Fortinet FortiGate license renewals: what MSPs need to know
ATP, UTP, and Enterprise bundles, what keeps working and what stops when FortiGuard expires, why web filtering drops all traffic by default, the six-month back-dating rule, co-term quotes, end-of-order dates for the F-series, and where the expiration date lives.
Last checked against Fortinet documentation on . Vendor policies change; the sources at the bottom are the record.
A FortiGate with expired subscriptions is still a firewall. Fortinet's administration guide says so plainly: the FortiGate will still function as a firewall if any or all of the FortiGuard licenses are expired. What changes is the intelligence behind it. Signature-based services keep scanning with the last signatures they received, and category-based web and DNS filtering stop entirely, which by default drops the traffic they were rating.
The other rule that shapes every late Fortinet renewal is that FortiGuard services are designed to be continuous. A lapse is covered back to the previous expiration date, so the client pays for the gap either way.
Fortinet license tiers
| Tier | What it includes |
|---|---|
| FortiCare Premium (support only) | 24x7 support with 1-hour response on critical issues, advance-replacement next-business-day RMA, and firmware. Also carries the base updates every contract gets: Application Control, inline CASB, device and OS detection, GeoIP, the Internet Service Database and botnet IP lists, DDNS, and anti-phishing. FortiCare Essential (web-only, next-business-day, return-and-replace) exists for FortiGate 9x and smaller. |
| Advanced Threat Protection (ATP) | IPS with malicious and botnet URL blocking, Advanced Malware Protection (antivirus, botnet domains, mobile malware, virus outbreak protection, content disarm, AI heuristic AV, and FortiGate Cloud Sandbox), plus FortiCare Premium. |
| Unified Threat Protection (UTP) | Everything in ATP plus URL, DNS, and video filtering, anti-botnet and command-and-control, malicious certificate detection, and anti-spam. |
| Enterprise Protection (ENT) | Everything in UTP plus AI-based inline malware prevention, data loss prevention, attack surface security (IoT detection and vulnerability correlation, Security Rating, Outbreak Check), and FortiConverter. |
| SD-WAN bundle | SD-WAN underlay and application monitoring, overlay orchestration, a FortiSASE connector, FortiGate Cloud with one year of log retention, FortiTelemetry Cloud, and attack surface security. FortiGate 100F and larger only. |
Resellers also list an "SMB Protection" bundle (SKU code -879) for the 40F, 60F, 70F, and 80F. Fortinet's own SMB solution brief describes those features as delivered through UTP and does not use that bundle name, so treat it as a reseller packaging of UTP-class services.
Available terms
Fortinet renewal SKUs come in 12-, 36-, and 60-month terms; the suffix on the SKU is the term. Premium and secure RMA add-ons are sold in 1-, 3-, and 5-year contracts.
Fortinet does not publish a multi-year discount structure. The documented advantage of a multi-year renewal is on the back-dating side: terms of two years or longer are not back-dated when a license has lapsed, so a 3-year renewal on a lapsed device starts fresh rather than absorbing the gap.
What happens when a Fortinet license expires
The FortiGate keeps enforcing policy. Fortinet's license-expiration table says IPS, antivirus, application control, the Internet Service Database, OT signatures, and botnet command-and-control detection continue scanning with the existing signatures but receive no updates.
Web and DNS category filtering stop, and by default all web and DNS traffic is dropped unless "allow on rating error" was enabled beforehand. Static URL and domain filters keep working. This is the behavior that turns an expired license into a helpdesk call, because it looks like an internet outage.
Email filtering, Outbreak Prevention, and the paid Security Rating and CIS checks stop.
When FortiCare support expires, firmware upgrades and TAC access are suspended, and RMA entitlement ends with the contract.
Grace period: the FortiGate adds a two-day buffer past the portal expiration date and FortiGuard adds another day, so the device typically keeps its services about three days past the date shown in the support portal. Fortinet staff on the community forum cite a ten-day window before back-dating applies. None of this is a policy grace period; it is how the enforcement clock is set.
Renewing after a lapse
FortiGuard services are designed to be continuous, and any lapse requires coverage back to the contract expiration date. Fortinet's distributor renewal guide spells out the mechanics: a 1-year renewal on a lapsed device is back-dated up to six months, so a device four months lapsed gets eight months of new coverage from a 1-year SKU. Fortinet staff confirm the six-month maximum.
Renewals of two years or longer are not back-dated. A co-term renewal shorter than two years is back-dated up to six months plus one year; a co-term longer than two years is not back-dated. On a badly lapsed device the multi-year term is usually the better buy for exactly this reason.
Fortinet does not document a reinstatement fee. Back-dating is the mechanism, so the cost of a lapse is the months you pay for and do not get.
Co-terming
Fortinet's ordering guide says you can request a co-term quotation from your Fortinet-authorized partner to align end dates. Distributors generate these from the Partner Portal, choosing one common end date across multiple serial numbers, priced from co-term price lists. Co-term SKUs carry an FCZ- prefix, for example FCZ-10-F100F-204-02-DD.
Co-terming stays available until the model's last service extension date. Past that, no contract can extend beyond end of support, so the co-term target on an aging FortiGate is its end-of-support date.
End of sale and end of life
Fortinet's life cycle has three dates that matter for renewals. End of Order is the last day the hardware can be ordered, announced at least 90 days ahead. The Last Service Extension Date is the last day support or subscriptions can be extended, and it falls 12 months before End of Support. No service contract may be extended past the End of Support date, which is generally 60 months after End of Order.
Fortinet's lifecycle lookup is public at support.fortinet.com under Product Life Cycle and needs no login, but it is an application rather than a page, so the dates below come from secondary trackers citing Fortinet notices and were not confirmed directly against the portal. Check the portal before quoting a co-term on any of these.
| Model | End of sale | End of life / support | Note |
|---|---|---|---|
| FortiGate 60E | 2021-12-29 | 2026-12-29 | End of Order / End of Support. Secondary source. |
| FortiGate 100E | 2021-08-17 | 2026-08-17 | Past end of support. Fortinet staff confirmed 08/2026 on the community forum. |
| FortiGate 70F | 2026-05-17 | 2031-05-17 | End of Order / End of Support. Secondary source. |
| FortiGate 80F | 2026-05-17 | 2031-05-17 | One tracker lists these dates only for the 80F-Bypass; verify on the portal. |
| FortiGate 100F | 2026-04-16 | 2031-04-16 | End of Order / End of Support. Secondary source. |
| FortiGate 40F / 60F / 90G | — | — | No End of Order announced as of the check date. |
Where to find the expiration date
- FortiGate GUI: System > FortiGuard lists each service with its expiration. On FortiOS 7.4 and later the Dashboard > Status "Licenses" widget shows green or orange per service.
- CLI: diagnose autoupdate versions and diagnose test update info print the contract dates the device believes.
- FortiCloud Asset Management: the Product List shows Days to Expiration, an About to Expire view groups assets at 30, 60, and 90 days, and an Expired view lists what has already lapsed.
- FortiManager: Device Manager > License tab shows the support contract and FortiGuard status as "Expires in" or "Expired," showing a date three days past the portal date.
- Warnings: the nightly update check logs "license will expire in N days" at a configurable threshold that defaults to 30 days. Expired notices appear on the dashboard, the bell, and the FortiGuard page and cannot be disabled since FortiOS 5.6.
How the renewal moves
Renewals are quoted by the distributor or partner from the Partner Portal, and the quote lists the serial numbers it covers. Renewal services bought with a FortiCare quote ID generated by the distributor are automatically registered to the serial number, which is the smoothest path: the device picks up the new contract on its next FortiGuard check-in.
If the renewal arrives as a contract registration code instead, it is registered in FortiCloud Asset Management with the Renew Contract or Add Licenses wizard. Fortinet's online-renew option is limited to US and Canada accounts with fewer than 50 units.
In our own renewals through TD SYNNEX, a FortiGate co-term came back as a single line on the distributor's spreadsheet, keyed to the serial number we put in the request, with the FCZ co-term SKU and the effective new expiration. The serial in the request is what makes the reply matchable.
How MSP Renewals tracks Fortinet
MSP Renewals stores each FortiGate with its serial number, the bundle you sell it on (Enterprise, UTP, ATP, or FortiCare only), the term you normally quote, and the expiration date you enter or sync. It alerts at 90, 30, and 5 days, drafts the renewal quote at 90 days, and can send the pricing request to your distributor automatically with the serial, bundle, term, and your reference number.
Because Fortinet back-dates lapsed 1-year renewals but not multi-year ones, the pricing request notes when a license has already lapsed and asks the distributor to show the renewal start date on the quote. When the client approves, the device's expiration rolls forward by the term you sold and the countdown restarts.
Fortinet renewal questions
- Does a FortiGate stop passing traffic when the license expires?
- No. Fortinet documents that the FortiGate still functions as a firewall with any or all FortiGuard licenses expired. What stops is category-based web and DNS filtering, which by default drops the traffic it can no longer rate, so users experience it as sites failing to load. Signature-based services keep working on stale signatures.
- Is there a grace period on FortiGuard subscriptions?
- Not as a policy. The device enforces about three days past the portal date because of buffers on the FortiGate and FortiGuard sides, and Fortinet staff cite roughly ten days before back-dating applies. Fortinet's stated position is that services are continuous and a lapse is covered back to the old expiration date.
- If a FortiGate license lapsed, does the renewal start today or on the old date?
- A 1-year renewal is back-dated to the old expiration date, up to a maximum of six months, so the gap comes out of the new term. Renewals of two years or longer are not back-dated. There is no reinstatement fee.
- What is the difference between UTP and ATP on a FortiGate?
- ATP is IPS plus Advanced Malware Protection with FortiCare Premium. UTP adds web, DNS, and video filtering, anti-botnet, malicious certificate detection, and anti-spam. Enterprise adds inline malware prevention, DLP, attack surface security, and FortiConverter on top of UTP.
- How long after End of Order can I still renew a FortiGate?
- Until the Last Service Extension Date, which is 12 months before End of Support, and no contract can run past End of Support. Hardware End of Support is generally 60 months after End of Order. The 100F reached End of Order in April 2026 and the 70F in May 2026 according to lifecycle trackers; the 40F, 60F, and 90G had no End of Order announced as of the check date.
- Can I co-term multiple FortiGates to one date?
- Yes. Ask your partner or distributor for a co-term quote; they generate it from the Partner Portal with a common end date across the serials, using FCZ-prefixed SKUs. Co-term quotes are available until each model's Last Service Extension Date.
Sources
- Fortinet — FortiGuard security services ordering guide (bundles, terms, co-term)
- Fortinet — FortiCare ordering guide (support tiers, FCZ co-term SKUs)
- Fortinet — FortiCare technical support and RMA services brief
- Fortinet — SMB FortiGuard solution brief
- Fortinet — Service contract activation and grace period policy
- FortiOS 7.4.4 administration guide — License expiration behavior
- FortiManager 8.0 administration guide — License expiration
- FortiManager 6.4 administration guide — License management
- FortiCloud Asset Management — Views (About to Expire, Expired)
- FortiCloud Asset Management — Online renew
- FortiCloud — Product life cycle
- Fortinet Community — Product life cycle information on Fortinet products
- Fortinet Community — From what moment is the validity of a subscription calculated (staff answer on back-dating)
- Fortinet Community — Subscription renewal policy
- Fortinet Community — FortiGate E and F series EOL (staff confirmation of 100E date)
- Fortinet Community — FortiGuard license expiration dates on FortiGate (buffer days)
- Fortinet Community — How to view license details via CLI and GUI
- Fortinet Community — How to generate FortiGuard license expiration warnings
- Fortinet Community — License expired notifications cannot be removed
- Exclusive Networks (Fortinet distributor) — Quoting renewal service contracts, back-dating table
- Lifecycle tracker — FortiGate 100F
- Lifecycle tracker — FortiGate 70F
- Lifecycle tracker — FortiGate 60E
- Lifecycle tracker — FortiGate 100E
- Reseller listing — SMB Protection bundle SKU for FortiGate 40F