Update Date Added additional migration options for some of the announced EoL devices. 27/03/2024 Added additional migration options for organisations that want to skip the 2100 series. 27/03/2024
Change Log
This article aims to highlight the possible migration paths from Cisco Firewalls that have been announced End of Life (EoL) to newer models.
Note
Although the 2100 series firewalls have not been announced EoL yet, some customers may choose to opt for the newer 3100 series firewalls. Therefore, we have included 3100 series firewall options where 2100s have been listed as a potential migration option.
Cost factors should also be considered.
Note
While we endeavour to keep this document updated as Cisco firewalls are announced EoL and newer devices are announced, we may not always have the latest information.
Furthermore, device migration paths may differ depending on your actual requirements and so we recommend that you always seek additional guidance where necessary.
If you feel as though any information is missing or inaccurate, please leave a comment and we will do our best to look into it.
Announced EoL Devices
The following selections ensure that each announced EoL device is matched with the closest available Firepower alternative, considering factors such as performance metrics, scalability, and compatibility .
Migration Options Summary
Announced EoL Cisco Firewall Migration Options ASA 5506 Firepower 1010/1010E ASA 5508 Firepower 1010/1010E Firepower 1140 ASA 5516 Firepower 2110 Firepower 2120 Firepower 1140 ASA 5525 Firepower 2120 Firepower 1150 ASA 5545 Firepower 2120 Firepower 2130 Firepower 3110 ASA 5555 Firepower 2120 Firepower 2140 Firepower 3120 Firepower 4110 Firepower 4125 Firepower 4120 Firepower 4125 Firepower 4140 Firepower 4125 Firepower 4150 Firepower 4125
Migration Option Summary
Migration Options Detail
ASA 5506 Migration Options
Best Migration Option
Metric ASA 5506 Firepower 1010/1010E Improvement Reason Stateful Inspection Firewall Throughput 750 Mbps 2 Gbps +1.25 Gbps Firepower 1010/1010E offers higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 300 Mbps 1.4 Gbps +1.1 Gbps Firepower 1010/1010E offers higher multiprotocol throughput Concurrent Firewall Connections 50,000 100,000 +50,000 Firepower 1010/1010E supports more concurrent connections New Connections per second 5,000 25,000 +20,000 Firepower 1010/1010E offers higher new connections per second IPsec VPN Throughput 100 Mbps 500 Mbps +400 Mbps Firepower 1010/1010E offers higher VPN throughput Maximum VPN Peers 50 75 +25 Firepower 1010/1010E supports more VPN peers
Best Migration Option for the ASA 5506
ASA 5508 Migration Options
Option One – Closest Match
Metric ASA 5508 Firepower 1010/1010E Improvement Reason Stateful Inspection Firewall Throughput 1 Gbps 2 Gbps +1 Gbps Firepower 1010 offers higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 400 Mbps 1.4 Gbps +1 Gbps Firepower 1010 offers higher multiprotocol throughput Concurrent Firewall Connections 100,000 100,000 Equal Both devices support the same number of concurrent connections New Connections per second 10,000 25,000 +15,000 Firepower 1010 offers higher new connections per second IPsec VPN Throughput 250 Mbps 500 Mbps +250 Mbps Firepower 1010 offers higher VPN throughput Maximum VPN Peers 250 75 -175 Firepower 1010 supports fewer VPN peers
Best Migration Option for the ASA 5508 – Closest Matched
Option Two – All Metrics Improved
Metric ASA 5508 Firepower 1140 Improvement Reason Stateful Inspection Firewall Throughput 1 Gbps 6 Gbps +5 Gbps Firepower 1140 offers higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 400 Mbps 3.5 Gbps +3.1 Gbps Firepower 1140 offers higher multiprotocol throughput Concurrent Firewall Connections 100,000 400,000 +300,000 Firepower 1140 supports more concurrent connections New Connections per second 10,000 100,000 +90,000 Firepower 1140 offers higher new connections per second IPsec VPN Throughput 250 Mbps 1.2 Gbps +950 Mbps Firepower 1140 offers higher VPN throughput Maximum VPN Peers 250 400 +150 Firepower 1140 supports more VPN peers
Best Migration Option for the ASA 5508 – All metrics improved
ASA 5516 Migration Options
Option One – Closest Match
Metric ASA 5516 Firepower 2110 Improvement Reason Stateful Inspection Firewall Throughput 1.8 Gbps 3 Gbps +1.2 Gbps Firepower 2110 offers an improvement in stateful inspection firewall throughput compared to ASA 5516. Stateful Inspection Firewall Throughput (multiprotocol) 900 Mbps 1.5 Gbps +600 Mbps Firepower 2110 provides an improvement in multiprotocol throughput compared to ASA 5516. Concurrent Firewall Connections 250,000 1 million +750,000 Firepower 2110 offers a substantial increase in concurrent firewall connections compared to ASA 5516. New Connections per Second 20,000 18,000 -2,000 Firepower 2110 provides a similar level of new connections per second compared to ASA 5516. IPsec VPN Throughput 250 Mbps 500 Mbps +250 Mbps Firepower 2110 offers an improvement in IPsec VPN throughput compared to ASA 5516. Maximum VPN Peers 300 1,500 +1,200 Firepower 2110 supports a significant increase in maximum VPN peers compared to ASA 5516.
Best Migration Option for the ASA 5516 – Closest Match
Option Two – All Metrics Improved
Metric ASA 5516 Firepower 2120 Improvement Reason Stateful Inspection Firewall Throughput 1.8 Gbps 6 Gbps +4.2 Gbps Firepower 2120 offers a significant improvement in stateful inspection firewall throughput compared to ASA 5516. Stateful Inspection Firewall Throughput (multiprotocol) 900 Mbps 3 Gbps +2.1 Gbps Firepower 2120 provides a substantial improvement in multiprotocol throughput compared to ASA 5516. Concurrent Firewall Connections 250,000 1.5 million +1.25 million Firepower 2120 offers a substantial increase in concurrent firewall connections compared to ASA 5516. New Connections per Second 20,000 28,000 +8,000 Firepower 2120 provides an improvement in new connections per second compared to ASA 5516. IPsec VPN Throughput 250 Mbps 700 Mbps +450 Mbps Firepower 2120 offers an increase in IPsec VPN throughput compared to ASA 5516. Maximum VPN Peers 300 3,500 +3,200 Firepower 2120 supports a significant increase in maximum VPN peers compared to ASA 5516.
Best Migration Option for the ASA 5516 – All metrics improved
Option Three – Non-2100 Series Firewall (All Metrics Improved)
Metric ASA 5516 Firepower 1140 Improvement Reason Stateful Inspection Firewall Throughput 1.8 Gbps 6 Gbps +4.2 Gbps Firepower 1140 offers higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 900 Mbps 3.5 Gbps +2.6 Gbps Firepower 1140 offers higher throughput Concurrent Firewall Connections 250,000 400,000 +150,000 Firepower 1140 supports more concurrent connections New Connections per second 20,000 100,000 +80,000 Firepower 1140 offers higher new connections per second IPsec VPN Throughput 250 Mbps 1.2 Gbps +950 Mbps Firepower 1140 offers higher VPN throughput VPN Peers 300 400 +100 Firepower 1140 supports more VPN peers
Best Migration Option for the ASA 5516 – Non-2100 Series Option
ASA 5525 Migration Options
Option One – Closest Match
Metric ASA 5525 Firepower 2120 Improvement Reason Stateful Inspection Firewall Throughput 2 Gbps 6 Gbps +4 Gbps Firepower 2120 offers a significant improvement in stateful inspection firewall throughput compared to ASA 5525. Stateful Inspection Firewall Throughput (multiprotocol) 1 Gbps 3 Gbps +2 Gbps Firepower 2120 provides a substantial improvement in multiprotocol throughput compared to ASA 5525. Concurrent Firewall Connections 500,000 1.5 million +1 million Firepower 2120 offers a substantial increase in concurrent firewall connections compared to ASA 5525. New Connections per Second 20,000 28,000 +8,000 Firepower 2120 provides an improvement in new connections per second compared to ASA 5525. IPsec VPN Throughput 300 Mbps 700 Mbps +400 Mbps Firepower 2120 offers an increase in IPsec VPN throughput compared to ASA 5525. Maximum VPN Peers 2,500 3,500 +1,000 Firepower 2120 supports an increase in maximum VPN peers compared to ASA 5525.
Best Migration Option for the ASA 5525 – Closest Match
Option Two – Non-2100 Series Firewall (All Metrics Improved)
Metric ASA 5516 Firepower 1150 Improvement Reason Stateful Inspection Firewall Throughput 1.8 Gbps 7.5 Gbps +5.7 Gbps Firepower 1150 offers significantly higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 900 Mbps 4.5 Gbps +3.6 Gbps Firepower 1150 offers significantly higher throughput Concurrent Firewall Connections 250,000 600,000 +350,000 Firepower 1150 supports more concurrent connections New Connections per second 20,000 150,000 +130,000 Firepower 1150 offers significantly higher new connections per second IPsec VPN Throughput 250 Mbps 1.7 Gbps +1.45 Gbps Firepower 1150 offers significantly higher VPN throughput VPN Peers 300 800 +500 Firepower 1150 supports more VPN peers
Best Migration Option for the ASA 5525 – Non-2100 Series Option
ASA 5545 Migration Options
Option One – Closest Match
Metric ASA 5545 Firepower 2120 Improvement Reason Stateful Inspection Firewall Throughput 3 Gbps 6 Gbps +3 Gbps Firepower 2120 offers a significant improvement in stateful inspection firewall throughput compared to ASA 5545. Stateful Inspection Firewall Throughput (multiprotocol) 1.5 Gbps 3 Gbps +1.5 Gbps Firepower 2120 provides a substantial improvement in multiprotocol throughput compared to ASA 5545. Concurrent Firewall Connections 750,000 1.5 million +750,000 Firepower 2120 offers a substantial increase in concurrent firewall connections compared to ASA 5545. New Connections per Second 30,000 28,000 -2,000 Firepower 2120 provides a slightly lower value for new connections per second compared to ASA 5545. IPsec VPN Throughput 400 Mbps 700 Mbps +300 Mbps Firepower 2120 offers an increase in IPsec VPN throughput compared to ASA 5545. Maximum VPN Peers 2,500 3,500 +1,000 Firepower 2120 supports an increase in maximum VPN peers compared to ASA 5545.
Best Migration Option for the ASA 5545 – Closest Match
Option Two – All Metrics Improved
Metric ASA 5545 Firepower 2130 Improvement Reason Stateful Inspection Firewall Throughput 3 Gbps 10 Gbps +7 Gbps Firepower 2130 offers a significant improvement in stateful inspection firewall throughput compared to ASA 5545. Stateful Inspection Firewall Throughput (multiprotocol) 1.5 Gbps 5 Gbps +3.5 Gbps Firepower 2130 provides a substantial improvement in multiprotocol throughput compared to ASA 5545. Concurrent Firewall Connections 750,000 2 million +1.25 million Firepower 2130 offers a substantial increase in concurrent firewall connections compared to ASA 5545. New Connections per Second 30,000 40,000 +10,000 Firepower 2130 provides an improvement in new connections per second compared to ASA 5545. IPsec VPN Throughput 400 Mbps 1 Gbps +600 Mbps Firepower 2130 offers a substantial improvement in IPsec VPN throughput compared to ASA 5545. Maximum VPN Peers 2,500 7,500 +5,000 Firepower 2130 supports a significant increase in maximum VPN peers compared to ASA 5545.
Best Migration Option for the ASA 5545 – All metrics improved
Option Three – Non-2100 Series Firewall (All Metrics Improved)
Metric ASA 5545 Firepower 3110 Improvement Reason Stateful Inspection Firewall Throughput 3 Gbps 18 Gbps +15 Gbps Firepower 3110 offers significantly higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 1.5 Gbps 15 Gbps +13.5 Gbps Firepower 3110 offers significantly higher throughput Concurrent Firewall Connections 750,000 2 million +1.25 million Firepower 3110 supports more concurrent connections New Connections per second 30,000 300,000 +270,000 Firepower 3110 offers significantly higher new connections per second IPsec VPN Throughput 400 Mbps 8 Gbps +7.6 Gbps Firepower 3110 offers significantly higher VPN throughput VPN Peers 2,500 3,000 +500 Firepower 3110 supports more VPN peers
Best Migration Option for the ASA 5545 – Non-2100 Series Option
ASA 5555 Migration Options
Option One – Closest Match
Metric ASA 5555 Firepower 2120 Improvement Reason Stateful Inspection Firewall Throughput 4 Gbps 6 Gbps +2 Gbps Firepower 2120 offers a higher throughput of 6 Gbps, an improvement over ASA 5555’s 4 Gbps. Stateful Inspection Firewall Throughput (multiprotocol) 2 Gbps 3 Gbps +1 Gbps Firepower 2120 provides a multiprotocol throughput of 3 Gbps, compared to ASA 5555’s 2 Gbps, resulting in a 1 Gbps improvement. Concurrent Firewall Connections 1,000,000 2,000,000 +1,000,000 Firepower 2120 supports double the concurrent firewall connections, providing a significant improvement over ASA 5555. New Connections per second 50,000 40,000 -10,000 ASA 5555 has a higher rate of new connections per second at 50,000 compared to Firepower 2120’s 40,000, resulting in a slight decrease. IPsec VPN Throughput 700 Mbps 1 Gbps +300 Mbps Firepower 2120 offers a higher IPsec VPN throughput of 1 Gbps, compared to ASA 5555’s 700 Mbps, resulting in a 300 Mbps improvement. VPN Peers 5,000 7,500 +2,500 Firepower 2120 supports 2,500 more VPN peers than ASA 5555, providing an enhancement in VPN capacity.
Best Migration Option for the ASA 5545 – Closest Match
Option Two – All Metrics Improved
Metric ASA 5555 Firepower 2140 Improvement Reason Stateful Inspection Firewall Throughput 4 Gbps 20 Gbps +16 Gbps Firepower 2140 has much higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 2 Gbps 10 Gbps +8 Gbps Firepower 2140 has significantly higher throughput Concurrent Firewall Connections 1,000,000 3,000,000 +2,000,000 Firepower 2140 supports far more connections New Connections per second 50,000 75,000 +25,000 Firepower 2140 supports more new connections per second IPsec VPN Throughput 700 Mbps 2 Gbps +1.3 Gbps Firepower 2140 has much higher VPN throughput VPN Peers 5,000 10,000 +5,000 Firepower 2140 supports more VPN peers
Best Migration Option for the ASA 5555 – All metrics improved
Option Three – Non-2100 Series Firewall (All Metrics Improved)
Metric ASA 5555 Firepower 3120 Improvement Reason Stateful Inspection Firewall Throughput 4 Gbps 22 Gbps +18 Gbps Firepower 3120 offers significantly higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 2 Gbps 17 Gbps +15 Gbps Firepower 3120 offers significantly higher throughput Concurrent Firewall Connections 1,000,000 4 million +3 million Firepower 3120 supports significantly more concurrent connections New Connections per second 50,000 500,000 +450,000 Firepower 3120 offers significantly higher new connections per second IPsec VPN Throughput 700 Mbps 10 Gbps +9.3 Gbps Firepower 3120 offers significantly higher VPN throughput VPN Peers 5,000 7,000 +2,000 Firepower 3120 supports more VPN peers
Best Migration Option for the ASA 5555 – Non-2100 Series Option
Firepower 4110 Migration Options
Best Migration Option
Metric Firepower 4110 Firepower 4125 Improvement Reason Stateful Inspection Firewall Throughput 70 Gbps 80 Gbps +10 Gbps The Firepower 4125 offers a higher stateful inspection firewall throughput. Stateful Inspection Firewall Throughput (multiprotocol) 40 Gbps 45 Gbps +5 Gbps The Firepower 4125 provides a higher multiprotocol firewall throughput. Concurrent Firewall Connections 25 million 25 million Same Both devices support the same number of concurrent firewall connections. New Connections per Second 350,000 1.1 million +750,000 The Firepower 4125 supports a significantly higher number of new connections per second. IPsec VPN Throughput 14 Gbps 19 Gbps +5 Gbps The Firepower 4125 offers higher IPsec VPN throughput. VPN Peers 20,000 20,000 Same Both devices support the same number of VPN peers.
Best Migration Option for the Firepower 4110
Firepower 4120 Migration Options
Best Migration Option
Metric Firepower 4120 Firepower 4125 Improvement Reason Stateful Inspection Firewall Throughput 70 Gbps 80 Gbps +10 Gbps Firepower 4125 offers higher throughput, an improvement over Firepower 4120. Stateful Inspection Firewall Throughput (multiprotocol) 40 Gbps 45 Gbps +5 Gbps Firepower 4125 provides a higher multiprotocol throughput, an improvement over Firepower 4120. Concurrent Firewall Connections 25 million 25 million Same Both devices support the same number of concurrent connections. New Connections per second 350,000 1.1 million +750,000 Firepower 4125 supports a significantly higher rate of new connections per second. IPsec VPN Throughput 14 Gbps 19 Gbps +5 Gbps Firepower 4125 offers higher VPN throughput, an improvement over Firepower 4120. VPN Peers 20,000 20,000 Same Both devices support the same number of VPN peers.
Best Migration Option for the Firepower 4120
Firepower 4140 Migration Options
Best Migration Option
Metric Firepower 4140 Firepower 4125 Improvement Reason Stateful Inspection Firewall Throughput 70 Gbps 80 Gbps +10 Gbps Firepower 4125 offers higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 40 Gbps 45 Gbps +5 Gbps Firepower 4125 offers higher throughput Concurrent Firewall Connections 25 million 25 million Same Firepower 4125 supports the same connections New Connections per second 350,000 1.1 million +750,000 Firepower 4125 offers significantly higher new connections per second IPsec VPN Throughput 14 Gbps 19 Gbps +5 Gbps Firepower 4125 offers higher VPN throughput VPN Peers 20,000 20,000 Same Firepower 4125 offers the same number of VPN peers as Firepower 4140, ensuring consistent support for VPN connections.
Best Migration Option for the Firepower 4140
Firepower 4150 Migration Options
Best Migration Option
Metric Firepower 4150 Firepower 4125 Improvement Reason Stateful Inspection Firewall Throughput 70 Gbps 80 Gbps +10 Gbps Firepower 4125 offers higher throughput Stateful Inspection Firewall Throughput (multiprotocol) 40 Gbps 45 Gbps +5 Gbps Firepower 4125 offers higher throughput Concurrent Firewall Connections 25 million 25 million Same Firepower 4125 supports the same connections New Connections per second 350,000 1.1 million +750,000 Firepower 4125 offers significantly higher new connections per second IPsec VPN Throughput 14 Gbps 19 Gbps +5 Gbps Firepower 4125 offers higher VPN throughput VPN Peers 20,000 20,000 Same Both devices support the same number of VPN peers
Best Migration Option for the Firepower 4150
Additional Reading
Cisco Firepower 1000 Series Data Sheet – Cisco
Cisco Firepower 2100 Series Data Sheet – Cisco
Cisco Secure Firewall 3100 Series Data Sheet – Cisco
Cisco Firepower 4100 Series Data Sheet – Cisco
Cisco Network Security Ordering Guide – Cisco
Cisco ASA 5500 Data Sheet
Cisco EoS and EoL Products
Leave a Reply