When a firewall licence expires: what actually stops on FortiGate and Sophos
The appliance keeps running — and that is precisely the problem. Exactly what continues and what silently stops when a FortiGate or Sophos licence expires, how to check the date yourself, and what to do if it has already lapsed.
The renewal quote arrives a month before expiry, and gets put off. The date passes and nothing happens: the internet works, the branches are connected, not one user complains. Three months later the question is a perfectly reasonable one — why pay, as long as the box is still working?
The answer is that it is indeed still working — but a large part of its security function has stopped, and nothing on any screen anyone looks at said so. What follows is what keeps running and what stops when a FortiGate or Sophos licence expires, how to check for yourself, and what to do if it has already lapsed.
The idea that explains all of it: local signatures versus live lookups
Protection on any modern firewall rests on two completely different sources, and that split alone explains every behaviour you see after expiry:
- Databases held on the appliance itself — IPS signatures, the antivirus database, application control signatures. They are updated periodically, but they live on the box, so they carry on after expiry, frozen at the last update that reached them.
- Live lookups to the vendor's cloud — site categorisation in web filtering, domain categorisation in DNS filtering, outbreak prevention, and spam filtering. The appliance asks the cloud about every address the moment it is requested, so all of this stops at once, because the query is refused.
FortiGate: what keeps running and what stops
Fortinet's documentation is explicit on this point: the appliance carries on working as a firewall even with every FortiGuard licence expired. Routing, NAT, the traffic policies you wrote and VPN tunnels all continue exactly as they were.
These continue alongside them, but on frozen databases:
- IPS inspection runs on the signatures already on the appliance, and no new signatures are added.
- Gateway antivirus keeps scanning with its current database, without updates.
- Application control, the Internet Service Database, device and operating-system identification, and Virtual Patch signatures — all work with what they already hold, and nothing more.
- Botnet IP/Domain lists keep blocking from what is stored. One detail catches many people out: these lists follow the Firmware & General Updates contract, not the IPS contract, even though they appear under Intrusion Prevention.
- Filtering by static lists (Static URL/Domain) that you wrote yourself works in full.
What stops:
- Category-based web filtering and DNS filtering — because both are live lookups. The default behaviour here is the surprise: according to Fortinet, by default all web and DNS traffic is dropped. And if Allow websites when a rating error occurs is enabled, all traffic passes through with no filtering whatsoever. The option is disabled by default in the default profile and in any new profile, so start by checking what it is actually set to on your own box.
- Outbreak Prevention — a pure live lookup to FortiGuard's global threat database.
- Antispam filtering that depends on FortiGuard servers; only the local options remain.
- The paid Security Rating checks and their mapping to CIS benchmarks; only what is built into the system remains.
There is one operational consequence that catches technical teams out. An appliance without a valid Firmware & General Updates licence — or one that has passed End of Engineering Support (EOES) — queries FortiGuard daily, and if it finds a new patch for its minor release it schedules a mandatory upgrade for itself. It cannot be cancelled; installation can only be deferred by seven days, with execute auto-upgrade delay-installation, and rescheduled within a fourteen-day window from when the patch was detected. Which means a reboot in a window you did not choose.
Sophos: separate modules, different behaviour
A Sophos licence is not one thing. It is a set of modules, each bought and each expiring on its own: Base License, Network Protection, Web Protection, Zero-Day Protection, Central Orchestration, Email Protection, Webserver Protection, and the Enhanced support subscription. One can expire while the rest stay valid — reason enough on its own to check each module individually rather than "the licence" as a whole.
The fundamental difference from FortiGate is that Sophos does not leave the module running on an old database; it stops applying the policy altogether. According to Sophos's documentation:
- When Network Protection expires: IPS signatures are not loaded and IPS policies are not applied. The appliance carries on pulling the Sophos X-Ops feed but does not use it to block malicious IP addresses and domains, and DNS does not return NXDOMAIN for indicators of compromise. SD-RED tunnels drop and show as offline — an outage users see the moment it happens, if a branch is connected through one. Security Heartbeat stops, meaning the link between the firewall and endpoint protection. Site-to-site RED tunnels, on the other hand, stay up, and SSL/TLS inspection continues in DPI mode.
- When Web Protection expires: traffic on ports 80, 443 and 3128 is still passed to the proxy or the DPI engine, depending on your configuration, but what stops is wider than many expect. Application signatures are not loaded and application filter policies are not applied, and web policies, malware scanning and web-filtering logs all stop. In proxy mode, HTTPS decryption and site categories stop with them, while Parent Proxy, pharming protection, SafeSearch and authentication remain. In DPI mode, SSL/TLS decryption and site categories continue.
The Base License does not expire on the cloud, virtual and software editions, and on physical appliances only once the unit reaches End of Life (EOL). If it does expire, the picture is harsh: firewall rules are not processed at all — neither allow nor block — and the appliance behaves as a router passing outbound traffic with masquerade, so traffic is permitted only from LAN and DMZ to WAN and between them. NAT rules, site-to-site RED tunnels and remote access points stop. IPsec and SSL VPN tunnels stay up, but no data passes through them.
For anyone without a valid support subscription: no technical support and no replacement of faulty hardware (RMA) on any SFOS version, and the appliance gets three free firmware upgrades only. Managing the firewall through Sophos Central also requires a paid subscription — Network Protection, say, or a bundle or a support subscription — and the Base License alone is not enough. Sophos states that renewal must happen within ninety days of expiry; once that passes, protection on the appliance stops.
Why "the box is still working" is the most dangerous sentence here
A network fault announces itself: the phones ring. An expired licence does not. Nothing changes in any user's experience, and the daily reports look exactly as they did — they may even look better. The number of threats detected falls, not because there are fewer threats, but because the appliance has stopped recognising anything new. A firewall running IPS signatures eight months old does not write "my databases are out of date" in the report. It writes "no threats detected" — a sentence that reads exactly like "you are protected".
Hence the paradox: the case that "breaks" loudly — web filtering that drops all traffic — is the kinder of the two, because it is found within minutes. The dangerous one is the setting that allows traffic on a rating error: no complaint, no visible symptom, and months of unfiltered web traffic. This intersects with a common entry point, remote access left exposed to the internet, where the difference between detecting something and missing it is a single signature update.
How to check for yourself in five minutes
On FortiGate
- In the interface: the System > FortiGuard page shows the status of each service and its expiry date. From 7.4.0 onwards, a Licenses widget appears on Dashboard > Status, marking licensed services in green and unlicensed ones in orange.
- From the command line: diagnose autoupdate versions lists the installed databases and the contract expiry date for each of them, and diagnose test update info shows contract detail at account and device level. The FMWR line is the Firmware & General Updates contract.
- Most important: the date that counts is the one in the Fortinet support portal (Asset Management, by serial number), not the one on the appliance. The appliance displays the contract date plus one day, because Fortinet adds a short grace period to allow for a late renewal. Do not build your schedule on the appliance's date.
On Sophos
- From the admin interface: Administration > Licensing, where you see the appliance's registration details and the status and expiry date of each module. There are four statuses: Subscribed, Evaluating, Not subscribed and Expired. Go through them one at a time; the common mistake is for an administrator to see one module valid and assume the whole appliance is covered.
- The appliance synchronises its licences automatically every twenty-four hours as long as it has an internet connection, and you can click Synchronize to sync immediately after any renewal.
What a renewal actually buys
A renewal does not buy "keeping the box running" — the box runs without it. It buys three things: a continuing signature feed, the return of live categorisation lookups, and the support subscription, including replacement of faulty hardware.
Four factors drive the cost: the model class and its throughput, the bundle level — that is, which services are included in it — the contract term, and the level of support that comes with it. Which is why comparing two quotes that each carry a single line reading "licence renewal" is a meaningless comparison: they are comparable only if the model, the bundle SKU, the term and the support level all match. And if you are still at the stage of choosing the appliance itself, this practical comparison of Sophos and FortiGate sets out the differences before you buy, while the FortiGate 100F and Sophos XGS 2100 pages show the common models in this class.
And one point that changes the arithmetic for anyone thinking "let us put it off for two months": FortiGuard services are designed to run without interruption, and any gap is covered by back-dating the renewal to the previous contract's expiry date. Which means you will pay for the months you deferred either way, without having been protected during them. The limits on that back-dating and on the grace period vary by region, contract type and term, so ask for them in writing in the quote.
A new purchase carries a similar trap: service contracts tied to a device have an activation window of ninety days from shipment — the window that applies to Egypt — and sixty days for shipments to the United States and Canada. Once it passes without registration the contract starts automatically, and registration is still required afterwards to make use of the remaining term. An appliance that sits in its box for four months has used up part of its licence life before it is even installed.
If the licence has already expired
- Establish the real date from the vendor portal by serial number, and work out which modules expired and how long ago — not "the licence" as a single block.
- Check the web filtering failure behaviour first. That one setting decides whether you have spent the past months with no filtering at all or with a noticeable outage.
- Make a deliberate decision about the profiles that are effectively disabled instead of leaving them to fail silently: either renew, or rewrite the policy to rely on what does work — static lists, restriction by source and destination — knowing what you have lost.
- Get the right details ready for pricing: the serial number, the exact model, and the current bundle. A bundle for one model is not a bundle for another.
- After renewing, confirm it reached the appliance. Buying is not activating: the appliance has to be registered under the right account, then licences and definitions are refreshed (Update Licenses & Definitions Now on FortiGate, the Synchronize button on Sophos), then you check that the database dates have actually changed.
A trap that recurs in the Egyptian market
A renewal is tied to the serial number and to the account the appliance was registered under. When it is registered under the supplier's account rather than the company's, renewing — and sometimes simply finding out the expiry date — is hostage to your relationship with that supplier continuing. Ask from day one for it to be registered under your own company's account on the vendor portal, and keep the login details yourself: a step that costs nothing at installation, and a great deal two years later.
At ZEMAVO we supply FortiGate and Sophos appliances and install and configure them as part of our firewall licensing service — as with the firewalls we deployed for the Awlad Ragab chain and the FortiGate at the edge of El Morshedy Shoes' network — and we register the appliances under the client's own account, with expiry dates a standing item in what we track under support and maintenance contracts.
And the simplest preventive step costs nothing: open the licensing page now, record each module's date separately in the company calendar with a reminder sixty days ahead, and add an item to the monthly review — "is every module still valid?". What matters is that this date has a named owner inside the company.
Further Reading
Egypt's Data Protection Law 151/2020: What It Means for Your Infrastructure
Most discussion of the law is legal. But compliance succeeds or fails at the infrastructure layer — in logs, encryption and backu…
Remote Access: How Most Ransomware Gets Into Egyptian Companies
The port was opened one afternoon so somebody could work from home, then forgotten. Two years later it is the door ransomware use…
Business Antivirus: Why Free Is Not Enough, and How to Choose
A consumer antivirus on company machines leaves one question unanswered: which machine is actually protected right now, and when …