The capability you actually want sits in the upper suite tier, the feature key expires on a date somebody else chose, and the appliance has an end-of-support date approaching. We replace that arrangement with an edge platform we deploy, document and maintain - with nothing that switches itself off.
The pattern is familiar to anyone who has renewed one. Security services are packaged into tiers, and the features that matter most - advanced malware handling, the better filtering, the reporting you would actually use in an incident - tend to live in the upper tier. You are not choosing a level of protection so much as choosing a price point.
The whole arrangement hangs on a feature key with an expiry date. When it lapses, the box carries on passing traffic while the services behind it stop being maintained. Nothing goes down, so nothing announces itself - which is precisely why lapsed subscriptions so often go unnoticed for months.
Then there is the hardware clock. Every model has a published end-of-sale and end-of-support date, and once it passes, firmware fixes stop. At that point the renewal quote and the new-hardware quote converge, and you are asked to buy the same relationship again.
We deploy a modern open edge platform on appropriately sized hardware, configure it to your requirements, and maintain it as part of the co-managed arrangement. The capability is not the differentiator - the licensing model and the ownership are.
| WatchGuard as sold | Modern open edge, maintained by us | |
|---|---|---|
| Hardware | Proprietary, with published end-of-sale and end-of-support dates. | Standard hardware sized for your throughput. Replaceable and re-deployable on your terms. |
| Feature licensing | Tiered security suites. The capability you want is usually one tier up. | No tiers and no feature keys. What the platform does, it does. |
| Expiry behaviour | Feature key expires; services stop being maintained while traffic keeps flowing. | Nothing expires. Configuration does not depend on an active entitlement. |
| IPS & filtering | Subscription-gated by tier. | Intrusion detection and prevention with maintained rule sets, plus DNS and content filtering, kept current by us. |
| VPN | Site-to-site included; remote access clients often counted. | IPsec site-to-site and modern WireGuard remote access, with no per-user seat count to police. |
| Segmentation | Supported, but frequently never implemented - one flat network behind one box. | VLAN segmentation designed in, so a compromised workstation does not have a clear path to your servers. |
| Logging & reporting | Retention and reporting tied to tier or to a separate product. | Shipped off the device to central logging and retained, so an outage or an intrusion is answerable weeks later. |
| Documentation | Whatever was captured at install, if anything. | Documented build and exportable configuration, recoverable by someone other than the person who built it. |
| If you stop paying | Services lapse quietly; support requires a current entitlement. | The firewall keeps working exactly as configured. You lose our maintenance, not your perimeter. |
A firewall replacement is a short, sharp change with a hard cutover moment. Everything that can be done in advance is done in advance, and the old unit stays on the shelf configured and ready.
Every policy, NAT, branch office tunnel and mobile VPN setting is extracted and reviewed. This step routinely finds policies nobody can explain and tunnels to companies that no longer exist - cleaning that up is half the value of the exercise.
Inbound services, mobile VPN users, branch peers, anything with a hard-coded public IP, and any vendor with your current address whitelisted. This list is what the cutover is verified against.
The new platform is built, configured to match the agreed policy set, and tested on the bench before it goes anywhere near your rack.
Typically brief - the physical swap and WAN reassignment is minutes, and the verification afterwards is what takes the time. Where an address change is involved we plan for DNS and peer updates ahead of the window.
Every inbound service, every tunnel, every remote access client - checked, not assumed. Branch peers are the usual source of surprises and get tested explicitly.
We do not wipe or return your WatchGuard on the night. It stays configured and on the shelf for an agreed period, so if something surfaces a week later, reverting is a cable swap - not a rebuild under pressure.
Logs shipped to central logging, the device monitored alongside the rest of your infrastructure, and the build documented. Then it is ours to maintain - firmware, rules and all.
The software underneath modern open firewalls is the same lineage that runs inside a great many commercial appliances and a large share of the internet's infrastructure. The difference between a good firewall and a bad one is almost never the brand on the bezel - it is whether someone competent configured it, keeps it patched, and watches its logs. That is the part we are actually selling.
Modern remote access, typically WireGuard, with IPsec available where a client demands it. It is faster, it reconnects cleanly when someone moves between networks, and there is no per-seat count to manage. We migrate users in a batch with a short overlap so nobody loses access mid-change.
Us. Not a queue, and not a support contract that has to be verified before anyone will speak to you. That is the whole basis of the co-managed model - you are not being handed a box and wished luck.
Not a problem. Standards-based IPsec interoperates, so a replaced firewall at head office can keep its tunnels to WatchGuards at branches. Plenty of clients migrate one site at a time for exactly this reason.
Tell us the framework and we will map the controls explicitly - segmentation, IPS, filtering, logging and retention, access control, change documentation. Auditors ask for evidence of controls and of who maintains them. Being able to produce a documented configuration and real retained logs tends to be a stronger position than a licence certificate.
Hardware appropriate to your throughput, a one-off deployment, and ongoing maintenance as part of the co-managed arrangement. For most small and mid-sized sites the recurring figure is materially below a comparable suite renewal, and it does not escalate at every anniversary. We will put real numbers against your actual renewal rather than quote a range.
Close to it. Most of the work happens before the window. The unavoidable interruption is the physical swap, which is minutes - and in HA or multi-WAN setups it can often be reduced further. We schedule it out of hours regardless.
Firewall subscriptions. Hypervisor licensing. Backup seat counts. Per-endpoint tooling. Individually they are line items - together they are a business you do not control, renewing on somebody else's schedule at somebody else's price.
A technical conversation, not a discovery call.
Tell us the model, when the feature key expires, your internet speed and how many sites and remote users you have. We will come back with what we would put in and what it costs against your renewal.
We do not share your details, and we will not add you to a drip campaign.