UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Network migration
From
Cisco ASA
To
Cisco Firepower

Cisco ASA to Firepower migration — UK enterprise programme

For Cisco-led UK enterprises hitting Cisco ASA end-of-sale, Firepower is the natural same-vendor refresh — preserves Cisco operations, integrates cleanly with Catalyst networking, ISE identity and Umbrella DNS security. Servnet runs end-to-end ASA → Firepower migrations including rule conversion, FMC deployment and per-site cutover.

Vendor migration programme — Cisco ASA source on the left, Cisco Firepower target on the right, with parallel-running data streams converging through a central Servnet cutover hub.
From → To: Cisco ASA vs Cisco Firepower
CURRENTCisco ASAProduction workloadsLegacy management planeRenewal due / EoSServnetparallel-running migrationTARGETCisco FirepowerProduction workloadsModern management planeStrategic 5-yr position
Typical outcomes

What good looks like after a Cisco ASACisco Firepower migration

Throughput uplift
×3-5

Typical Firepower replacing an ASA at similar £-band.

Per-site cutover
45-90 min

Single firewall site cutover with rule conversion + validation.

Migration window
10-16 wk

End-to-end for a 10-30 site estate.

Cisco operational continuity
↑ high

No vendor change — existing Cisco skills, support contracts, tooling all preserved.

The why

Why UK organisations migrate from Cisco ASA to Cisco Firepower

  • ASA reached EoS — same-vendor refresh maintains Cisco operational continuity
  • Native integration with Cisco Catalyst networking + ISE + DNA Center + Umbrella
  • Snort 3 IPS + AMP for Networks + URL filtering + AVC built-in
  • Cisco DNA Subscription bundles centralised management + licensing
  • Single-pane FMC (Firepower Management Center) across the fleet
  • Existing Cisco TAC + Smart Net Total Care continuity
How we run it

Migration phasing — typical Cisco ASACisco Firepower programme

Cisco ASA → Cisco Firepower — programme timeline
W0W2W4W6W8W10W12W14W16Discovery + rule analysis3wFirepower platform build4wPilot site cutover (1-3 sites)2wPhased site cutover6wASA decommission1wTotal programme: 16 weeks · parallel running throughout
  1. 1

    Discovery + rule analysis

    Weeks 1-3

    ASA config extraction; Firepower Migration Tool (FMT) conversion; per-site sizing; FMC architecture design; ISE + Umbrella + DNA Center integration design.

  2. 2

    Firepower platform build

    Weeks 4-7

    Hardware delivery; FMC deployment + clustering; central policy templates; access policies + intrusion + URL + AMP policies configured; integration testing.

  3. 3

    Pilot site cutover (1-3 sites)

    Weeks 8-9

    Non-critical sites cutover with on-site engineer; rollback rehearsal; functional + performance validation; user acceptance.

  4. 4

    Phased site cutover

    Weeks 10-15

    Remaining sites cutover in waves; rollback option preserved 24h post-cutover; ITSM tracked.

  5. 5

    ASA decommission

    Week 16

    Final sites cutover; ASA hardware decommissioned; FMC + Smart Net Total Care operational handover.

Included in scope

What Servnet delivers in a Cisco ASACisco Firepower migration

Firepower Migration Tool (FMT)

Free Cisco tooling — we run + validate + remediate the converted ruleset before any cutover.

Hardware procurement

<a href="/cisco/products">Firepower 1100 / 2100 / 3100 / 4100 / 9300 series</a> sized per site — quoted at vendor-direct pricing.

FMC + FMC HA deployment

Centralised management with HA + DR-paired FMC where the estate size warrants.

Cisco DNA Subscription licensing

Essentials / Advantage / Premier sized to feature requirements.

ISE / Umbrella / DNA integration

Identity-aware policy enforcement + DNS security + topology integration.

Per-site cutover runbook

Each site gets a runbook with cutover steps, rollback triggers, validation tests.

De-risking the cutover

Top risks + how we mitigate them

⚠️ FMT conversion has rule limitations
FMT handles the bulk of conversion; we identify + manually convert the remaining edge cases (complex NAT, certificate-based rules, custom logging). Result is a fully validated ruleset before cutover.
⚠️ Firepower licensing more complex than ASA Smart Licensing
We size the DNA Subscription tier (Essentials / Advantage / Premier) to your feature requirements and document the licensing position for ongoing management.
⚠️ Existing AnyConnect VPN must continue
Firepower supports AnyConnect SSL VPN — existing client deployments continue working with minimal user impact. Many customers use this as the trigger to evaluate <a href="/insights/vpn-to-ztna-migration">ZTNA</a> as the longer-term direction.
⚠️ Cutover impacts production during weekday hours
Cutovers scheduled for change windows; HA pairs cut over one chassis at a time with no production impact; rollback preserved for 24h.
Pricing guide rail

Indicative: ASA → Firepower migrations for a 10-30 site estate typically run £30k-£70k professional services (excluding Firepower hardware + DNA Subscription licences). Total programme cost typically 30-50% above equivalent FortiGate alternative, justified by Cisco operational continuity + ecosystem integration. Talk to us for a sized commercial proposal modelling both options.

Frequently asked

FAQs — Cisco ASACisco Firepower

Should we stay with Cisco or move to FortiGate?

If your network estate is Cisco-led (Catalyst switches, ISE, DNA Center, Umbrella, Webex) the same-vendor continuity often outweighs FortiGate's pricing advantage. If your network estate is mixed-vendor or already moving toward best-of-breed, FortiGate is the typical winner.

What's the difference between Firepower 1100 / 2100 / 3100 / 4100 / 9300?

1100-series is small branch (up to 4 Gbps); 2100-series is mid-branch; 3100-series is medium enterprise; 4100-series is data centre; 9300-series is service-provider chassis. We size per-site during discovery.

Will Cisco TAC continue covering the migrated estate?

Yes — Smart Net Total Care (SNTC) coverage moves to the Firepower hardware. Existing Cisco TAC relationships continue without interruption.

Can we cluster Firepower for high throughput?

Yes — Firepower supports inter-chassis clustering on 4100 + 9300 platforms, plus active/active failover on 3100 + 4100. Sized appropriately during discovery.

Go deeper

Ready to scope your Cisco ASACisco Firepower migration?

30-minute discovery call with an engineer who's run this migration before. Honest scoping, no sales script.

Book a scoping call →
💷 Spread the cost · IT finance

Finance the hardware behind your Cisco ASA → Cisco Firepower migration

Spread the cost of the target Cisco Firepower platform, servers and storage across a lease or hire-purchase term instead of a single capital outlay — keep the migration moving without a big up-front bill. Indicative terms; subject to status.

See IT finance options

Indicative estimate · subject to change · no credit check at this stage · hire purchase, lease & subscription for UK businesses

Indicative illustration only. Servnet Limited is not authorised or regulated by the FCA and does not provide financial advice or arrange finance. All finance opportunities are referred to Number Eight Business Finance. Finance policy

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111