The renewal quote arrives four to eight weeks before expiry, it is broadly the same as last time with a higher number at the bottom, and the path of least resistance is to approve it. That is usually how a business ends up running an appliance sized for the company it was five years ago.
What a renewal quote usually is
Most renewal quotes are generated from what is already on the account. The reseller pulls the existing serial and licence bundle, applies current pricing, and sends it. That is not dishonesty, it is how the process works. But it means the quote reflects a sizing decision made when it was first bought, and nobody has revisited whether it still fits.
In the meantime the business has probably changed. Another site. More staff. A move to more video calls and cloud applications, which changes traffic patterns. Someone enabled deep packet inspection, which is the setting most likely to push an undersized appliance into trouble.
Five things to check before signing
- Sizing against today, not the purchase date. How many users and sites does the appliance actually carry now? Throughput figures on datasheets are measured with inspection features off. The number that matters is throughput with the features you have switched on.
- Which licences you actually use. Firewall licensing is sold in bundles. It is common to pay annually for sandboxing, web control or an endpoint tier that was never configured. Log into the console and check what is enabled before renewing what is not.
- The hardware end-of-support date. Renewing a subscription on an appliance that reaches end of support partway through the term leaves you paying for updates on a device that stops receiving firmware. This is the single most common thing we find on a renewal quote.
- What the rule base has become. A rule base that has grown for three years usually contains rules for staff who left, suppliers you no longer use, and an any-any left in during a troubleshooting session. Renewal is the natural moment for a rule review, because you are about to commit to the platform for another term.
- Whether the term matches your plans. If you are opening a site or consolidating offices in the next year, a three-year commitment on the current configuration may not be the cheapest path.
The case for simply renewing
We deploy and migrate firewalls, so we have an obvious commercial interest in recommending change. Frequently the honest answer is still to renew.
If the appliance is correctly sized, in support for the whole term, and the platform suits how your IT is run, renewing is cheaper and less disruptive than migrating. Firewall migrations carry real risk, mostly in the rules that get carried across without anyone understanding them. A clean renewal on a well-configured device beats a rushed migration to a different brand every time. Changing vendor because of a price difference, without changing anything about how the device is managed, tends to reproduce the same problems on new hardware.
When replacement is the better answer
Replacement earns its cost in a few specific situations. When the appliance is at or near end of support, because no amount of subscription fixes unsupported firmware. When it is genuinely undersized and staff are working around the slowness. When you have added sites and the topology has outgrown a single-site design, which is the point at which SD-WAN usually enters the conversation. And when the licence bundle you need is priced better on a different platform, which does happen, though less often than sales conversations suggest.
If you are replacing, the work worth paying for is the rule rebuild rather than the box. Carrying a decade of accumulated rules onto new hardware moves the problem rather than fixing it. See firewall migration for how we approach that.
What to do this week
Find the renewal date, then find the hardware end-of-support date for your exact model on the vendor's site. If the second is earlier than the end of the term you are being quoted, stop and ask about it before signing. Then open the management console and list which licensed features are actually switched on. Those two checks take under an hour between them and are where most of the avoidable spend hides.
Unsupported firmware is not a theoretical concern: CERT-In publishes advisories against exactly this class of perimeter device, and an appliance past end of support stops receiving the fixes those advisories call for. For hardening guidance that applies whichever platform you land on, the CIS Benchmarks cover firewall and network device configuration in a vendor-neutral way.