Uniqcli

Cisco ASA 5508-X (ASA5508-K9) to Firepower 1000 Migration

A practical refresh guide for branch teams replacing the end-of-life ASA 5508-X with FirePOWER Services with the Cisco Secure Firewall 1000 Series before the August 31, 2026 last day of support.

UT
Uniqcli Team
September 22, 2025 · 9 min read
Share
Cisco ASA 5508-X (ASA5508-K9) to Firepower 1000 Migration

If you still run a Cisco ASA 5508-X with FirePOWER Services (PID ASA5508-K9) at a branch, a remote site, or a small data closet, the clock has effectively run out. This 1RU appliance was the workhorse of the ASA 5500-X line for years, but it went end-of-sale on August 2, 2021, and its Last Day of Support (LDoS) is August 31, 2026. After that date Cisco issues no further software fixes, no PSIRT remediation, and no TAC or RMA coverage for the platform. This guide explains, in concrete terms, what each milestone means, why the Firepower 1000 Series (now branded Cisco Secure Firewall 1000 Series) is the right successor for this specific box, and how to execute the migration without an outage or a compliance gap.

Why the ASA 5508-X end of life matters right now

The 5508-X has a structural problem that makes its retirement more urgent than a typical refresh: it splits security across two software stacks. The ASA image handles stateful firewalling and VPN, while a separate FirePOWER Services (SFR) software module — running on its own partition on the SSD — handles application visibility (AVC) and next-generation IPS. Two images means two patch trains, and once LDoS passes, neither one receives fixes. A future critical vulnerability in either the ASA code or the FirePOWER module simply will not be patched. There is nothing to upgrade to.

For regulated buyers this is not an abstract risk. An internet-facing firewall that can no longer receive security patches is a documented finding in any serious audit. Frameworks that federal, DoD, SLED, and healthcare organizations live under — FISMA/NIST 800-53 (notably SI-2, flaw remediation), CMMC, HIPAA Security Rule, and PCI-DSS — all expect that perimeter security devices remain vendor-supported and patchable. Running an unsupported edge firewall past LDoS converts a hardware-lifecycle issue into a control failure. Acting before August 31, 2026 keeps the refresh on your schedule and budget instead of an auditor's or an incident responder's.

What each milestone date actually means

Cisco's lifecycle vocabulary trips people up, so here is the plain-English version for the 5508-X specifically.

  • End of Sale (Aug 2, 2021): Cisco stopped selling new ASA5508-K9 units. Anything you buy after this is used, refurbished, or remaining channel stock — relevant to TAA and warranty questions covered below.
  • End of Software Maintenance: the point after which Cisco stops producing maintenance and bug-fix releases for the platform's software trains. For the 5508-X this is folded into the broader timeline; in practice, treat new feature and routine bug fixes as already gone.
  • Last Day of Support (Aug 31, 2026): the true cliff. This is the final date Cisco provides any support — TAC cases, RMA hardware replacement, and critically, PSIRT security patches. After this, the device is on its own.

You can confirm the dates and the official replacement guidance for your exact PID on our ASA 5508-X end-of-life detail page, and browse the broader retirement schedule on the Cisco EoL hub. The practical takeaway: the only milestone that stops the world is LDoS, and you should aim to have hardware racked and traffic cut over well before it, not on it.

The replacement: Cisco Secure Firewall 1000 Series

The direct successor to the ASA 5508-X is the Firepower 1120 (FPR1120-NGFW-K9) within the 1000 Series, with the 1140 and 1150 available if you need more headroom or 10G fiber. The 1010 sits below for very small sites. The 1120 keeps the same 1RU desktop/rack form factor and the same eight 10/100/1000 copper interfaces you have today, then adds four SFP ports for fiber uplinks — something the all-copper 5508-X never had. That single change often removes a media converter or a separate switch hop at the branch edge.

The throughput and architecture jump

The performance difference is not incremental. The 5508-X delivered roughly 1 Gbps of stateful firewall throughput, but the moment you turned on the FirePOWER module for AVC and NGIPS — the entire reason most people bought it — real throughput collapsed to about 250 Mbps because inspection ran on the separate SFR module. Branch links have outgrown that. The Firepower 1120 sustains about 2.3 Gbps with firewall, AVC, and IPS all enabled simultaneously, roughly a 9x improvement in inspected throughput, because there is no separate module: it runs a single unified image. IPsec VPN throughput climbs from around 175 Mbps to about 1.2 Gbps, concurrent sessions double from 100,000 to 200,000, and new connections per second rise to about 15,000. For any site doing TLS-heavy traffic or backhauling VPN, this is the difference between inspection being a tax and inspection being free.

One image, one manager, modern licensing

The biggest operational change is the move from the ASA-plus-FirePOWER split to a single Firepower Threat Defense (FTD) image. On the 1000 Series, firewall, VPN, AVC, and IPS are one software stack with one configuration and one upgrade. You manage FTD with Firepower Management Center (FMC, on-prem or virtual) for centralized multi-site policy, with the on-box Firepower Device Manager (FDM) for single appliances, or with cloud-delivered Cisco Defense Orchestrator (CDO) — none of which existed in usable form for the 5508-X's split model. Licensing also modernizes: the old PAK/à-la-carte activation keys give way to Cisco Smart Licensing with subscription tiers (Threat, Malware/Secure Malware Analytics, URL Filtering, and the bundled Threat+Malware+URL option), tracked in your Smart Account.

A practical migration plan

1. Assess and inventory

Pull the running config from each 5508-X (show running-config) and export the FirePOWER access control, intrusion, and malware policies separately, since they live in the SFR module. Document every site's WAN bandwidth, VPN peers (the 5508-X capped at 100; the 1120 supports 150), NAT rules, interface assignments, and any high-availability failover pairs. Use show version and show inventory to capture serials for asset reconciliation. This inventory is also your sizing input: if a site is already saturating the 5508-X, the 1120's headroom may let you consolidate.

2. Plan licensing and the config conversion

Stand up or confirm a Cisco Smart Account, then size subscriptions per appliance. Cisco's Firepower Migration Tool (FMT) imports an ASA configuration and converts interfaces, objects, NAT, ACLs, and site-to-site VPN into FTD policy, flagging anything unsupported for manual review. Treat the output as a draft to validate, not a finished policy — the FirePOWER intrusion and AVC policies are rebuilt in FMC/FDM, where rule sets are richer than the old SFR module's.

3. Confirm feature parity

Map each 5508-X feature to its FTD equivalent before cutover: remote-access VPN (the 1000 Series supports AnyConnect/Secure Client), site-to-site IPsec, identity policy, URL and application control, and any ASA features in use (some niche ASA capabilities differ under FTD, which is another reason to test). Validate that your syslog/SIEM, NetFlow, and management ACLs are accounted for in the new policy.

4. Handle the physical layer

Both boxes are 1RU, so rack space and the single non-redundant power story are similar — but plan power and cabling deliberately. The 1120 adds four SFP cages: order the right optics (1G SFP, e.g. GLC-LH-SMD for fiber or GLC-TE for copper SFP) if you intend to use fiber uplinks, since they are not included. Confirm console (the 1000 Series uses standard RJ-45/USB console) and management port wiring. If a site runs an HA failover pair, you migrate them as a pair and rebuild failover under FTD.

5. Cut over in phases, then decommission securely

Stage and pre-configure the Firepower 1120 on the bench, push policy from FMC/FDM, and validate against the inventory. For a single site, schedule a maintenance window and swap; for a fleet, run a phased rollout — a pilot site, a soak period, then waves grouped by region or risk. Keep the 5508-X powered but cabled-out for a brief rollback window. Once the new edge is stable, decommission the old unit properly: wipe the configuration and the SSD (which held the FirePOWER module and any cached data), record the serial as retired, and dispose through a process that satisfies your data-sanitization policy — NIST SP 800-88 media sanitization is the federal benchmark.

Procurement notes for government and enterprise

Because the 5508-X is end-of-sale, do not solve a support problem by buying more used 5508-X units — that just resets the same expiring clock. Buy current 1000 Series hardware through an authorized partner so you get genuine, warranty-eligible, Smart-License-attachable appliances. For federal and SLED buyers, specify TAA-compliant product and confirm country of origin up front; an authorized partner can provide the documentation auditors expect. Government Purchase Card (GPC) orders, GSA/SEWP and other contract-vehicle purchases, and quoted lead times all run more smoothly when the source is authorized rather than gray-market. Build in lead time: branch firewalls are high-volume but supply can tighten near a popular platform's transitions, and you want hardware in hand with margin before the August 31, 2026 LDoS.

You can compare and browse the Firepower 1000 Series replacement options in our catalog, and when you are ready to size the refresh for one site or a whole fleet, our team will scope licensing, optics, and quantities against your inventory.

Frequently asked questions

What replaces the Cisco ASA 5508-X (ASA5508-K9)?

The direct replacement is the Cisco Firepower 1120 (FPR1120-NGFW-K9) in the Secure Firewall 1000 Series. It keeps the same 1RU form factor and eight Gigabit copper ports, adds four SFP fiber uplinks, and runs a single unified Firepower Threat Defense image instead of the 5508-X's split ASA-plus-FirePOWER-module design. The 1140 and 1150 are available if you need more throughput or 10G.

When does the ASA 5508-X reach end of support?

The Last Day of Support (LDoS) is August 31, 2026. It went end-of-sale on August 2, 2021. After LDoS, Cisco provides no PSIRT security patches, no software maintenance, and no TAC support or hardware RMA, so the device should be replaced before that date.

How much faster is the Firepower 1120 than the ASA 5508-X with inspection on?

With firewall, AVC, and IPS all enabled, the Firepower 1120 sustains about 2.3 Gbps, versus roughly 250 Mbps of AVC/NGIPS on the 5508-X's FirePOWER module — close to a 9x improvement. IPsec VPN throughput also rises from about 175 Mbps to roughly 1.2 Gbps, and concurrent sessions double to 200,000.

Can the Firepower 1000 Series still run ASA software?

Yes. The 1000 Series can boot a classic ASA image or the unified FTD image. That lets teams with heavy ASA CLI/ASDM investment land on the new hardware first with ASA, then transition to FTD later. Most deployments should target FTD to gain unified inspection and modern management via FMC, FDM, or cloud-delivered CDO.

How do I migrate my ASA 5508-X configuration to FTD?

Use Cisco's Firepower Migration Tool (FMT) to import the ASA running-config and convert interfaces, objects, NAT, ACLs, and site-to-site VPN into FTD policy. Rebuild the FirePOWER intrusion and application-control policies in FMC or FDM, since those lived on the separate SFR module. Validate the converted config against your inventory before cutover, and migrate HA pairs together.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote