Uniqcli

Cisco ASA 5585-X (S20) EoL: Migration to Secure Firewall 3130

The ASA 5585-X SSP-20 (ASA5585-S20-K9) passed Last Day of Support on May 31, 2023. Here is what each milestone means and how to migrate cleanly to the Cisco Secure Firewall 3130.

UT
Uniqcli Team
March 28, 2026 · 9 min read
Share
Cisco ASA 5585-X (S20) EoL: Migration to Secure Firewall 3130

If you still have a Cisco ASA 5585-X with an SSP-20 (PID ASA5585-S20-K9) anchoring a data-center perimeter or a high-throughput internet edge, the support clock has fully run out. This 2U chassis-based appliance reached End of Sale on June 1, 2018, and crossed its Last Day of Support (LDoS) on May 31, 2023. As of today it is an unsupported, unpatchable security device sitting in one of the most exposed positions on your network. This guide explains what each milestone actually means for an ASA5585-S20-K9 in production, why the exposure compounds the longer it stays racked, and how to migrate cleanly to the platform Cisco positions as its successor for this class of appliance: the Cisco Secure Firewall 3130 (Firepower 3130, PID FPR3130-NGFW-K9).

What the ASA 5585-X SSP-20 actually was

The ASA 5585-X was Cisco's high-end, chassis-based data-center firewall. Unlike the fixed 5500-X desktop and 1U models, it used a slot-based design: a Security Services Processor (SSP) blade carried the firewall data plane, and an optional second blade or software module added FirePOWER Services (NGIPS, AVC, URL filtering, and Advanced Malware Protection). The S20 is the second tier in that family. In round numbers it delivered roughly 7 Gbps of stateful (multiprotocol) firewall throughput, about 75,000 connections per second, up to 1 million concurrent connections, and on the order of 10,000 IPsec/AnyConnect VPN peers. The S20-K9 typically shipped with 8 copper Gigabit Ethernet ports plus 2 x 10GE SFP+ uplinks on the SSP. Crucially, when you turned on threat inspection, throughput fell hard: AVC alone ran near 7 Gbps, but AVC plus IPS together dropped to roughly 3.5 Gbps. That blade ran the ASA OS for the firewall and a separate FirePOWER/FTD image for inspection, with PAK-based, node-locked licenses (Security Plus, AnyConnect Plus/Apex, context and clustering licenses).

Why acting now matters

The trap with an end-of-life firewall is not that it stops passing traffic. It is that it keeps working flawlessly while the entire support floor disappears beneath it. After May 31, 2023, three concrete exposures stack on top of each other for the ASA5585-S20-K9:

  • No PSIRT security patches. When a new ASA, FirePOWER, or WebVPN/IKE vulnerability is disclosed, this hardware will not receive a fixed image. The ASA software family has a long history of critical, remotely exploitable CVEs in exactly the services a perimeter firewall exposes (SSL VPN, IKEv1/IKEv2, SNMP). Any new advisory affecting this code path on this hardware is permanent and unremediable.
  • No TAC or RMA. A failed SSP, power supply, or chassis cannot be opened as a support case or swapped under a service contract. Your only recovery is a cold spare you bought before LDoS or gray-market stock of the same dead-end model, neither of which is a defensible production posture.
  • Audit and compliance exposure. The frameworks federal, DoD, SLED, healthcare, and regulated enterprise buyers live under, including FedRAMP, CMMC, the HIPAA Security Rule, PCI DSS, and CISA directives, all expect supported, patchable infrastructure. An internet-facing firewall the vendor no longer patches is a finding waiting to happen, and 'no fix is available' is not an acceptable remediation plan for an assessor.

What each milestone means in practice

  • End of Sale (June 1, 2018): the last day Cisco accepted new orders for the 5585-X. Everything after this date was the platform consuming its support tail.
  • Last Day of Support (May 31, 2023): the hard cutoff. After this date Cisco provides no software fixes, no security patches, no TAC engineering, and no RMA, regardless of any SmartNet contract you may still be paying for. There is no extension or exception path.
  • The practical takeaway: a 5585-X running today is not 'almost out of support.' It has been fully unsupported for over three years. Every day it stays in line is accepted, unmanaged risk.

Cisco's named successor for this class of high-throughput, data-center-grade ASA is the Secure Firewall 3100 Series, and the 5585-X SSP-20 maps cleanly onto the Secure Firewall 3130 (FPR3130-NGFW-K9). This is a generational leap, not a like-for-like swap, and it collapses the old two-blade firewall-plus-FirePOWER architecture into a single, unified threat-defense appliance in 1U instead of 2U.

The hardware difference is dramatic. The 3130 is built on an AMD EPYC 7352 24-core 2.3 GHz CPU with 128 GB of RAM and a 900 GB SSD, versus the single-CPU, six-DIMM SSP-20 design. It delivers around 38 Gbps of firewall throughput and roughly 33 Gbps of IPsec VPN throughput, supports up to 6 million concurrent sessions, and up to 15,000 VPN peers, every one of those numbers a multiple of what the S20 could do. More importantly for a modern perimeter, the 3130 inspects encrypted traffic at scale: it runs the Snort 3 inspection engine and performs hardware-assisted TLS 1.3 decryption, so you can keep IPS and malware inspection on without watching throughput collapse the way it did on the 5585-X when you enabled AVC plus IPS.

Ports, optics, and licensing changes you must plan for

  • Interfaces: the 3130 ships with 8 x 10M/100M/1GBASE-T (RJ-45) and 8 x 1/10/25G SFP/SFP+/SFP28 fiber ports onboard, plus a network-module slot that accepts an 8x25G (FPR3K-XNM-8X25G), 4x40G (FPR3K-XNM-4X40G), or 2x40/100G QSFP28 (FPR3K-XNM-2X100G) module. Your old 5585-X 10GE SFP+ uplinks move forward natively, and you gain a clean path to 25G/40G/100G data-center fabrics the S20 could never reach.
  • Licensing model: this is the biggest operational change. The 5585-X used PAK-based, node-locked licenses. The Secure Firewall 3100 uses Cisco Smart Licensing with term subscriptions, a base layer plus add-ons for IPS, URL Filtering, and Malware Defense, with Cisco Secure Client (formerly AnyConnect) for remote access. Budget for subscription terms, not a one-time perpetual right, and stand up a Smart Account before cutover.
  • Management: FirePOWER on the 5585-X was managed through FireSIGHT/FMC. The 3130 is managed by Secure Firewall Management Center (on-prem FMC or cloud-delivered cdFMC) for centralized multi-device policy, or by the on-box Firewall Device Manager (FDM) for a single appliance. You can run it in ASA mode or, recommended for a perimeter refresh, in FTD (threat-defense) mode to consolidate firewall and NGIPS in one image.

A practical migration plan

A data-center firewall refresh is a change-managed project, not a forklift. The sequence below keeps policy intact and avoids an outage.

  • Assess and inventory: export the running ASA configuration (show running-config, show inventory, show version) and catalog every object, ACL, NAT rule, VPN tunnel, and AnyConnect profile. Note interface speeds, contexts, and any clustering or failover pairing, since high-end 5585-X deployments are frequently active/standby or clustered.
  • License transition: create or confirm a Smart Account, then size Essentials plus the threat and URL/malware subscriptions and Secure Client seats to match what the FirePOWER blade was licensed for. Order license terms alongside the hardware so nothing is stranded at activation.
  • Config and feature parity: use the Cisco Secure Firewall migration tool to convert the ASA configuration to FTD policy. Treat the output as a draft, then validate object groups, NAT, identity/VPN, and any inspection rules by hand. Map old FirePOWER policies to Snort 3 equivalents and confirm TLS decryption policy where you previously could not afford to decrypt.
  • Physical and fabric: the 3130 drops you from 2U to 1U, so reclaim rack space and confirm power (the 3130 takes dual AC or DC supplies) and front-to-back airflow against your hot/cold aisle. Reuse compatible 10GE SFP+ optics, and order 25G/40G/100G optics and network modules where you are upgrading uplinks.
  • Phased cutover: stage the 3130 in parallel, replicate policy, and cut over per security zone or per context during a maintenance window, ideally building an active/standby HA pair of 3130s so you retain redundancy through the transition. Keep the 5585-X powered but isolated as an immediate rollback until the new appliance is proven.
  • Secure decommission: once cut over, wipe the ASA and FirePOWER configurations (including keys, certificates, and credentials), record serials, and dispose of the chassis through a certified, auditable process. For federal and DoD environments, follow your media-sanitization standard before the hardware leaves the facility.

Procurement notes for regulated buyers

Source the Secure Firewall 3130 and its subscriptions through an authorized Cisco partner with documented country-of-origin so the hardware qualifies as TAA-compliant for federal, DoD, and SLED contract vehicles, and is eligible for Government Purchase Card and GSA-style purchasing. Avoid gray-market 5585-X stock entirely now that the platform is years past LDoS; secondary-market ASA hardware carries no support and may fail TAA scrutiny. Lead times on current NGFW hardware and the matching optics and network modules can stretch during budget cycles, so lock the bill of materials, including license terms and Smart Account details, well ahead of your refresh window. You can browse current Secure Firewall models in our catalog, see the full milestone record on the ASA5585-S20-K9 EoL page, or review other Cisco end-of-life platforms you may be carrying.

The ASA 5585-X SSP-20 was a capable data-center firewall in its day, but as of May 31, 2023 it is an unsupported, unpatchable device in the most exposed position on your network. Replacing it with a Secure Firewall 3130 buys you roughly five times the firewall throughput, line-rate Snort 3 threat inspection with TLS 1.3 decryption, a unified single-appliance architecture, and a clean compliance story. To scope the right model and license tier for your environment, get a sized, TAA-compliant refresh quote and we will map your existing ASA configuration to the replacement.

Frequently asked questions

When did the Cisco ASA 5585-X SSP-20 reach end of life?

The ASA 5585-X (PID ASA5585-S20-K9) reached End of Sale on June 1, 2018 and crossed its Last Day of Support (LDoS) on May 31, 2023. Since that date Cisco provides no software fixes, no PSIRT security patches, no TAC support, and no RMA hardware replacement for this platform, even if you still hold a SmartNet contract.

What is the recommended replacement for the ASA 5585-X SSP-20?

Cisco positions the Secure Firewall 3100 Series as the successor for this class of high-throughput data-center ASA, and the 5585-X SSP-20 maps cleanly onto the Secure Firewall 3130 (FPR3130-NGFW-K9). It consolidates the old firewall-plus-FirePOWER blade architecture into a single 1U threat-defense appliance with far higher throughput.

How much faster is the Secure Firewall 3130 than the ASA 5585-X SSP-20?

Substantially. The S20 delivered about 7 Gbps stateful firewall throughput, ~1 million concurrent connections, and roughly 3.5 Gbps once AVC and IPS were both enabled. The 3130 delivers around 38 Gbps firewall throughput, up to 6 million concurrent sessions, ~33 Gbps IPsec VPN, and runs Snort 3 with hardware TLS 1.3 decryption so threat inspection no longer collapses throughput.

Do my ASA and AnyConnect licenses transfer to the Secure Firewall 3130?

No. The 5585-X used PAK-based, node-locked licenses, while the Secure Firewall 3100 uses Cisco Smart Licensing with term subscriptions: a base tier plus IPS, URL Filtering, and Malware Defense add-ons, and Cisco Secure Client (formerly AnyConnect) for remote access. You must stand up a Smart Account and purchase new subscription terms sized to your deployment.

Can I migrate my existing ASA configuration to the Secure Firewall 3130?

Yes. Cisco's Secure Firewall migration tool converts an ASA running-config into FTD policy. Treat the output as a draft and validate object groups, ACLs, NAT, VPN, and identity rules by hand, then map old FirePOWER policies to Snort 3 equivalents. Staging the 3130 in parallel as an HA pair and cutting over per zone during a maintenance window preserves redundancy and gives you a rollback path.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote