Buying a used firewall: what happens to licenses & subscriptions?
A used firewall is one of the best price-to-performance buys on the secondary market — but the hardware and the subscriptions are two separate purchases. Here is exactly what transfers, what doesn't, and what each major vendor requires before a second-hand unit is fully supported, based on published Fortinet, Palo Alto Networks, Cisco, and SonicWall policies.
What happens to licenses and subscriptions when you buy a used firewall? Firewall subscriptions are tied to the serial number and the seller's vendor account, so they rarely follow a used unit. The base firmware still runs — routing, firewall policies, and VPN all work — but signature updates, cloud services, and vendor support stop until the device is re-registered to the new owner and new subscriptions are purchased.
A used firewall is one of the best price-to-performance buys on the secondary market — but the hardware and the subscriptions are two separate purchases. Here is exactly what transfers, what doesn't, and what each major vendor requires before a second-hand unit is fully supported, based on published Fortinet, Palo Alto Networks, Cisco, and SonicWall policies.
How Firewall Licensing Actually Works
Enterprise firewalls separate three things that buyers often conflate:
- Hardware and base OS. The appliance and its operating system (FortiOS, PAN-OS, SonicOS, Cisco ASA/FTD software) are what you physically buy. On most platforms the base OS boots and forwards traffic regardless of subscription state — Cisco is the notable exception, since its software license itself does not transfer to a secondary buyer.
- Security subscriptions. IPS signatures, antivirus definitions, URL-category lookups, and cloud sandboxing are recurring services keyed to the unit's serial number and to the vendor account that registered it. They are not property of the box; they are a contract between the vendor and the registered owner.
- Support entitlement. TAC access, RMA, and (on some platforms) firmware downloads require an active support contract in the new owner's name.
Because entitlements bind to the serial number and to an account, the transaction that matters on a used purchase is not the shipment — it is the de-registration by the previous owner and re-registration by you. Until that happens, the vendor still considers the unit someone else's.
What Works Without Subscriptions — and What Stops
With no active subscriptions, a used FortiGate, Palo Alto, or SonicWall appliance is a capable stateful firewall and VPN gateway. What it is not is a current threat-prevention device. The split is consistent across vendors:
| Function | Status without active subscriptions |
|---|---|
| Static and dynamic routing (OSPF, BGP) | Works |
| Firewall policies and NAT | Works |
| IPsec and SSL VPN tunnels | Works |
| Local and remote authentication (LDAP, RADIUS, SAML) | Works |
| IPS and antivirus signature updates | Stops — engine may keep running on last-downloaded signatures |
| Web filtering by cloud category lookup | Stops — static allow/block URL lists still work |
| Cloud sandboxing and threat-intelligence feeds | Stops |
| Vendor TAC support and RMA | Stops |
| Firmware upgrades | Restricted — Fortinet, for example, blocks major/minor FortiOS upgrades on expired contracts, allowing only patch-level builds within the current version |
For lab use, routing-only edge roles, or site-to-site VPN concentration, an unsubscribed unit is often entirely adequate. For an internet edge protecting production users, budget for subscriptions from day one.
Fortinet: FortiCare and FortiGuard Follow the Serial Number
Fortinet registers every unit to a FortiCloud/support account by serial number. FortiCare (support, RMA, firmware access) and FortiGuard (IPS, AV, web filtering, and other security services) are sold against that serial.
- Buying used: the previous owner must remove the unit from their account — typically by opening a customer-service ticket at support.fortinet.com requesting removal or transfer to your account. If the unit is still registered to them, you cannot register it yourself, and Fortinet may ask for proof of ownership (invoice or PO) before releasing a serial.
- Without subscriptions: FortiOS runs fully — policies, NAT, routing, IPsec/SSL VPN, and authentication all work. FortiGuard-dependent features (new IPS/AV signatures, live web-rating lookups) stop, and TAC and firmware downloads require active FortiCare. On current FortiOS releases, an expired contract limits you to patch upgrades within your existing minor version.
- Practical takeaway: a de-registered unit such as the FortiGate 100F can be registered to your account and re-subscribed at list price for the services you actually need — you are not locked out of the platform, only out of the update stream until you pay for it.
Palo Alto Networks: Portal Transfer vs. the Secondary Market Policy
Palo Alto Networks draws a sharp line between moving a device between support accounts and legally changing its ownership between companies.
- Account transfer: in the Customer Support Portal, the current owner selects the serial under Assets → Devices and clicks Transfer Ownership to send it to another account, which the recipient then accepts. This works for related entities but does not constitute a company-to-company ownership change.
- Secondary Market Policy: when the buying and selling companies are unrelated — the normal used-market case — the new owner must have the device recertified. That means placing two orders through an authorized reseller: a non-refundable certification fee, then a one-time activation fee plus a one-year support subscription. Palo Alto then runs a verification process (hardware tests, a tech-support file upload, and possibly a remote check by a PANW engineer). If the unit fails, the certification fee is not refunded.
- Without recertification: PAN-OS boots and passes traffic, but you have no path to support, software updates, or subscription licenses (Threat Prevention, Advanced URL Filtering, WildFire) under your name.
Cisco: Licenses Do Not Transfer — Plan to Relicense
Cisco's published position is the strictest of the four: software licenses are not transferable between users unless a scenario in the Cisco Software Transfer and Re-licensing Policy applies or applicable law requires it. That includes the embedded OS on ASA and Firepower hardware.
- Secondary-market purchases: Cisco defines secondary-market equipment as anything bought from a seller that is not an authorized Cisco reseller — even if sealed. The buyer must acquire a new license before the software is legally licensed for use.
- Smart Licensing: entitlements live in the seller's Smart Account, not on the box, so feature licenses stay behind when the hardware ships.
- Service contracts: used or secondary-market equipment cannot be placed under a Cisco support contract (SmartNet/Smart Net Total Care) until it passes inspection and is relicensed — handled through Cisco's Hardware Inspection and Software Relicensing program (contact: tss-inspections@cisco.com). Inspection and relicense fees vary by product.
Factor those costs into the total price before assuming a used Cisco firewall is the cheapest option on the shelf.
SonicWall: Registration Transfer Through MySonicWall
SonicWall handles used units through a registration transfer in MySonicWall, and it is one of the more buyer-friendly processes.
- Cooperative seller: the current owner logs into MySonicWall, selects the product by serial number, and transfers it to your organization — or simply deletes it from their account so you can register it fresh.
- Unknown or unresponsive seller (the eBay case): MySonicWall has a self-service transfer request that emails the registered owner for release; if that fails, SonicWall support will process the transfer against proof of purchase such as an invoice or receipt. SonicWall's KB quotes 24–48 hours for a registration transfer.
- Licenses: a separate "transfer of services" exists for moving purchased licenses between units, but default bundled licenses do not transfer, and a used unit should be assumed to arrive with zero active security services. SonicOS itself keeps firewalling and VPN running without them.
Vendor Policy Comparison
| Vendor | Do licenses/subscriptions follow the used unit? | Ownership-change process | Inspection / recertification | Usable without subscriptions? |
|---|---|---|---|---|
| Fortinet | No — FortiCare/FortiGuard are sold per serial to the registered account; assume zero remaining term | Previous owner removes or transfers the serial via a support ticket; buyer registers it, with proof of ownership if requested | None published; registration release is the gate | Yes — full FortiOS; no FortiGuard updates, TAC, or major/minor firmware upgrades |
| Palo Alto Networks | No — subscriptions must be re-licensed under the new owner | Portal Transfer Ownership between accounts; unrelated companies must follow the Secondary Market Policy | Yes — non-refundable certification fee, activation fee, and 1-year support, plus hardware verification | PAN-OS runs, but no updates, support, or subscription features until recertified |
| Cisco | No — software licenses are non-transferable; Smart Licensing entitlements stay in the seller's Smart Account | Buyer relicenses through Cisco; transfers outside permitted scenarios require Cisco consent and a fee | Yes — inspection and relicensing required before any service contract on secondary-market gear | Not licensed for use until relicensed; support unavailable until inspection passes |
| SonicWall | No for bundled/default licenses; assume none remain on a used unit | Registration transfer in MySonicWall by the current owner, or self-service/support request with proof of purchase (24–48 h) | None published | Yes — SonicOS firewalling and VPN work; security services stop |
The pattern is consistent: the hardware transfers, the paper does not. Where vendors differ is in how much friction (and cost) stands between you and a supported, updating device. This is also the core difference between grades of gear covered in our refurbished vs. new vs. recertified guide — a properly processed refurbished unit arrives with a clean, registrable serial instead of a paperwork dispute.
Pre-Purchase Checklist for a Used Firewall
Run through this before money changes hands:
- Get the serial number up front. No serial, no deal — everything about the unit's registration and entitlement status hangs off it.
- Confirm registration status. Ask the seller for written confirmation that the unit is de-registered (Fortinet, SonicWall) or that they will initiate the portal transfer (Palo Alto). For Cisco, price in relicensing and inspection from the start.
- Demand proof-of-purchase documentation. An invoice or PO chain is what Fortinet, SonicWall, and Palo Alto ask for when a transfer is contested or the prior owner has vanished.
- Check the shipped firmware version. With no active contract you may be limited to patch releases (Fortinet) or unable to download software at all (Cisco, Palo Alto), so the version on the flash is the version you live with until subscriptions are active.
- Price subscriptions into TCO. A year of UTM/threat-prevention services can approach or exceed the hardware price on small units — compare the bundle against new before committing.
- Verify hardware condition. Fans, PSUs, and flash storage are the common failure points on used security appliances. Our process for this is documented at how we test, and every unit in our networking catalog ships with a clean, transferable serial.
Frequently asked questions
Can I use a used FortiGate without any license or subscription?
Yes. Base FortiOS does not require a subscription: firewall policies, NAT, routing (OSPF/BGP), IPsec and SSL VPN, and authentication all work. What you lose are FortiGuard services — new IPS/AV signatures and live web-category lookups — plus TAC support, RMA, and major/minor firmware upgrades, which require active FortiCare.
The used FortiGate I bought is still registered to the previous owner. What now?
The previous owner must release it: they open a customer-service ticket at support.fortinet.com asking to remove the serial from their account or transfer it to yours. If they are unreachable, contact Fortinet support yourself with proof of ownership (invoice or PO). You cannot register the unit until the serial is released.
If the seller had months of subscription left, do I get the remaining term?
Do not count on it. Subscriptions are contracts between the vendor and the registered owner, keyed to the serial number, and vendors do not guarantee that remaining term survives an ownership change. Price the deal as if the unit arrives with zero entitlement; anything that carries over is a bonus.
Is a used Palo Alto firewall usable without going through recertification?
It will boot PAN-OS and pass traffic on its existing configuration, but between unrelated companies Palo Alto's Secondary Market Policy applies: until you pay the certification and activation fees and buy a year of support through an authorized reseller, you have no path to software updates, TAC support, or subscription licenses like Threat Prevention and WildFire in your name.
Can I put SmartNet on a used Cisco ASA or Firepower appliance?
Only after it passes Cisco's Hardware Inspection and Software Relicensing process. Cisco will not place secondary-market equipment — anything bought outside its authorized channel — under a service contract until the hardware is inspected and the software is relicensed, both at the buyer's cost. Smart Licensing entitlements also stay in the seller's Smart Account rather than following the hardware.
Does a refurbished firewall from a reseller arrive de-registered?
It should — that is a core part of professional refurbishment. A reputable refurbisher verifies that each serial has been released from the prior owner's vendor account before resale, so you can register it cleanly. Ask the seller to confirm registration status in writing before purchase; a unit stuck in someone else's account is the single most common used-firewall problem.