AnchorInfrastructure
Anchor Infrastructure › Edge › WatchGuard
WatchGuard Replacement

Your WatchGuard works. The renewal is the problem.

The capability you actually want sits in the upper suite tier, the feature key expires on a date somebody else chose, and the appliance has an end-of-support date approaching. We replace that arrangement with an edge platform we deploy, document and maintain - with nothing that switches itself off.

End-of-life appliances retired No suite tiers Old unit kept for rollback Maintained by us

Get a replacement quote How the swap runs

Tiered suites are a pricing strategy, not a security model.

The pattern is familiar to anyone who has renewed one. Security services are packaged into tiers, and the features that matter most - advanced malware handling, the better filtering, the reporting you would actually use in an incident - tend to live in the upper tier. You are not choosing a level of protection so much as choosing a price point.

The whole arrangement hangs on a feature key with an expiry date. When it lapses, the box carries on passing traffic while the services behind it stop being maintained. Nothing goes down, so nothing announces itself - which is precisely why lapsed subscriptions so often go unnoticed for months.

Then there is the hardware clock. Every model has a published end-of-sale and end-of-support date, and once it passes, firmware fixes stop. At that point the renewal quote and the new-hardware quote converge, and you are asked to buy the same relationship again.

A subscription that can be allowed to lapse without anything visibly breaking is not a safety net. It is a billing mechanism.
  • The suite renewal rivals the cost of the appliance it runs on.
  • You are on the lower tier and quietly missing features you assumed you had.
  • Your model has an end-of-support date in sight.
  • The feature key expired and nobody is sure what stopped.
  • Reporting lives in a separate product or a separate subscription.
  • Firmware is behind because the upgrade is nerve-racking and nobody owns it.

What you have vs. what we put in

We deploy a modern open edge platform on appropriately sized hardware, configure it to your requirements, and maintain it as part of the co-managed arrangement. The capability is not the differentiator - the licensing model and the ownership are.

 WatchGuard as soldModern open edge, maintained by us
HardwareProprietary, with published end-of-sale and end-of-support dates.Standard hardware sized for your throughput. Replaceable and re-deployable on your terms.
Feature licensingTiered security suites. The capability you want is usually one tier up.No tiers and no feature keys. What the platform does, it does.
Expiry behaviourFeature key expires; services stop being maintained while traffic keeps flowing.Nothing expires. Configuration does not depend on an active entitlement.
IPS & filteringSubscription-gated by tier.Intrusion detection and prevention with maintained rule sets, plus DNS and content filtering, kept current by us.
VPNSite-to-site included; remote access clients often counted.IPsec site-to-site and modern WireGuard remote access, with no per-user seat count to police.
SegmentationSupported, but frequently never implemented - one flat network behind one box.VLAN segmentation designed in, so a compromised workstation does not have a clear path to your servers.
Logging & reportingRetention and reporting tied to tier or to a separate product.Shipped off the device to central logging and retained, so an outage or an intrusion is answerable weeks later.
DocumentationWhatever was captured at install, if anything.Documented build and exportable configuration, recoverable by someone other than the person who built it.
If you stop payingServices lapse quietly; support requires a current entitlement.The firewall keeps working exactly as configured. You lose our maintenance, not your perimeter.

How the swap actually runs

A firewall replacement is a short, sharp change with a hard cutover moment. Everything that can be done in advance is done in advance, and the old unit stays on the shelf configured and ready.

  1. Export and read the existing configuration

    Every policy, NAT, branch office tunnel and mobile VPN setting is extracted and reviewed. This step routinely finds policies nobody can explain and tunnels to companies that no longer exist - cleaning that up is half the value of the exercise.

  2. Confirm what must not break

    Inbound services, mobile VPN users, branch peers, anything with a hard-coded public IP, and any vendor with your current address whitelisted. This list is what the cutover is verified against.

  3. Build and stage the replacement

    The new platform is built, configured to match the agreed policy set, and tested on the bench before it goes anywhere near your rack.

  4. Cut over in a planned window

    Typically brief - the physical swap and WAN reassignment is minutes, and the verification afterwards is what takes the time. Where an address change is involved we plan for DNS and peer updates ahead of the window.

  5. Verify against the list

    Every inbound service, every tunnel, every remote access client - checked, not assumed. Branch peers are the usual source of surprises and get tested explicitly.

  6. The old unit stays ready

    We do not wipe or return your WatchGuard on the night. It stays configured and on the shelf for an agreed period, so if something surfaces a week later, reverting is a cable swap - not a rebuild under pressure.

  7. Logging, monitoring, documentation

    Logs shipped to central logging, the device monitored alongside the rest of your infrastructure, and the build documented. Then it is ours to maintain - firmware, rules and all.

Straight answers

Is an open platform really enterprise-grade?

The software underneath modern open firewalls is the same lineage that runs inside a great many commercial appliances and a large share of the internet's infrastructure. The difference between a good firewall and a bad one is almost never the brand on the bezel - it is whether someone competent configured it, keeps it patched, and watches its logs. That is the part we are actually selling.

We use Mobile VPN with SSL for remote staff. What replaces it?

Modern remote access, typically WireGuard, with IPsec available where a client demands it. It is faster, it reconnects cleanly when someone moves between networks, and there is no per-seat count to manage. We migrate users in a batch with a short overlap so nobody loses access mid-change.

Who do I call at 2am?

Us. Not a queue, and not a support contract that has to be verified before anyone will speak to you. That is the whole basis of the co-managed model - you are not being handed a box and wished luck.

We have WatchGuards at branch sites that need to stay.

Not a problem. Standards-based IPsec interoperates, so a replaced firewall at head office can keep its tunnels to WatchGuards at branches. Plenty of clients migrate one site at a time for exactly this reason.

Our compliance framework requires a "next-generation firewall".

Tell us the framework and we will map the controls explicitly - segmentation, IPS, filtering, logging and retention, access control, change documentation. Auditors ask for evidence of controls and of who maintains them. Being able to produce a documented configuration and real retained logs tends to be a stronger position than a licence certificate.

What does it cost?

Hardware appropriate to your throughput, a one-off deployment, and ongoing maintenance as part of the co-managed arrangement. For most small and mid-sized sites the recurring figure is materially below a comparable suite renewal, and it does not escalate at every anniversary. We will put real numbers against your actual renewal rather than quote a range.

Can we do this without downtime?

Close to it. Most of the work happens before the window. The unavoidable interruption is the physical swap, which is minutes - and in HA or multi-WAN setups it can often be reduced further. We schedule it out of hours regardless.

The bigger picture

Your firewall renewal and your hypervisor renewal are the same problem

Firewall subscriptions. Hypervisor licensing. Backup seat counts. Per-endpoint tooling. Individually they are line items - together they are a business you do not control, renewing on somebody else's schedule at somebody else's price.

See how the pieces connect Replacing a SonicWall instead?

Get a WatchGuard replacement quote

A technical conversation, not a discovery call.

Tell us the model, when the feature key expires, your internet speed and how many sites and remote users you have. We will come back with what we would put in and what it costs against your renewal.

We do not share your details, and we will not add you to a drip campaign.

Thanks - that came through. We read every one of these ourselves and will get back to you, usually the same business day.
That did not send. Please check your name and a valid email address, then try again.