Firmware Lifecycle Planning
Tracking vendor security advisories, choosing target releases against the FortiOS support calendar, upgrading in a maintenance window and always taking a configuration backup first.
We run firmware planning, configuration backups, rule clean-up, HA and log checks for your firewall on a fixed schedule, with FortiGate as our focus, and can take over day-to-day operation as well.
Firewall maintenance is the set of recurring tasks that keep a firewall current, backed up, readable and auditable: firmware lifecycle planning, configuration backups, rule (policy) reviews, and HA, log and VPN checks. Firewall management goes further, adding monitoring, change requests and reporting so that day-to-day operation is handed to a contracted team.
Buying a firewall and running one are different jobs. Risk rarely comes from the appliance itself; it comes from configuration debt that builds up over time: temporary rules nobody dares to delete, broad policies with "all" as source or destination, firmware waiting for patches, a full log disk, an HA failover that has never been tested. Firewall maintenance puts that debt on a schedule and documents every check with evidence. We describe the periodic checks in our firewall maintenance guide and the rule review step by step in firewall rule clean-up and policy audit.
We offer two working models. With periodic maintenance we carry out health, backup, firmware and policy checks at the frequency set in the contract and report findings by priority; changes are applied by your team, or by us with your approval. With a managed firewall, monitoring, policy change management, patching, log review, reporting and license tracking sit with us, while approval stays with you. For organizations with their own specialists a co-managed model is also possible: routine work is ours, and console access and emergency authority are shared. We compare the models in what is a managed firewall service.
Firmware maintenance is now a remote-access decision. With FortiOS 7.6.3 (April 2025), SSL VPN tunnel mode was replaced by IPsec VPN on every FortiGate model, and existing settings are not carried over on upgrade; on entry-level models such as the 40F, 60F/61F and 90G/91G, SSL VPN web mode is no longer available either. That is why, on our schedule, no appliance that relies on SSL VPN is upgraded to 7.6.3 or later until IPsec IKEv2 or ZTNA access has been verified. The migration steps are in the FortiOS 7.6 SSL VPN migration plan.
Log and compliance checks are an integral part of maintenance. For organizations in Türkiye, the Regulation on Internet Collective Use Providers requires access records to be stored electronically for two years, with a value confirming their accuracy and integrity recorded daily. During maintenance we check that log flow has not stopped, that the time source (NTP) is correct, that the FortiAnalyzer or syslog quota covers the retention period and that time-stamping works. Please confirm your own obligations against the current legislation; see Law No. 5651 log retention and central log management and the KVKK technical measures checklist.
Sora Yazılım is an independent solution and procurement partner for Fortinet products. We deliver maintenance and management mainly for FortiGate firewalls; for other brands, the scope is agreed during the discovery call. Service hours, response and intervention times and change classes are defined in the contract. We have no fixed price list; quotes depend on the number of appliances and sites, HA design, change volume and log retention needs.
Out of scope: hardware faults follow the vendor's RMA process, and license and support contracts are handled separately under our FortiGate License Renewal Service. Moving from a legacy firewall to FortiGate is planned as a separate project (see our firewall migration plan). A full security operations center (SOC) or endpoint detection and response (EDR) service is not part of this contract.
The frequency and output of each item are written into the contract, and every check goes into the report together with its evidence.
Tracking vendor security advisories, choosing target releases against the FortiOS support calendar, upgrading in a maintenance window and always taking a configuration backup first.
Dated backups before and after every change, stored off the appliance, and a written rollback note for every major change.
Hit-count and last-used analysis; detection of shadowed, duplicate, any-any and expired temporary rules; an owner, purpose and ticket reference for every rule.
HA sync status, planned failover tests in a maintenance window, CPU, memory, session and disk usage, interface errors and management-access restrictions.
Remote-access inventory, MFA and user groups; an IPsec IKEv2 or ZTNA migration plan in line with the FortiOS 7.6 change, validated with a pilot.
Checks on log flow, NTP, FortiAnalyzer/syslog retention quota and Law 5651 time-stamping; periodic reports on changes, findings, firmware and license dates.
An initial audit makes the current state visible; every period after that repeats the same checklist and the same report format.
Appliances, FortiOS versions, license end dates, rule count, HA, VPN and log architecture are documented. Output: a baseline report.
A dated backup is taken; policy, management-access, VPN and log findings are ranked by risk, and urgent items are closed first.
Maintenance frequency, windows, approval matrix, escalation chain, service hours and response times are put in writing.
Every change passes through request, approval, implementation, verification and logging, with a backup before and after.
Periodic reports cover changes, findings, firmware and license status; a full policy review is repeated at least every six months.
Periodic maintenance and a prioritized findings report for teams that run daily IT but have no time for firmware, rule reviews and log checks.
Consistent policy across sites, central backups and a single report; appliances stuck on different releases brought onto one firmware plan.
Maintenance records that document log retention, access control and rule reviews with dated evidence, ready to show an auditor.
A controlled move to IPsec IKEv2 or ZTNA ahead of the FortiOS 7.6 change: pilot users first, upgrade afterwards.
An inventory of an undocumented rule base, re-approval of rules without a justification and a documented management process.
Global vendor solutions we position within this service scope.
NIST SP 800-41 Rev. 1 — Guidelines on Firewalls and Firewall Policy
NIST SP 800-41 Rev. 1 — Guidelines on Firewalls and Firewall Policy →We plan your FortiGuard security bundle (ATP, UTP, Enterprise Protection) and FortiCare support contract before they expire, procure them, register them to your appliance and verify that the services are actually updating again.
CI/CD pipeline setup, container orchestration, observability and zero-downtime deployment processes that put your infrastructure on a modern foundation.
Can't find your question here? Use the form below.
Tell us the appliance model, the number of sites and whether you use SSL VPN. We will assess the current state and come back with a maintenance scope and quote.
We work Monday–Friday, 09:00–18:00 (TRT).
GDPR/KVKK compliant — never shared with third parties.
No commitment required; a proposal follows.
An initial audit shows the priorities across firmware, rules, HA, logs and VPN; we then build the maintenance schedule around them.