What usually goes wrong
A renewal quote is generated from what is on the account. The reseller pulls the serial, applies current pricing, and sends it. That is the process working as designed, but it means nobody has revisited a sizing decision made when the appliance was first bought.
In the meantime the business has usually changed. Another site. More staff. A shift to video calls and cloud applications that changes traffic patterns entirely. And frequently someone enabled deep packet inspection, which is the single setting most likely to push an undersized appliance into trouble.
The three checks
- Sizing against today. Datasheet throughput figures are measured with inspection features switched off. The number that matters is throughput with the features you actually run. We check the appliance's own utilisation during a normal working afternoon rather than relying on the sticker.
- Licence bundle against actual use. Firewall licensing is sold in bundles and it is common to pay every year for sandboxing, web control or an endpoint tier that was never configured. We log in and list what is enabled.
- Hardware end-of-support date. Renewing a subscription on an appliance that reaches end of support partway through the term means paying for updates on a device that stops receiving firmware. This is the most common problem we find on a renewal quote.
What you get
A short written summary: whether the appliance is correctly sized, which licensed features are unused, when the hardware leaves support, and whether renewing or replacing is the better commercial decision. If the rule base has not been reviewed in years, we will say so and quote separately for a rule review rather than bundling it in.
If replacement is the answer
Replacement earns its cost in specific situations: the appliance is at or near end of support, it is genuinely undersized and staff are working around the slowness, or you have added sites and the topology has outgrown a single-site design. That last one is usually where SD-WAN enters the conversation.
Where you do replace, the work worth paying for is the rule rebuild rather than the box. See firewall migration for how we handle that, including cutovers scheduled outside business hours.
What the timeline usually looks like
Renewal quotes tend to arrive four to eight weeks before expiry, which is enough time to make a considered decision and not enough to be leisurely about it. A review takes a couple of days, most of it remote.
If the answer is to renew, you sign with a written reason rather than because the date was approaching. If the answer is to replace, four to eight weeks is comfortable for a single-site cutover and tight for a multi-site rollout, which is worth knowing early rather than late.
Where a renewal date has already passed and you are running on a lapsed subscription, tell us on the call. An appliance without an active subscription keeps forwarding traffic but stops receiving threat intelligence and firmware updates, and the risk of that grows the longer it runs.
Questions worth asking your current supplier first
Before bringing anyone new in, four questions to whoever quoted you. Ask them by email, because you want the answers in writing.
- What is the hardware end-of-support date for this exact model?
- Which licensed features in this bundle are currently enabled on our appliance?
- When was the rule base last reviewed, and can we see it?
- Is this appliance still correctly sized for our current staff count and site count?
A supplier who has taken ownership can answer all four, and if they do, you may not need us at all. A supplier who cannot answer them has told you something useful.
What it costs
The review is scoped on a short call and quoted as a fixed price before any work starts. Replacement and migration work is quoted per engagement once we know the site count and what you already own. We do not take a margin position that depends on which answer we give you.