
If you still have a Cisco ASA 5515-X (PID ASA5515-K9) carrying production traffic, it is now running well past every support boundary Cisco defined for it. The platform went End-of-Sale on August 25, 2017, and reached its Last Date of Support (LDoS) on August 31, 2022, per Cisco bulletin c51-738644. As of today the box is unpatched, unsupported, and — in most regulated environments — a live audit finding. This guide lays out exactly what those dates mean, why the Secure Firewall 1100 Series is the right successor for a unit this size, and a practical, low-risk plan to move.
What this product was, and why its clock ran out
The ASA 5515-X was the small-enterprise rung of the ASA 5500-X line: a 1RU appliance built on a multi-core x86 (Sandy Bridge-class) CPU with 8 GB of RAM, six copper GigabitEthernet data interfaces plus a dedicated management port, and a slot for an SSD that hosted the optional FirePOWER Services software module. Real-world numbers were modest by current standards — roughly 1.2 Gbps of stateful firewall throughput, about 250 Mbps once you turned on next-gen IPS/AVC inspection through FirePOWER Services, around 250,000 concurrent connections, and 250 IPsec/AnyConnect VPN peers. It shipped in the PAK (Product Activation Key) licensing era, where features like Security Plus, AnyConnect Premium, and FirePOWER subscriptions were tied to per-box activation keys rather than a cloud license pool.
That architecture aged out in two ways. First, the hardware crypto and packet-processing engines simply cannot keep pace with TLS 1.3 inspection, modern AnyConnect/Secure Client loads, or line-rate threat inspection. Second — and decisively — Cisco closed the support lifecycle. The detailed lifecycle dates live on the ASA5515-K9 EoL page; the rest of the ASA 5500-X family is tracked on our Cisco EoL hub.
What each milestone date actually means
- End-of-Sale (Aug 25, 2017): Cisco stopped selling the ASA5515-K9 through normal channels. Any unit acquired after this is refurbished or gray-market — fine for a lab, not for a supported production edge.
- End of Software Maintenance: not separately published for this PID; in practice, maintenance and PSIRT coverage tracked to the LDoS date. The takeaway is the same — no new ASA software trains or vulnerability fixes are being produced for this hardware.
- Last Date of Support / LDoS (Aug 31, 2022): the hard wall. After this date Cisco TAC will not open new cases, RMA hardware replacement ends, and PSIRT no longer ships patches for newly disclosed CVEs on this platform. The device is frozen in time while the threat landscape is not.
For federal, DoD, SLED, and healthcare buyers the compliance angle is concrete. FedRAMP, CMMC, HIPAA, PCI-DSS, and most STIG/RMF baselines require that security-relevant systems remain vendor-supported and patchable. An edge firewall past LDoS fails that test on its face — it is one of the first items a serious assessor looks for, and it cannot be remediated by configuration. The only fix is a refresh.
The replacement: Cisco Secure Firewall 1100 Series
Cisco's named successor for a 5515-X-class deployment is the Secure Firewall 1100 Series (formerly Firepower 1100). It is a desktop/1RU family — the 1010, 1120, 1140, and 1150 — purpose-built for branch and small-enterprise edge. For a site that was correctly sized on a 5515-X, the 1140 is the natural like-for-like target, with the 1150 adding 10G SFP+ uplinks and more inspection headroom, and the 1120 covering lighter branches. (Sites that have outgrown the 5515-X envelope entirely should look at the 3100 Series instead; we'll flag that during sizing.)
What you concretely gain
- Throughput and crypto: the 1100 Series delivers multi-gigabit threat-inspection throughput — many times the 5515-X's ~250 Mbps NGFW number — with dedicated onboard crypto acceleration, so you can finally run TLS decryption and full IPS without falling off a cliff.
- Dual personality: the 1100 boots either classic ASA software or Firepower Threat Defense (FTD). You can keep an ASA config running on day one and convert to FTD later — a migration lever the 5515-X's bolt-on FirePOWER module never offered cleanly.
- Integrated SSD and embedded NGFW: IPS, application visibility/control (AVC), URL filtering, and malware defense are built into the unified image rather than a separate co-processor sharing a chassis.
- Modern management: manage on-box with Firepower Device Manager (FDM), centrally with Secure Firewall Management Center (FMC), or from the cloud with Cisco Defense Orchestrator (CDO). The 5515-X era's ASDM-plus-separate-FMC split is gone.
- Smart Licensing: the 1100 uses Cisco Smart Licensing with a cloud entitlement pool (Essentials/Base plus optional Threat, Malware, and URL subscriptions). No more per-box PAK keys to chase at RMA time — entitlements follow your Smart Account.
A practical migration plan
1. Assess and inventory
Pull the running config and a 'show tech' from the 5515-X. Catalog interfaces in use, security levels, peak throughput and concurrent connections (from monitoring, not the datasheet), VPN tunnels and peers, identity/AAA integrations, and any FirePOWER Services policies. This data drives model selection — 1120 vs 1140 vs 1150 — and surfaces features that need a parity check.
2. License transition
Set up or confirm your Cisco Smart Account and Virtual Account before hardware arrives. Map old PAK entitlements (Security Plus, AnyConnect, FirePOWER subscriptions) to the 1100's Smart License equivalents — the firewall Essentials tier plus the Threat/Malware/URL subscriptions you actually use. AnyConnect/Secure Client user licensing moves to the modern Secure Client tiers.
3. Config and feature parity
If you stay on ASA software, most of the config ports over with interface and naming adjustments. If you move to FTD, use the Cisco Secure Firewall Migration Tool to convert the ASA config into an FTD policy, then review every rule — the tool is a strong starting draft, not a finished policy. Validate NAT, identity, VPN crypto maps/profiles, and any ACL ordering by hand.
4. Physical: rack, power, uplinks, optics
The 1100 Series is compact and single-PSU on the smaller models — confirm rack space, outlet type, and whether you want the 1150's redundant power. Plan uplinks: if you move from copper GigE to SFP+ on the 1150, order the correct Cisco-coded optics. Stage interface mapping so the new appliance's port layout matches your existing cabling and VLAN/trunk design.
5. Phased cutover
Build and burn-in the 1100 in parallel with the live 5515-X. Pre-stage the policy, replicate VPN configs, and test in a maintenance window with the ability to roll back to the 5515-X if validation fails. Cut over interface by interface where the topology allows, validate VPN re-establishment and inspection logging, then run a soak period before retiring the old unit.
6. Secure decommission
Once the 1100 is stable, securely wipe the 5515-X — erase the startup config, certificates, pre-shared keys, and the FirePOWER SSD. For DoD/federal disposal, follow your NIST SP 800-88 media sanitization process and retain the certificate of destruction or wipe for your records.
Procurement notes for government and enterprise buyers
- TAA compliance: specify TAA-compliant Secure Firewall 1100 SKUs for federal and many SLED contracts — we confirm country-of-origin before quoting.
- GPC / purchase card: micro-purchase and card-payable orders are supported, which keeps small branch refreshes moving without a full procurement cycle.
- Lead times: firewall lead times fluctuate — because you are past LDoS, order early and ask us to confirm current availability and any in-stock units.
- Authorized sourcing: buy the replacement and its subscriptions through an authorized Cisco partner so the hardware is genuine, Smart Licensing registers cleanly, and SmartNet/Success Tracks coverage is valid from day one. Browse the family in our catalog.
Running an edge firewall years past its Last Date of Support is the kind of risk that stays invisible right up until an auditor or an attacker finds it. The good news is the path off the ASA 5515-X is well-trodden and the Secure Firewall 1100 Series is a clear upgrade in throughput, security efficacy, and manageability. Get the sizing right and the cutover is a routine maintenance window. Ready to scope it? Get a refresh quote and we'll size the exact 1100 model, line up TAA-compliant, GPC-payable hardware, and plan the migration.
Frequently asked questions
Is the Cisco ASA 5515-X (ASA5515-K9) still supported in 2026?
No. The ASA 5515-X went End-of-Sale on August 25, 2017 and reached its Last Date of Support on August 31, 2022. Cisco no longer issues software maintenance, PSIRT security fixes, or TAC/RMA hardware service for it. Any 5515-X in production is running unpatched and unsupported, which most auditors will flag. The replacement is the Secure Firewall 1100 Series.
What Firepower 1100 model replaces the ASA 5515-X?
For most sites that sized a 5515-X, the Secure Firewall 1140 is the closest like-for-like, with the 1150 adding 10G SFP+ uplinks and more inspection headroom, and the 1120 covering lighter branches. All deliver far higher throughput than the 5515-X's ~1.2 Gbps stateful firewall and ~250 Mbps with threat inspection, plus onboard crypto acceleration the 5515-X lacked. We size the exact model from your real throughput, VPN, and feature data.
Can I keep running ASA software, or do I have to move to FTD?
You have a choice. The Firepower 1100 Series boots either ASA software or Firepower Threat Defense (FTD). Staying on ASA software is the fastest, lowest-risk cutover because your ACLs, NAT, and VPN config translate almost directly. Moving to FTD unlocks the full next-gen feature set and unified policy but is a re-architecture. Many teams land on ASA software first to make the deadline, then convert to FTD later.
How does licensing change from the ASA 5515-X to the 1100 Series?
The 5515-X used PAK-based per-box activation keys for Security Plus, AnyConnect, and FirePOWER subscriptions. The 1100 Series uses Cisco Smart Licensing with a cloud entitlement pool: a firewall Essentials tier plus optional Threat, Malware, and URL subscriptions, all tied to your Smart Account rather than the chassis. Set up or confirm your Smart Account before the hardware arrives so registration is clean.
Are Secure Firewall 1100 appliances TAA compliant and GPC-payable for government buyers?
Yes. We quote TAA-compliant 1100 Series SKUs and confirm country-of-origin before ordering, and the appliances are card-payable for micro-purchase and GPC orders. Because the 5515-X is already past Last Date of Support, order early so we can confirm current lead times and any in-stock units.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read