Before you sign the firewall renewal

By S. Sridhar Thewar · 6 min read · Published August 2026
Short version: A renewal quote is normally a reorder of the appliance and licence bundle you bought three years ago, priced for today. Before signing, check the sizing against your current site count and staff, check which licences in the bundle you actually use, and check the hardware end-of-support date. Renewing is often the right answer. It should still be a decision rather than a default.

The renewal quote arrives four to eight weeks before expiry, it is broadly the same as last time with a higher number at the bottom, and the path of least resistance is to approve it. That is usually how a business ends up running an appliance sized for the company it was five years ago.

What a renewal quote usually is

Most renewal quotes are generated from what is already on the account. The reseller pulls the existing serial and licence bundle, applies current pricing, and sends it. That is not dishonesty, it is how the process works. But it means the quote reflects a sizing decision made when it was first bought, and nobody has revisited whether it still fits.

In the meantime the business has probably changed. Another site. More staff. A move to more video calls and cloud applications, which changes traffic patterns. Someone enabled deep packet inspection, which is the setting most likely to push an undersized appliance into trouble.

Five things to check before signing

The case for simply renewing

We deploy and migrate firewalls, so we have an obvious commercial interest in recommending change. Frequently the honest answer is still to renew.

If the appliance is correctly sized, in support for the whole term, and the platform suits how your IT is run, renewing is cheaper and less disruptive than migrating. Firewall migrations carry real risk, mostly in the rules that get carried across without anyone understanding them. A clean renewal on a well-configured device beats a rushed migration to a different brand every time. Changing vendor because of a price difference, without changing anything about how the device is managed, tends to reproduce the same problems on new hardware.

When replacement is the better answer

Replacement earns its cost in a few specific situations. When the appliance is at or near end of support, because no amount of subscription fixes unsupported firmware. When it is genuinely undersized and staff are working around the slowness. When you have added sites and the topology has outgrown a single-site design, which is the point at which SD-WAN usually enters the conversation. And when the licence bundle you need is priced better on a different platform, which does happen, though less often than sales conversations suggest.

If you are replacing, the work worth paying for is the rule rebuild rather than the box. Carrying a decade of accumulated rules onto new hardware moves the problem rather than fixing it. See firewall migration for how we approach that.

What to do this week

Find the renewal date, then find the hardware end-of-support date for your exact model on the vendor's site. If the second is earlier than the end of the term you are being quoted, stop and ask about it before signing. Then open the management console and list which licensed features are actually switched on. Those two checks take under an hour between them and are where most of the avoidable spend hides.

Unsupported firmware is not a theoretical concern: CERT-In publishes advisories against exactly this class of perimeter device, and an appliance past end of support stops receiving the fixes those advisories call for. For hardening guidance that applies whichever platform you land on, the CIS Benchmarks cover firewall and network device configuration in a vendor-neutral way.

Frequently asked questions

Should we renew the same firewall or replace it?

Renew if it is correctly sized and remains in hardware support for the whole term. Replace if it reaches end of support during the term, if it is undersized for current traffic, or if your site count has outgrown the original design.

How do we know if our firewall is undersized?

Check CPU and memory use on the appliance during a normal working afternoon, not overnight. Persistent high utilisation, or staff reporting slowness that clears when inspection features are disabled, are the practical signs.

Can we renew for one year instead of three?

Usually yes, though the per-year cost is higher. A shorter term is worth considering when the appliance is close to end of support or when you expect the site count to change.

Do you sell firewalls, or just configure them?

We are an official partner of Sophos, Fortinet and WatchGuard and can supply and deploy all three. We are equally willing to tell you the appliance you already own is fine and needs only a rule review.

Renewal quote you are not sure about?

Send it over with your model number. We will tell you whether the sizing and the support dates hold up, before you commit for another term.

Book a free consultation