UK’s trusted IT infrastructure partner since 2003
sales@servnetuk.com
0800 987 4111
Servnet
ConfiguratorGet in Touch
Migration · Networking · Firewall

Cisco ASA to Firepower or FortiGate: a UK migration playbook

Servnet Editorial · Networking Practice8 min read

Cisco ASA is end-of-engineering for new features — the product line continues to receive security patches but Cisco directs all new investment to Firepower (Secure Firewall) and Catalyst SD-WAN. UK customers refreshing ASA typically face a fork: stay Cisco (Firepower), or move to Fortinet FortiGate. This is the honest playbook for both paths.

ASA → Firepower or FortiGate — 12-week plan
W0W2W4W6W8W10W12Discovery + rules2wNew FW build3wPolicy migration3wCutover (per-site)3wASA decom1wTotal: 12 weeks end-to-end

Why migrate now

Cisco ASA hardware EOSL — ASA 5500-X series increasingly past Cisco end-of-support-life. Servnet TPM can extend but the strategic direction is clear.

Feature parity — ASA doesn't support modern features (URL category, application visibility, SSL inspection at scale) that Firepower + FortiGate have as standard.

Modernisation — ZTNA + SD-WAN integration that ASA can't deliver are now standard expectations.

Path 1 — ASA to Firepower (same vendor)

Hardware: Firepower 1010 (branch), Firepower 1140 (mid), Firepower 2130 (campus), Firepower 4110 (DC).

Tools: Cisco Secure Firewall Migration Tool (free) translates ASA config to Firepower Threat Defence (FTD) config. Works for ~80% of ASA features automatically; 20% needs manual review.

Operational continuity: same Cisco TAC, same enterprise agreement, same Cisco DNA Center integration.

Timeline: 6-12 weeks for typical campus environment.

Path 2 — ASA to FortiGate (cross-vendor)

Hardware: FortiGate 60F, 100F, 400F, 1000F, 1800F.

Tools: Fortinet Migration Service (FortiConverter) translates ASA config to FortiGate. Cleaner translation than ASA → Firepower for some constructs.

Commercial: typically 30-50% lower TCO over 5 years vs Firepower equivalent. SD-WAN included in FortiOS (no separate licence).

Timeline: 8-14 weeks because of vendor change (training + management plane).

When to pick which

Existing Cisco-deep estate (Catalyst, ISE, DNA Center, Smart Net everywhere): Firepower. Single-vendor relationship value.

Cost-sensitive + open to vendor change + want SD-WAN convergence: FortiGate. Lower TCO + better SD-WAN.

Mixed estates already running both vendors: pick on lifecycle (refresh whichever is end-of-support first).

Firepower or FortiGate at swap?
Is the rest of your stack Cisco-led?
YES
Firepower — single pane
NO
FortiGate — best £ / Gbps
Mixed
FortiGate per branch + central management

Common gotchas

NAT rules — ASA NAT syntax differs significantly from both Firepower + FortiGate. Manual review essential.

VPN — IPSec site-to-site + SSL VPN migrate cleanly. Anyconnect → AnyConnect Secure Mobility Client (Firepower) or FortiClient (FortiGate) requires user-side change.

High-availability — ASA failover groups translate but the syntax differs. Test thoroughly.

Logging + monitoring — ASA syslog → SIEM rules need updating for Firepower / FortiGate event formats.

What Servnet does

Servnet runs both ASA → Firepower + ASA → FortiGate migrations. Vendor-neutral commercial bid first, then customer picks platform, then phased migration with parallel-run.

Key takeaways
  • Cisco ASA is end-of-engineering. Refresh decision is now.
  • ASA → Firepower: same vendor, lowest operational friction. Migration tools work for ~80% automatically.
  • ASA → FortiGate: cross-vendor, 30-50% lower 5-year TCO, SD-WAN included. Migration takes longer due to vendor change.
  • NAT + VPN config + HA groups + SIEM rules are the common technical gotchas regardless of path.
  • Servnet quotes both paths vendor-neutrally; you pick.
Frequently asked

FAQs — Cisco ASA to Firepower or FortiGate

Tools

How automated are the migration tools?

Cisco Secure Firewall Migration Tool covers ~80% of ASA → Firepower config automatically. Fortinet FortiConverter similar for ASA → FortiGate. Both leave NAT, VPN, custom NAT-T constructs, and HA failover for manual review.

Operations

Can we run ASA + new firewall in parallel?

Yes — typical pattern: new firewall deployed as inactive in HA standby, then promote to active during change window with rollback ready. Most cutovers happen within a 4-8 hour weekend window.

Related

Got a question this article didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →