How to Manage Fortinet Renewals Without Gaps

A FortiGate can keep passing traffic after a subscription expires, which is precisely why renewal risk is often missed. The appliance may appear healthy while current threat intelligence, web filtering, application control updates or vendor support have lapsed. Knowing how to manage Fortinet renewals means treating each renewal as an operational security decision, not a last-minute procurement task.

For Australian organisations, that distinction matters. A lapsed service can weaken incident response, complicate compliance evidence and create an avoidable gap in protection across branches, remote users, cloud workloads and endpoints. The practical objective is straightforward: maintain the right entitlements, for the right devices and services, on dates that are visible to both IT and procurement.

Start with a complete Fortinet entitlement register

The most effective renewal process begins with an accurate register. Do not rely on an old purchase order, a spreadsheet owned by one administrator or a renewal email arriving in an unattended mailbox. Build a current record of every Fortinet asset and subscription in use, then make ownership clear.

For each item, capture the device serial number, model, physical location or business function, service bundle, support level, start and end dates, renewal term, licence owner and purchasing contact. Include FortiGate firewalls, FortiSwitch, FortiAP, FortiAnalyzer, FortiManager, FortiClient, FortiEDR, FortiMail and cloud services where applicable.

This inventory should distinguish between hardware support and security services. A FortiGate, for example, may require FortiCare support alongside FortiGuard services. FortiCare provides access to technical support, hardware replacement options where covered, and firmware and software assistance. FortiGuard subscriptions provide the security intelligence and service capabilities that make features such as IPS, antivirus, DNS filtering, web filtering and application control effective.

Those entitlements are related, but they are not interchangeable. Renewing one while overlooking the other can leave an organisation with support but reduced security coverage, or active services without the support response level its operational model requires.

How to manage Fortinet renewals by business priority

Not every device deserves the same renewal approach. Start by identifying systems that protect internet-facing services, production sites, remote access, regulated data or critical operational technology. These are the assets where a lapse carries the greatest commercial and security consequence.

For a smaller business with a single firewall, a bundled renewal may be the most economical and least complex path. For a multi-site organisation, co-terming subscriptions can reduce the administrative burden by aligning many renewal dates to one common anniversary. The trade-off is that co-terming may require an initial adjustment to bring separate contracts into line. It is often worthwhile when dozens of devices are involved, but it should be priced against the expected administration savings and budget timing.

Also review whether each product is still fit for purpose. A renewal is a useful control point to identify appliances approaching end of support, undersized firewalls after growth, duplicate services or locations that have changed their connectivity model. Extending an unsuitable platform for three years may look cheaper on paper, but it can postpone a necessary security or performance decision.

Validate services against your deployed policy

Entitlements should match the controls you have actually enabled. If SSL inspection, IPS, antivirus and web filtering are central to your security policy, confirm the relevant FortiGuard services are active for every device enforcing that policy. If an appliance protects a guest network only, its requirements may differ from a firewall carrying sensitive business applications.

This review also exposes licence waste. Organisations sometimes renew services for retired devices, lab equipment that no longer has a purpose, or sites that have closed. Conversely, a new branch may have been deployed under pressure and never added to the central renewal plan. The goal is not simply to reduce cost. It is to direct spend towards protection that supports real operational risk.

Set a renewal timeline before urgency drives the price

A disciplined timeline gives technical teams time to verify requirements and gives procurement time to compare term options without rushing. Begin the review around 90 days before expiry for standard environments, and earlier where approvals, tenders, budget cycles or multiple business units are involved.

At the 90-day point, reconcile serial numbers and expiry dates, identify any changes in the environment and request pricing for the appropriate service level and term. At 60 days, confirm the preferred option, internal approvals and any co-terming or upgrade decisions. At 30 days, finalise the order and confirm how entitlement activation will be checked.

Longer terms can provide better price certainty and reduce annual purchasing effort, particularly for stable branch infrastructure. However, a one-year term may be more sensible if the organisation expects a hardware refresh, merger, site closure or major architecture change. The best value is not always the lowest first-year figure. It is the option that avoids paying twice for services during a planned transition.

Avoid allowing renewal dates to sit solely with finance. Finance needs forecastable costs, but IT and security teams need enough time to assess coverage and technical dependencies. Assign a named technical owner and a procurement owner, with a shared calendar reminder schedule and a visible escalation path.

Check your Fortinet portal data, not assumptions

Before placing a renewal order, verify the serial number and current contract details in the relevant Fortinet account. This is where many avoidable errors occur. A similar model number, an old asset register entry or an incorrect serial number can result in a renewal that cannot be applied as intended.

Confirm the device is registered to the correct organisation, the existing services and dates, and the support level required. For managed environments, establish whether the customer, internal IT team or service provider holds portal access and who is authorised to administer assets. Portal access is an operational control, not just an administrative convenience. During an incident, the team should not be searching for credentials or disputing ownership of a firewall.

If your estate includes several Fortinet products, document which portal or console provides the authoritative view for each service. That prevents a false sense of coverage based on a single dashboard.

Buy the right renewal SKU and term

Fortinet part numbers can be highly specific. The correct renewal depends on the appliance model, desired FortiCare level, FortiGuard bundle, term and, in some cases, the existing entitlement position. Ordering from a vague description such as “FortiGate support renewal” is not enough.

Provide your reseller with serial numbers, the current services, expiry dates and your intended outcome. Be explicit about whether you want to maintain existing coverage, consolidate renewal dates, improve support response, add security services or prepare for a hardware refresh. This makes the quote auditable and reduces back-and-forth when timing matters.

An authorised reseller can add practical value here by checking compatibility and helping map commercial options to the environment rather than simply matching a partial part number. FortiSecure Store supports this process with genuine Fortinet subscriptions and certified Australian guidance for organisations that need renewal decisions aligned to their wider security design.

Treat activation as a verification task

A purchase order is not proof of protection. Once the renewal is processed, verify that the entitlement appears against the correct serial number and that the new end date is visible in the management portal. Check the firewall or relevant management console for licence status, update connectivity and any warnings related to expired or missing services.

For critical devices, keep evidence of the updated entitlement in the asset register and renewal record. This is useful for internal audits, insurance questionnaires, customer security assessments and incident reviews. It also provides a clean baseline for the next renewal cycle.

Where a service did lapse, investigate whether security updates, signature downloads or support access were interrupted, then confirm normal operation has resumed. The technical response will depend on the product and services involved, but the lesson is consistent: expiry should trigger verification, not assumption.

Build renewals into security governance

The strongest renewal process is part of normal security governance. Review expiry exposure alongside vulnerability management, asset lifecycle planning, backup testing and incident response readiness. Include renewal status in quarterly IT or security reporting, particularly for internet-edge firewalls, remote-access infrastructure and systems subject to compliance obligations.

For larger estates, use a simple traffic-light view showing renewal status, business criticality, owner and next action. The purpose is not reporting for its own sake. It ensures senior stakeholders can see which security controls depend on a decision before the decision becomes urgent.

A Fortinet renewal should leave your organisation with more than a new expiry date. It should confirm that each protected service is current, each critical device is supported and each dollar of security spend is tied to a clear operational outcome.

Let's keep in touch

Subscribe for practical Fortinet insights, cost‑saving strategies, and security updates delivered straight to your inbox.