When to Upgrade FortiGate: Signs That Matter

A FortiGate rarely fails at a convenient time. More often, the warning signs appear gradually: VPN users report slow access, inspection features are switched off to keep throughput acceptable, or a critical FortiOS release is no longer available for the appliance. Knowing when to upgrade FortiGate infrastructure means acting before those compromises become a security, availability or compliance issue.

The right upgrade is not always a larger firewall. It may be a licensing change, a redesign of high availability, faster interfaces for a growing site, or a move to a current platform with greater security processing capacity. The practical question is whether your existing FortiGate can still provide the protection your organisation intends to run, at the performance your operations require.

When to upgrade FortiGate hardware

Hardware age matters, but age alone is not the decision point. A firewall that is still passing traffic may nevertheless be approaching a supportability or capacity limit that creates avoidable risk. The decision should be based on security services, traffic demand, lifecycle position and business dependence on the site.

A FortiGate upgrade should be actively assessed when one or more of these conditions applies:

  • The appliance is approaching end of engineering support, end of support, or a FortiOS version ceiling that prevents a planned software upgrade.
  • Security inspection is creating sustained CPU, memory or session pressure during normal business peaks.
  • SSL/TLS inspection, IPS, application control, web filtering or malware protection have been reduced or disabled to preserve performance.
  • WAN bandwidth, branch traffic, remote access users, cloud connectivity or east-west traffic has materially increased.
  • The business requires faster interfaces, higher availability, segmentation or secure connectivity that the current model cannot economically support.
These indicators need context. A small office with modest internet use can run effectively on a lower-capacity appliance for years. A head office firewall carrying cloud applications, site-to-site VPNs, voice, guest access and inspected web traffic can outgrow its sizing much sooner, even if its raw internet connection has not changed.

Inspect the performance that actually matters

Firewall datasheet figures are useful for initial comparisons, but they are not a sizing guarantee. Maximum firewall throughput is not equivalent to throughput with the security profile your organisation uses. Enabling IPS, antivirus, application control and SSL inspection changes the processing requirement considerably. So do high concurrent session counts, encrypted traffic, logging volume and VPN demand.

Review operational data rather than relying on anecdotal reports. Look at peak CPU and memory utilisation, concurrent sessions, new sessions per second, interface utilisation, VPN tunnel performance and event logs. The concern is not one brief utilisation spike during a backup window. It is sustained pressure, recurring congestion, dropped sessions or a platform operating too close to its practical limit to absorb an incident or traffic surge.

There is a security trade-off here. If a team responds to performance pressure by excluding more traffic from inspection, weakening web controls or deferring FortiOS updates, the firewall may still be online but it is no longer delivering the intended protection. That is often the clearest signal that a refresh is warranted.

Lifecycle and FortiOS support are security decisions

A FortiGate should remain within a supported lifecycle for its role and risk profile. Once a model can no longer receive relevant FortiOS releases, security fixes and engineering support, the organisation loses options. This is particularly significant for internet-facing firewalls, remote-access gateways and appliances protecting regulated or sensitive environments.

Do not wait for the last support date to begin planning. Hardware refreshes can involve lead times, change windows, configuration review, carrier coordination and high-availability testing. A sensible approach is to assess replacement 12 to 18 months before lifecycle milestones, particularly for critical sites or standardised multi-site deployments.

FortiOS compatibility is equally important. A new FortiOS release may provide features, security improvements or bug fixes that make operational sense for your environment, yet an older appliance may not support it. Conversely, upgrading software without validating hardware capacity can create performance surprises. The best outcome is a planned hardware and software roadmap, not an emergency replacement after a support gap or security event.

Growth changes the sizing equation

Organisations often size a firewall for the office they have, then retain it through years of change. Staff numbers rise, SaaS adoption expands, internet services move to cloud platforms and remote work becomes a normal operating model. The firewall’s role grows with each change.

Consider a mid-sized business that originally used a FortiGate for internet access and a handful of site VPNs. Three years later, it may be terminating remote-access VPNs, inspecting encrypted SaaS traffic, connecting branch offices over SD-WAN, enforcing application policies and forwarding logs to central security tools. The original hardware may not be wrong, but it may no longer be correctly matched to the role.

Network changes can also make an upgrade commercially sensible before the existing appliance is exhausted. Moving from 1 GbE to multi-gigabit connectivity, adopting 10 GbE uplinks at a core site, or requiring redundant power and higher port density can justify a new platform. Adding adapters, workarounds or separate appliances to extend an undersized firewall can cost more over time than selecting the right model for the next stage of growth.

Remote access, SD-WAN and cloud deserve separate attention

VPN capacity should be assessed using real user behaviour, not just the number of named users. Concurrent users, authentication methods, split tunnelling policy, endpoint posture checks and the applications accessed all affect demand. A surge in remote work after an incident or local disruption can expose a capacity limit that was invisible during normal operations.

For SD-WAN deployments, consider the number of sites, overlays, application steering rules and expected internet circuit growth. For cloud-connected environments, assess the traffic patterns between on-premises systems, cloud workloads and SaaS applications. A firewall can have adequate internet throughput yet still become a bottleneck because it is handling a far more complex mix of encrypted and inter-site traffic than it was designed for.

Licensing can be the upgrade you need first

Not every gap requires new hardware. If the appliance has adequate capacity and support life, reviewing subscriptions may provide the security improvement you need. FortiGuard services, FortiCare coverage and relevant bundles determine whether the firewall can apply current intelligence and whether your team has access to vendor support when it matters.

The reverse is also true: renewing every subscription on an ageing appliance may not be the best-value decision. If the model is close to lifecycle limits or lacks the capacity to run the security services included in the bundle, a renewal-only approach can defer rather than solve the problem.

Treat hardware, subscriptions and support as one protection outcome. The right decision weighs remaining appliance life, required features, inspection performance, support requirements and the cost of an unplanned outage. For many organisations, a bundle that aligns a current FortiGate with appropriate security services is easier to budget and operate than piecemeal renewals.

Plan the change around resilience, not just replacement

A firewall replacement is an opportunity to improve design quality. Review high availability, dual-WAN failover, configuration backup, logging, administrative access, segmentation and the recovery process. If the existing FortiGate is a single point of failure for a critical site, simply replacing it with a newer single appliance may leave the core resilience problem unresolved.

Migration should include a configuration and policy review. Years of operational changes often leave unused rules, broad objects, legacy VPN settings and exceptions that no longer have an owner. Carrying all of that into a new firewall can reproduce old risk on new hardware. Clean-up takes effort, but it provides a more defensible policy base and makes future troubleshooting easier.

Test the cutover against the services the business relies on: internet access, DNS, remote access, site VPNs, voice, payment systems, cloud applications and monitoring. Confirm rollback steps, backups and access methods before the window begins. For critical environments, staged deployment or an HA migration may be preferable to a single high-risk change.

Make the decision before protection is compromised

The strongest reason to upgrade is not that a newer FortiGate exists. It is that your current platform can no longer support the security controls, capacity, lifecycle position or resilience your organisation needs at a justifiable cost.

A structured assessment turns that decision into a practical business case. Compare current utilisation and service requirements with the next 24 to 36 months of growth, then factor in lifecycle dates, subscription costs, connectivity plans and the impact of downtime. FortiSecure Store can help translate those inputs into a correctly sized Fortinet solution backed by certified Australian guidance, rather than an oversized purchase or a short-term compromise.

The best time to act is while your team still has time to test, plan and negotiate from a position of control - not after the firewall has become the constraint on your security or operations.

Let's keep in touch

Subscribe for practical Fortinet insights, cost‑saving strategies, and security updates delivered straight to your inbox.