UK’s trusted IT infrastructure partner since 2003
sales@servnetuk.com
0800 987 4111
Servnet
ConfiguratorGet in Touch
Network migration
From
Cisco ASA
To
Cisco Firepower

Cisco ASA to Firepower migration — UK enterprise programme

For Cisco-led UK enterprises hitting Cisco ASA end-of-sale, Firepower is the natural same-vendor refresh — preserves Cisco operations, integrates cleanly with Catalyst networking, ISE identity and Umbrella DNS security. Servnet runs end-to-end ASA → Firepower migrations including rule conversion, FMC deployment and per-site cutover.

Vendor migration programme — Cisco ASA source on the left, Cisco Firepower target on the right, with parallel-running data streams converging through a central Servnet cutover hub.
From → To: Cisco ASA vs Cisco Firepower
CURRENTCisco ASAProduction workloadsLegacy management planeRenewal due / EoSServnetparallel-running migrationTARGETCisco FirepowerProduction workloadsModern management planeStrategic 5-yr position
Typical outcomes

What good looks like after a Cisco ASACisco Firepower migration

Throughput uplift
×3-5

Typical Firepower replacing an ASA at similar £-band.

Per-site cutover
45-90 min

Single firewall site cutover with rule conversion + validation.

Migration window
10-16 wk

End-to-end for a 10-30 site estate.

Cisco operational continuity
↑ high

No vendor change — existing Cisco skills, support contracts, tooling all preserved.

The why

Why UK organisations migrate from Cisco ASA to Cisco Firepower

  • ASA reached EoS — same-vendor refresh maintains Cisco operational continuity
  • Native integration with Cisco Catalyst networking + ISE + DNA Center + Umbrella
  • Snort 3 IPS + AMP for Networks + URL filtering + AVC built-in
  • Cisco DNA Subscription bundles centralised management + licensing
  • Single-pane FMC (Firepower Management Center) across the fleet
  • Existing Cisco TAC + Smart Net Total Care continuity
How we run it

Migration phasing — typical Cisco ASACisco Firepower programme

Cisco ASA → Cisco Firepower — programme timeline
W0W2W4W6W8W10W12W14W16Discovery + rule analysis3wFirepower platform build4wPilot site cutover (1-3 sites)2wPhased site cutover6wASA decommission1wTotal programme: 16 weeks · parallel running throughout
  1. 1

    Discovery + rule analysis

    Weeks 1-3

    ASA config extraction; Firepower Migration Tool (FMT) conversion; per-site sizing; FMC architecture design; ISE + Umbrella + DNA Center integration design.

  2. 2

    Firepower platform build

    Weeks 4-7

    Hardware delivery; FMC deployment + clustering; central policy templates; access policies + intrusion + URL + AMP policies configured; integration testing.

  3. 3

    Pilot site cutover (1-3 sites)

    Weeks 8-9

    Non-critical sites cutover with on-site engineer; rollback rehearsal; functional + performance validation; user acceptance.

  4. 4

    Phased site cutover

    Weeks 10-15

    Remaining sites cutover in waves; rollback option preserved 24h post-cutover; ITSM tracked.

  5. 5

    ASA decommission

    Week 16

    Final sites cutover; ASA hardware decommissioned; FMC + Smart Net Total Care operational handover.

Included in scope

What Servnet delivers in a Cisco ASACisco Firepower migration

Firepower Migration Tool (FMT)

Free Cisco tooling — we run + validate + remediate the converted ruleset before any cutover.

Hardware procurement

<a href="/cisco/products">Firepower 1100 / 2100 / 3100 / 4100 / 9300 series</a> sized per site — quoted at vendor-direct pricing.

FMC + FMC HA deployment

Centralised management with HA + DR-paired FMC where the estate size warrants.

Cisco DNA Subscription licensing

Essentials / Advantage / Premier sized to feature requirements.

ISE / Umbrella / DNA integration

Identity-aware policy enforcement + DNS security + topology integration.

Per-site cutover runbook

Each site gets a runbook with cutover steps, rollback triggers, validation tests.

De-risking the cutover

Top risks + how we mitigate them

⚠️ FMT conversion has rule limitations
FMT handles the bulk of conversion; we identify + manually convert the remaining edge cases (complex NAT, certificate-based rules, custom logging). Result is a fully validated ruleset before cutover.
⚠️ Firepower licensing more complex than ASA Smart Licensing
We size the DNA Subscription tier (Essentials / Advantage / Premier) to your feature requirements and document the licensing position for ongoing management.
⚠️ Existing AnyConnect VPN must continue
Firepower supports AnyConnect SSL VPN — existing client deployments continue working with minimal user impact. Many customers use this as the trigger to evaluate <a href="/insights/vpn-to-ztna-migration">ZTNA</a> as the longer-term direction.
⚠️ Cutover impacts production during weekday hours
Cutovers scheduled for change windows; HA pairs cut over one chassis at a time with no production impact; rollback preserved for 24h.
Pricing guide rail

Indicative: ASA → Firepower migrations for a 10-30 site estate typically run £30k-£70k professional services (excluding Firepower hardware + DNA Subscription licences). Total programme cost typically 30-50% above equivalent FortiGate alternative, justified by Cisco operational continuity + ecosystem integration. Talk to us for a sized commercial proposal modelling both options.

Frequently asked

FAQs — Cisco ASACisco Firepower

Should we stay with Cisco or move to FortiGate?

If your network estate is Cisco-led (Catalyst switches, ISE, DNA Center, Umbrella, Webex) the same-vendor continuity often outweighs FortiGate's pricing advantage. If your network estate is mixed-vendor or already moving toward best-of-breed, FortiGate is the typical winner.

What's the difference between Firepower 1100 / 2100 / 3100 / 4100 / 9300?

1100-series is small branch (up to 4 Gbps); 2100-series is mid-branch; 3100-series is medium enterprise; 4100-series is data centre; 9300-series is service-provider chassis. We size per-site during discovery.

Will Cisco TAC continue covering the migrated estate?

Yes — Smart Net Total Care (SNTC) coverage moves to the Firepower hardware. Existing Cisco TAC relationships continue without interruption.

Can we cluster Firepower for high throughput?

Yes — Firepower supports inter-chassis clustering on 4100 + 9300 platforms, plus active/active failover on 3100 + 4100. Sized appropriately during discovery.

Go deeper

Ready to scope your Cisco ASACisco Firepower migration?

30-minute discovery call with an engineer who's run this migration before. Honest scoping, no sales script.

Book a scoping call →