Notifications
Clear all
Topic starter
29/07/2026 3:55 pm
We've been on ASA for years. Pushed to migrate to Firepower for VPN. I don't see the win.
With ASA, the config is straightforward. You know where everything is.
Firepower Management Center (FMC) feels like a layer of unnecessary abstraction for VPN. More clicks, slower changes. AnyConnect profiles are more complex to manage at scale.
* Is the centralized policy management actually better for VPN-specific rules?
* Any tangible security benefit, or just checkbox compliance?
* Does the telemetry/insights from FTD justify the operational overhead for this use case?
Looking for real-world experience, not sales sheets. If it's just "the future," I'll stay on ASA until EOL.
Ship it, but test it first