SonicWall will stop supporting the last of its Gen 6 firewalls on October 1, and no amount of money will buy them another patch. Plenty of them went into racks in the late 2010s and never gave anyone a reason to touch them. When rising PC prices and louder emergencies claimed the replacement money, the TZ500 in the closet kept right on working. Soon it won’t be eligible for patches anymore, which means it’s moving up the priority list.
SonicWall has been retiring this generation in stages. The TZ300 family lost support in January 2025, the original SOHO and the NSa 9000 series crossed in April, and the TZ400 and TZ600 families followed on August 1. The TZ350 and TZ500 families, the SOHO 250, and the NSA 4600 through 6650 lines are the ones reaching end of support this time. After that, the whole generation is out of runway.
If a firewall that’s past the end of life is still on duty at your company, now’s the time to look into whether it’s time to buy a replacement. You can compare what that new device would cost versus another year of exposure. Then, you’ll be able to decide whether it makes sense to upgrade or hold off until a certain point.
READ MORE:
Cisco”s AI super cycle is coming for your networking budget
What SonicWall end of support cuts off
Once a firewall passes its cutoff date, SonicWall stops providing firmware updates, technical support, and hardware replacement for it. Security service subscriptions may stay available on paper during that phase, but the company says it won’t support the product or those services.
In one 2024 security advisory, SonicWall told owners of end-of-life units that no software update would be released for out-of-support gear, even though the flaw in question was critical and the fix already existed for supported models.
None of these decisions stop these firewalls from working, of course. They can keep filtering traffic and terminating VPN tunnels the same as ever. But they can’t take a patch anymore, and the cybercriminals scanning the internet for exactly that condition know it.
Ransomware crews keep exploiting end-of-life firewalls
In August 2024, SonicWall patched CVE-2024-40766, an improper access control flaw in SonicOS rated 9.3 in severity, and within weeks CISA added it to its Known Exploited Vulnerabilities catalog with ransomware activity already confirmed. The flaw touched Gen 5, Gen 6, and some Gen 7 firewalls, so the exposure spanned gear both in and out of support.
In late July 2025, Arctic Wolf tracked a surge in Akira ransomware intrusions arriving through SonicWall SSL VPN accounts. SonicWall tied the activity to the same 2024 flaw, not anything new. At that time, the patch had been out for nearly a year. By CISA’s accounting, Akira had collected about $244 million in ransom proceeds as of late September 2025.
ThreatDown said in a September 8 report that its incident responders are still handling Akira cases involving SonicWall devices. The company also counted roughly 213,900 SonicWall VPN and management interfaces exposed to the open internet. That tally doesn’t prove any one of them is vulnerable, but it does measure how much of this surface the intruders can see.
READ MORE:
What are the most practical Wi-Fi 7 use cases in 2026?
SonicWall is hardly an outlier here. The same CISA catalog has picked up edge gear from Cisco, Fortinet, Citrix, Palo Alto Networks, and Check Point in 2026 alone, and VulnCheck research reported by Cybersecurity Dive found that more than four in 10 vulnerabilities exploited during 2025 involved end-of-life or likely end-of-life products. The report found that only about a quarter of the exploited edge-device flaws ended up in the KEV catalog at all, so a model with no KEV entry isn’t necessarily in the clear.
Verizon’s 2026 Data Breach Investigations Report ranks exploitation of a vulnerability as the most common initial access vector, at 31% of breaches, and up from 20% the year before. If you have a firewall that can no longer take patches, the writing’s on the wall about the risk this represents.
How much a Gen 6 replacement costs
While Spiceworks community members may occasionally joke about skipping upgrades in “Wrong Answers Only” threads, they’re prioritizing them when necessary. In the State of IT report, 54% of companies cite upgrading outdated infrastructure as the top driver of 2026 budget increases. This suggests that IT pros are grappling with how best to deal with this type of backlog.
When it comes to the Gen 6 issue, the exit costs a few hundred dollars at the low end. SonicWall operates a Gen 6 replacement program through its resellers. Firewalls.com currently lists the TZ80 bundle at $352, down from a $440 list price, with a year of security services included. That model is SonicWall’s designated successor for the old SOHO class. Further up, reseller SonicGuard’s replacement pricing starts at $980 list for a TZ370, reaching $2,090 for a TZ570 and $2,600 for a TZ670. The NSa-class models start around $3,300 and climb past $25,000 at the top of the range.
On the flip side, stretching hardware past its refresh date tends to cost more than replacing it would have. Once a model reaches end of support, you can’t buy another year of vendor coverage for it at any price, since SonicWall’s lifecycle stops offering one-year support renewals well before that date arrives. Instead, one more year buys you time on the wrong side of an active ransomware campaign.
The keep-or-replace call comes down to exposure and price
So how do you make the call about when to replace your firewall? If you already have a technology lifecycle framework in place, then you’re set. Just run this unit through it like you would anything else in your stack. If you haven’t yet had time to put one of those together while you’ve been busy fighting fires and juggling priority projects, these two scenarios can help you decide.
What a defensible extra year could look like
You might be able to keep a Gen 6 running under very specific conditions. The SSL VPN and management interfaces would have to stay off the public internet, since that’s the door the Akira intrusions came through. In practice, that describes a firewall filtering traffic at a site rather than hosting remote access. If remote users still come in that way, you’re likely already in replacement territory.
When replacement is the cheaper choice
If your firewall terminates SSL VPN for remote users over the public internet, it’s probably time for an upgrade. That’s precisely the exposure the ransomware crews have been targeting, and SonicWall has said gear this old won’t get another fix. You’re in the same boat if a KEV-listed flaw touches your model, especially when the mitigation guidance amounts to upgrading. And if you’ve promised an auditor or a business partner vendor-supported gear at the perimeter, you answered this question back when you signed. Against that, a TZ-line replacement runs $352 to $2,600, security services included.
Whichever way the numbers land for your environment, you’ll want to run them before October 1, when every Gen 6 model will be past its support date. Put the replacement on the calendar and in the budget, and you can retire your firewall the right way—as the result of an informed risk assessment.
I reached out to SonicWall for comment on this story, but the company did not provide one by publication time. I’ll update this reporting if that changes.
Click Here For The Original Source.
