// FIREWALLS · VENDOR DOCUMENTATION

Your firewall licence expired. What actually happens?

It depends entirely on whose box is on your wall — and the range runs from “nothing visible” to “the whole site loses internet”. Five vendors, five documented answers, side by side.

  • ● Vendor sources linked
  • ● Checked 27 July 2026
  • ● Independent — we sell no vendor’s kit

Independent, and dated. 365 Techies is an independent IT firm. We are a Dell reseller and a Microsoft partner; we are not an authorised partner, reseller or agent of SonicWall, Fortinet, WatchGuard, Sophos, Cisco, Cisco Meraki, Ubiquiti or any other vendor named on this page, and we have no access to their support entitlements on your behalf. Every quoted behaviour comes from the vendor’s own documentation, linked in the source column, and was checked on 27 July 2026. Where we could not verify something from a vendor source we say “check with vendor” rather than guess. We publish no prices for this work — every site is different, and we would rather give you a real number on the phone than a fake one here.

Five vendors. Five genuinely different answers.

A renewal quote lands, or somebody notices a licence lapsed three months ago, and the question is always the same: is the firewall about to stop working, or is this a scare tactic?

The honest answer is that it depends entirely on whose box is on your wall, and the range is wider than most people expect — from “nothing visible happens” to “the whole site loses internet”. One vendor’s kit stops applying your firewall rules altogether and quietly becomes a router.

Every description below is the vendor’s own documented behaviour, linked to the source. We sell none of these products.

Checked: 27 July 2026. Vendors reword their documentation and move their dates. If you are making a decision on something below, open the vendor link and check it yourself — then tell us if it has moved and we will correct this page.

What each vendor says happens

SonicWall

TZ series (Gen 7 and Gen 8) — keeps working, stops protecting

The box carries on routing and doing stateful firewalling. What stops is the inspection: intrusion prevention, anti-malware, application control, content filtering and Capture ATP are all marked “requires added subscription” on the vendor’s own datasheet. Traffic still flows; it simply stops being examined.

Watch out: Signature-based protection running on a frozen signature set is worse than no protection, because the dashboard still looks green.

Source: SonicWall TZ datasheets
Fortinet

FortiGate 40F / 70F / 70G / 90G — degrades to a plain router, and you cannot patch it

Fortinet’s own knowledge base states the device “will operate as classic L3 firewalls with only cached NGFW functionalities”. Signatures freeze at whatever was last downloaded.

Watch out: The one that hurts most: without FortiCare you cannot apply firmware upgrades. So a lapsed licence blocks the security patch you need when the next advisory lands.

Source: Fortinet support knowledge base
WatchGuard

Firebox T25 / T45 / T85 — the expired service switches off, the box keeps passing traffic

Each service carries its own expiry date inside the feature key. In WatchGuard’s words, when a subscription expires “that service does not operate, and the configuration options are disabled”. The Firebox continues passing traffic.

Watch out: Services expire individually, so you can be part-protected without realising. Support is a separate subscription again — check both.

Source: WatchGuard help centre
Sophos

Firewall XGS (base licence) — FAILS OPEN — your firewall rules stop being applied

This is the one nobody says out loud, and it is Sophos’ own documentation: when the base licence expires on hardware, “firewall rules aren’t processed whether you’ve configured them to allow or block traffic. The firewall acts as a router and masquerades all outbound traffic.” NAT rules, site-to-site tunnels, remote access points and wireless networks stop working.

Watch out: Read that twice. Your block rules stop being processed too. A lapsed base licence turns a firewall into a router that lets everything out.

Source: Sophos Firewall documentation
Cisco Meraki

MX series — depends entirely on which licensing model you are on

Two models, opposite behaviours. On co-termination or per-device licensing, Meraki’s documentation says hardware “will be non-operational” after the 30-day grace period — the site loses internet. On the newer subscription model the device keeps forwarding traffic but management locks.

Watch out: If you do not know which licensing model your organisation is on, find out today. It is the difference between an inconvenience and the whole site going dark.

Source: Cisco Meraki licensing documentation

What a lapse does not do

Renewal quotes are often sold with more urgency than the facts support, so here is the reassuring half — also from the vendors’ own documentation.

  • Your firewall is not bricked. No vendor here erases configuration or disables the hardware permanently. Renewing restores service.
  • Nothing happens on the stroke of midnight. Meraki documents a 30-day grace period. Others degrade quietly rather than stopping. That is precisely why lapses go unnoticed for months.
  • It is not always urgent — but you must know which case you are in. A SonicWall that has stopped inspecting is a risk decision. A co-term Meraki past grace is an outage. Those need different responses and different budgets.

What to do this week

  • Find out what you actually own. Make, model, and which subscription bundle. On WatchGuard, check each service separately — they expire individually, so you can be half-protected without knowing.
  • Meraki owners: establish your licensing model first. Co-termination and per-device fail closed after the grace period. Subscription keeps traffic flowing. It is the difference between an inconvenience and an outage, and it is worth ten minutes to check.
  • Check who receives the renewal emails. The single most common reason a licence lapses unnoticed is that the notices go to someone who left, or to the company that installed the box years ago. Free to fix, today.
  • Fortinet owners: check firmware separately. Without FortiCare you cannot apply firmware upgrades — so a lapse blocks the patch you will need when the next advisory lands.
  • Then decide, knowingly. A box that has stopped inspecting is a risk decision somebody should take deliberately. It is not automatically an emergency — but it should never be an accident.
  • Ageing access points on the same network? The same “still supported or not?” question applies there, and we have published the vendor dates for those too.

    Not sure which case you are in?

    Tell us the make and model and we will tell you what your situation actually is — no charge for the answer, and no quote unless you ask for one. We always ring before we connect to anything.

    01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM