permanently. The same date applies to the T20, T80, M270, M370, M470, M570 and M670.
When does the WatchGuard Firebox M370 reach end of life?
The Firebox M370 reached End-of-Sale on 1 July 2023 and reaches End-of-Life on 1 July 2028. Security renewals remain fully supported until that milestone, after which WatchGuard discontinues firmware maintenance, signature updates and RMA replacement for the model.
Can I still use a Firebox after its end-of-life date?
It will keep routing and passing traffic, because the kernel does not stop. Every dynamic service does: Gateway AntiVirus, IPS, WebBlocker and botnet detection stop receiving definitions, support ends, and newly disclosed firmware vulnerabilities are never patched. Proxy policies with inspection actions can also start failing unpredictably.
Which Firebox models are stuck on old Fireware?
Six models are permanently capped on the v12.5.x maintenance branch and cannot run v12.6 or later: T15, T15-W, T35, T35-W, T35-R and T35-DW. The limit is architectural — 32-bit ARM silicon or 1GB to 2GB of memory — so no firmware release will lift it.
What replaces the Firebox T40?
WatchGuard names the T125 and T145 as the successors, with the T125-W and T145-W for wireless sites. The T145 adds a 2.5GbE uplink and an SFP/SFP+ cage. Note that the base T45 dropped the integrated PoE+ that the T40 had on port 1.
What happens to my Total Security Suite if the hardware reaches end of life first?
The remaining days are not refunded and do not transfer automatically. You must open a WatchGuard Customer Care case quoting the retired serial number, the replacement serial number and the feature key details. Support then validates the balance and issues a new feature key co-terming the remainder onto the replacement appliance.
Can I restore my old Firebox configuration onto the new model?
Not directly across hardware generations. Interface indices, NIC driver mappings and expansion module configurations differ, and restores across processor architectures fail. Use WatchGuard System Manager Policy Manager with both configurations open and copy policies across, or edit the interface tags in the XML before loading it.
Can I buy a used Firebox and license it?
Only if the previous owner formally released the serial number from their WatchGuard account. Units retired through the Customer Loyalty Trade-Up programme are permanently deactivated in WatchGuard’s licensing database and cannot be reactivated, which means no feature keys, no subscriptions and no firmware downloads.
How does the WatchGuard trade-up programme work?
Existing owners buy a current Firebox with a one, three or five-year security suite at a discount that often reduces the chassis to nominal cost. The displaced unit must be retired: activating the new serial retires the old one automatically, and competitive trade-ins require a signed Certificate of Destruction within 60 calendar days.
Why did WatchGuard remove Data Loss Prevention?
The OEM licence for the underlying scanning engine ended, and WatchGuard permanently deprecated the Fireware DLP service across all Firebox models on 26 February 2025. On mainline releases the controls were removed cleanly. On appliances capped at v12.5.x the old rules remain in the configuration store and can cause silent proxy errors.