Cisco ASA End of Life: Which Models Die August 31, 2026 (And What Replaces Them)

Four Cisco ASA models lose all support on 2026-08-31. Which ones, what replaces them, and what to do if you can't migrate before the date.
200+
Engineers Certified
50+
Lab Scenarios
4.9★
Average Rating
8min
Read Time
Network cables connected to a Cisco switch or router port.
Four Cisco ASA models lose all support on 2026-08-31. Which ones, what replaces them, and what to do if you can't migrate before the date.

Four Cisco ASA models stopped getting security patches on 2026-08-31.

Not end of sale. Not “reduced support.” The actual last day of support for the ASA 5506-X, 5508-X, 5515-X and 5516-X is 2026-08-31, and after that date a vulnerability found in your firewall stays open forever. No TAC case, no patch, no signature update.

You’ve probably known this was coming. Cisco announced it years ago and it’s been sitting in a spreadsheet somewhere. The thing is, a lot of teams only found out the date had already passed by reading something like this.

Here’s what this covers: exactly which models lost support and when, which ones died years ago, what Cisco says replaces each one, how the migration actually goes, and what to do if you’re reading this after the deadline and still haven’t moved.

Everything below was checked on 2026-08-17.

The short answer: four models, one date

ModelLast day of supportStatus
ASA 5506-X2026-08-31Support ended
ASA 5508-X2025-09-30Support ended
ASA 5515-X2026-08-31Support ended
ASA 5516-X2026-08-31Support ended
ASA 5512-X2022-08-31Already dead
ASA 5525-X2025-09-30Already dead
ASA 5545-X2023-05-31Already dead
ASA 5555-X2023-05-31Already dead
ASA 5585-X2025-09-30Already dead

Look at the bottom half of that table. If you’re running a 5525-X or a 5555-X, you haven’t been getting patches for over three years. That’s the more common situation than people admit.

Paper-craft diorama of ASA appliance boxes, three tipped over tagged DEAD, two standing with an AUG 31 flag
Three models already dead, two more joining them on August 31

After 2026-08-31, none of the nine main ASA 5500-X models are supported. Source: Cisco EOL notices, collated by EOSL.date.

The 5506-X is the one that matters most by volume. It was the cheap desktop model that went into thousands of branch offices, dental practices and small manufacturing sites, and a lot of them were installed by someone who’s since left the company.

What “end of life” actually means here

Cisco uses three terms and they get mixed up constantly.

End of sale is when you can’t buy it anymore. For the 5508-X and 5516-X that was 2021-08-02. Long gone.

End of software maintenance is when bug fixes stop. Feature work already ended before that.

Last day of support is the one that matters. It’s the final date Cisco will do anything at all: no security patches, no TAC, no RMA, no signature releases. For these four models that’s 2026-08-31, per Cisco’s own EOL notice.

Think of it like a car manufacturer discontinuing parts. The car still drives on September 1st. But the day something breaks, nobody’s making the replacement piece.

One more thing that trips people up. The hardware EOL is separate from the software EOL. ASA software releases have their own dates, and 9.18 and 9.19 run to 2027-11-30. So you might read “supported until 2027” somewhere and think you’re fine. You’re not, if the box underneath is a 5506-X.

Why this one is worse than a normal EOL

Most end-of-life dates are a budgeting problem. This one is a security problem, and the difference is timing.

Cisco ASA has been under active attack. CVE-2026-20349, rated 8.6, is being exploited in the wild right now and CISA added it to the Known Exploited Vulnerabilities catalogue with a federal remediation deadline of 2026-08-14. That deadline was over a month ago.

Then there’s ArcaneDoor. That’s the campaign that’s been targeting ASA and FTD devices since 2024, and the part that should worry you is the persistence. The group built a mechanism that survives upgrading to fixed releases. A bootkit in ROM, so reflashing doesn’t clear it.

Put those two facts next to each other. Attackers have been actively hunting these boxes, and these four models stopped receiving the patches that would have closed the next hole.

Paper-craft diorama of a single ASA appliance box alone with an EXPOSED tag
An unsupported firewall with no one watching the door

Around 113K ASA devices face the public internet, and close to half expose a login panel. Source: Eclypsium.

Both the US and UK cyber agencies have told organisations to replace end-of-life security appliances rather than keep running them. Not “plan to replace.” Replace.

Here’s the uncomfortable version. A firewall that can’t be patched isn’t a firewall. It’s a device with a public IP and a permanent open door, sitting exactly where you put your most trusted boundary.

Want to understand why these boxes get owned? Our CCIE Security Workbook covers hardening and ASA configuration with labs you run yourself, so the concepts stick past exam day.

What replaces each ASA model

Cisco’s mapping is the Firepower 1000 Series for the small models. Rough equivalents:

If you haveCisco’s replacementNotes
ASA 5506-XFirepower 1010Desktop, built-in switch ports, same footprint
ASA 5508-XFirepower 11201RU
ASA 5516-XFirepower 11401RU, more throughput
ASA 5525-XFirepower 1150 or Secure Firewall 3105Depends on throughput needs
ASA 5555-XFirepower 1150 / FPR 3100 series

The 1010 is the direct swap for a 5506-X. Desktop form factor, integrated switch, aimed at exactly the small-site deployments the 5506-X owned.

Paper-craft diorama of an ASA box next to a Firepower box with a rising arrow tagged 360 percent
The replacement is not a sidegrade

The replacement is not a sidegrade. Source: Cisco ASA 5500-X and Firepower 1000 Series datasheets.

Paper-craft diorama of a thin cable tagged 175 beside a thick cable tagged 1200
The old box carries a fifth of the VPN load

VPN capacity is where the gap is widest. Source: Cisco ASA 5500-X and Firepower 1000 Series datasheets.

But there’s a decision hiding in this table that nobody flags clearly enough.

ASA software or FTD? Pick before you buy

The Firepower 1000 boxes run either ASA software or Firepower Threat Defense. Two different operating systems on the same hardware.

Running ASA software on new hardware means your config mostly carries over, your team keeps working the way they always have, and the migration is short. It also means you’re extending a platform Cisco is clearly winding down.

Running FTD means learning a new management model, rebuilding policy, and probably a longer project. It’s where Cisco is putting its effort.

Say you’re a two-person IT team at a 60-person company with one firewall and no change window until December. Load ASA software, buy yourself the runway, and plan FTD properly next year. Say you’re a managed service provider with 40 of these across clients. Bite the bullet on FTD now, because doing this twice costs more than doing it once slowly.

Your call. Just make it deliberately instead of discovering it during the cutover.

How the migration actually goes

Cisco ships a Secure Firewall Migration Tool that converts ASA configs to Threat Defense. It supports every 5500-X model from the 5506-X up to the 5585-X.

It handles the mechanical parts well: interfaces, objects, NAT rules, access lists. It gives you a pre-migration report so you can see what won’t convert before you commit.

What it doesn’t do is think for you.

The rules it can’t translate cleanly are usually the ones that matter. Anything relying on ASA-specific inspection behaviour. VPN configs with unusual crypto. That one access list somebody hand-wrote in 2017 with a comment that says “do not remove, ask Dave.” Dave left.

A realistic sequence:

  1. Inventory first. show version on every ASA you can reach. You will find at least one you’d forgotten about. This is the step people skip and it’s the step that saves the project.
  2. Export configs and run the pre-migration report. Before you order hardware, so throughput sizing is based on real rule counts.
  3. Order with lead time in mind.This is the part that made the original deadline so tight, and if you’re migrating now, past the deadline, lead time still decides your timeline.
  4. Build and test in a lab. Not on the production box at 2am.
  5. Cut over with the old unit still racked. Powered off, cabled, ready to bring back.
  6. Watch for a week. The failures show up in the traffic nobody thought about, printing, a site-to-site tunnel that only runs monthly, a vendor VPN.

Step 4 is where most of the risk gets removed, and it’s the step that gets cut when the date is close. You can build the whole topology in an emulator and test the converted policy before hardware arrives. Our guide on home lab setup for network engineers covers the build, and the emulator comparison helps you pick which one runs ASAv and FTDv comfortably.

You didn’t migrate before the deadline. Now what?

Realistically, if you’re reading this after 2026-08-31, you didn’t rack new firewalls before the deadline. Hardware lead times alone ruled that out for most teams.

So here’s the honest fallback. None of this makes the device supported. All of it reduces how exposed you are while you fix the real problem.

Confirm you’re running Cisco’s last release for this hardware. The well is dry now, nothing new is coming for these models. If you’re not certain you have everything Cisco shipped before 2026-08-31 installed, check today, it’s the highest-value thing left to do.

Kill remote management on the outside interface. No SSH, no ASDM, no HTTPS management from the internet. Management goes through a jump host or a VPN, full stop. Most of the exploitation activity targets exactly these services.

Turn off WebVPN if you’re not using it. The clientless SSL VPN portal has been the entry point in multiple ASA campaigns. If nobody’s using it, it shouldn’t be listening.

Check whether you’re already compromised. CISA’s ED 25-03 has the detection guidance. Given that ArcaneDoor persists through upgrades, “we patched it” isn’t the same as “we’re clean.”

Write down the date you’re actually migrating. With a name against it. An unsupported firewall with no migration date becomes a permanent unsupported firewalland every week past 2026-08-31 makes that more true, not less.

Anyway.Mitigation is a bridge, not a destination, and the longer you’re still on this hardware, the shakier that bridge gets.

Is Cisco ASA obsolete?

The hardware line is being retired, yes. ASA software still gets releases and 9.18/9.19 run to 2027-11-30, but the 5500-X appliances are ending model by model. New deployments go to Secure Firewall, not ASA.

What is replacing Cisco ASA?

Cisco Secure Firewall, previously called Firepower. Firepower 1000 Series for small sites, 3100 and 4200 Series as you scale up. The software side moves from ASA to Firepower Threat Defense.

What if my ASA still has an active support contract past August 31?

The contract doesn’t extend the product’s last day of support. After 2026-08-31 there’s nothing left to deliver on these four models.

Can I keep running it if it’s behind another firewall?

You can, and it’s better than nothing. But you’ve now got an unpatchable device inside your perimeter, which is a different risk rather than no risk. Treat it as temporary.

Which ASA models are still supported?

None of the 5500-X hardware line after 2026-08-31. The 5512-X went in 2022, the 5525-X through 5585-X went in 2023, and these last four go this month. Adding a firewall to the picture? Start with what FortiGate is and how an NGFW works.

Bottom line

Four models, one date, already passed. The 5506-X, 5508-X, 5515-X and 5516-X all lost support on 2026-08-31.

What to do this week, in order: inventory every ASA you own, confirm you’re on Cisco’s last available release, pull management off the outside interface, and put a real date and a real name against the migration.

The Firepower 1010, 1120 and 1140 are the direct replacements. Decide whether you’re loading ASA software or going to FTD before you order, not during the cutover.

And if you want to practise the migration before you do it for real, that’s what a lab is for. The CCIE Security Workbook covers both sides of the move, from ASA to Firepower Threat Defence clustering, with topologies that run in EVE-NG. To get the reps in before you touch production, the FortiGate NSE4 Lab Workbook runs the scenarios in EVE-NG.

Migrations like this are the reason the certification matters. The people who handle them calmly are the ones who’ve built it before, in a lab, where breaking things costs nothing.

Keep Reading

Related Articles

Ethernet ports and cables on the back of a router, with SMEnode Labs cyan fading in from the bottom-left corner.

EVE-NG Download Guide 2026: Community, Freemium and Pro ISO Explained

EVE-NG v7.2.0-4 is one 10 GB ISO. The free Freemium mode caps labs at 7 nodes, Pro costs 150 EUR, and Community is EOL. Here's which file to download now.
Network switch ports with VLAN tagging labels for network segmentation.

What Is a VLAN? Types, Tagging and Config Examples

A VLAN splits one physical switch into separate networks. Learn VLAN types, 802.1Q tagging, native VLAN and the Cisco commands, with a lab you can boot.

Share Your Valuable Opinions