Cisco AnyConnect Alternative 2026: ASA Support Ends, the Migration Plan to NetBird
Cisco AnyConnect Alternative 2026: ASA Support Ends, the Migration Plan to NetBird
Cisco ASA support ends on 31 August 2026 and AnyConnect 4.x gets no patches. Migration plan to NetBird: WireGuard, Zero Trust, hosted in Germany.
Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.
On 31 August 2026, Cisco support for the ASA 5506-X, 5508-X and 5516-X ends for good: no patches, no TAC, and the signature release expires as well. The accompanying VPN client, AnyConnect 4.x, has already received no security fixes since 31 March 2024. Cisco's official successor, Secure Client 5.x, is available, but key features require ASA software that will never run on the end-of-life models: staying with Cisco effectively means new hardware plus a license migration for these devices. At the same time, the FIRESTARTER backdoor documented in April 2026 shows that compromised VPN appliances can survive even applied patches. This article delivers the complete EoL timeline, puts the security situation into sober context and lays out a migration plan that gets you there in four weeks without buying hardware: from AnyConnect to WireGuard-based Zero Trust networking with NetBird, run as a managed service hosted in Germany.
Quick Comparison: Cisco ASA/AnyConnect vs. NetBird
If you are facing the "new Cisco hardware or architecture change" decision, these are the two paths in essence:
| Criterion | Cisco path (Secure Firewall + Secure Client 5) | NetBird (birdhost) |
|---|---|---|
| Required investment | New appliance, licenses, migration project | Software rollout, from €99.90/month, no hardware |
| VPN architecture | Central gateway, publicly reachable VPN portal | WireGuard mesh, peer-to-peer, no public portal |
| AnyConnect replacement | Secure Client 5.x, full feature set only with newer ASA software | NetBird client, centrally deployable via MDM |
| Site-to-site | IPsec between appliances | Routing peers and networks in the overlay |
| Zero Trust | Add-on products (ISE, Duo, SSE) | Access policies, posture checks, SSO built in |
| Operations and patches | Own team or partner | Managed: backups, patches, updates, 24/7 monitoring |
| Firewall functions (NAT, IPS, inspection) | Included | Not included, remain separate |
| Data location and control | Depends on setup | Your own instance, Germany or 7 more regions |
| Open source | No | Yes (BSD-3-Clause, server components AGPL-3.0) |
The Deadline: What Ends on 31 August 2026
The ASA 5500-X series was for years the default firewall and VPN choice in small and midsize companies, which is why this date hits so many networks: on 31 August 2026, the ASA 5506-X (including 5506H-X and 5506W-X), 5508-X and 5516-X reach their Last Date of Support.[1][2] The complete timeline from the two Cisco end-of-life notices:
| Milestone | Date |
|---|---|
| End-of-sale (last day to order) | 2 August 2021 |
| Last ship date | 31 October 2021 |
| End of routine failure analysis | 2 August 2022 |
| End of new service attachment | 2 August 2022 |
| End of service contract renewal | 28 October 2025 |
| End of signature release | 31 August 2026 |
| Last Date of Support | 31 August 2026 |
What does Last Date of Support mean? It is the day from which Cisco ends all support for the product: no TAC support, no software fixes, no workarounds. From this date the device is considered obsolete.
Equally important for planning: the last software version for these models is ASA 9.16. The ASA 9.17 release notes explicitly drop support for the 5506-X, 5506H-X, 5506W-X, 5508-X and 5516-X from version 9.17(1).[3] There is no upgrade path to current software for this hardware, regardless of the support contract.
AnyConnect 4.x: No Security Patches Since March 2024
The second half of the problem sits on the endpoints. Cisco's AnyConnect 4.x end-of-life notice is unambiguous: after 31 March 2024 there are no more patches and no maintenance releases; formal support ends on 31 March 2027.[4] Anyone still running AnyConnect 4.x on one of these ASAs operates a combination in which neither client nor appliance receives security updates.
Cisco's migration path is Secure Client 5.x. The catch for owners of the EoL models: key features of the new client require ASA software that will never run on these devices. The Secure Client 5 release notes spell out the requirements:[5]
| Secure Client 5 feature | Minimum requirement | On 5506/5508/5516 (max. ASA 9.16) |
|---|---|---|
| SAML External Browser | ASA 9.17.x and ASDM 7.17.x | Not possible |
| TLS 1.3 | ASA 9.19(1) | Not possible |
| HostScan 4.x with Secure Client 5.0.x | Not supported | Not applicable |
"Just update the client" is therefore not a solution. For this hardware generation, staying in the Cisco ecosystem means a new Secure Firewall appliance plus license migration plus a project. That is a legitimate path for organizations deeply invested in the Cisco stack. If your ASA mainly served as a VPN dial-in point, the underlying architecture question is worth a look.
CVE-2025-20333, FIRESTARTER, FortiBleed: The Pattern Behind Appliance VPNs
The EoL deadline falls into a phase in which publicly reachable VPN appliances are under pressure across the industry. The events of the past twelve months, documented neutrally:
September 2025: Cisco publishes advisories for two ASA/FTD vulnerabilities. CVE-2025-20333 is a critical buffer overflow rated CVSS 9.9 that allows remote code execution with root privileges.[6] Cisco rates CVE-2025-20362 at CVSS 6.5; the NVD rates the same vulnerability at 8.6.[7] Both were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 25 September 2025.[6][7]
Emergency Directive ED 25-03 (25 September 2025): CISA required US federal agencies to identify all ASA and Firepower devices, submit memory images for forensics and, where compromise was detected, disconnect the devices immediately without powering them off.[8] An important scoping detail: the permanent disconnect order applied only to ASA models with end of support on or before 30 September 2025. For the 5506-X, 5508-X and 5516-X, supported until 31 August 2026, the order was to patch by 26 September 2025 and apply all subsequent updates within 48 hours.[8]
November 2025: In its updated implementation guidance, CISA reports that several organizations believed they had applied the necessary updates but had in fact not updated to the minimum software version.[9]
April 2026: On 23 April 2026, CISA and the UK's NCSC publish malware analysis report AR26-113A on the FIRESTARTER backdoor: a Linux ELF backdoor on Cisco Firepower and Secure Firewall devices (ASA/FTD) that hooks the LINA data plane, sits below the ASA software and survives reboots as well as firmware updates unless a hard power cycle occurs.[10] The attackers used FIRESTARTER in March 2026 to regain access without re-exploiting the original vulnerabilities and to redeploy the LINE VIPER malware on already patched devices; the report documents the compromise of a US federal agency that had patched in accordance with ED 25-03.[10] Eviction required a physical hard power cycle, meaning unplugging the power supply because a reboot is not sufficient, plus a Cisco patch released in April 2026 against this specific persistence mechanism, with a deadline of 30 April 2026.[8]
24 April 2026: Germany's BSI updates its cybersecurity warning "Cisco firewalls infected with persistent malware" to version 1.1, naming CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363 as well as the FIRESTARTER persistence.[11]
This is not a Cisco-specific problem. On 18 June 2026, Bitsight documented, under the name FortiBleed, more than 73,000 potentially affected internet-facing FortiGate firewalls, around 50 percent of all reachable devices across 194 countries: admin passwords remained stored as weak SHA-256 hashes after upgrades until the administrator logs in again, and attackers cracked them with a 45-GPU offline infrastructure.[12] The full analysis of that case, including immediate actions, is in FortiBleed: what the FortiGate leak reveals about SSL VPN appliances. We covered the history at other vendors in Fortinet VPN alternative 2026 and Sophos VPN alternative 2026.
Why Patching Alone Is No Longer Enough
The real pattern is architectural: a publicly reachable VPN portal on a proprietary appliance is a permanently exposed, rewarding target. FIRESTARTER shifts the debate further, because if a backdoor survives patches and reboots, "patch faster" no longer suffices as a strategy. The structural answer is to remove the attack surface rather than mend it ever faster. That is where a WireGuard overlay without a publicly listening portal comes in, a line of thought we also explore in OpenVPN alternative 2026.
The Alternative: WireGuard Mesh and Zero Trust with NetBird
NetBird is an open-source overlay network built on WireGuard. Instead of terminating all connections at a central gateway, devices connect directly peer-to-peer; a management plane consisting of management, signal and relay services handles authentication, key distribution and policies. Our guide setting up WireGuard in the enterprise explains the technical foundations.
Architecture: Peer-to-Peer Instead of a Public Portal
The decisive difference for the Cisco migration: there is no publicly reachable VPN portal left for attackers to grind against. Connections run directly between peers; a relay steps in only when no direct connection is possible. This removes exactly the attack surface exploited in the documented appliance campaigns of 2025 and 2026. That is an architecture statement, not a security superlative: a mesh network also needs to be configured cleanly, monitored and kept up to date.
Zero Trust Building Blocks: Policies, Posture Checks, SSO
What required add-on products with the ASA comes with NetBird as a platform feature: group-based access policies, SSO integration with your identity provider, and posture checks that tie access to conditions. Checks can cover the NetBird client version, country and region, peer network range (IPv4 and IPv6), operating system or kernel version, and running processes, for example an EDR agent.[15]
The client does not have to hide behind AnyConnect for enterprise rollout either: NetBird officially documents Intune deployment,[16] and since version 0.73.0 from 18 June 2026 the client supports MDM configuration profiles via the Windows Registry and macOS plist.[13] The development pace is also notable: four releases shipped in July 2026 alone, with v0.76.1 from 31 July 2026 being current.[13] That is the contrast to a client that has received no updates since March 2024. License-wise, NetBird is open source under BSD-3-Clause; the server directories management/, signal/, relay/ and combined/ are licensed under AGPL-3.0.[14]
Honest Scoping: What NetBird Replaces and What It Does Not
NetBird replaces the ASA's VPN functions: remote access for employees and site-to-site coupling via routing peers and networks. It does not replace the firewall functions: NAT, IDS/IPS, traffic inspection and web filtering remain a separate task. If you use your ASA primarily as a next-generation firewall, you are planning a firewall replacement, not a VPN replacement. And if regulations require certified IPsec gateways in special environments, evaluate that separately. For everyone else: the future firewall no longer has to expose a VPN portal and can be correspondingly simpler and cheaper.
Migration Plan: From AnyConnect to NetBird in Four Weeks
Four weeks until the deadline are not enough for a hardware procurement project, but they are enough for an orderly architecture change. A proven sequence:
- Week 1, inventory: Record what the ASA actually does today: who dials in via AnyConnect, which sites are coupled via site-to-site, which firewall functions (NAT, IPS, filtering) must stay? This list separates the VPN replacement from the firewall topic.
- Week 1, instance and identity: Create the birdhost instance and connect your identities. The Startup plan includes an integrated identity provider (Dex); on the Business plan you connect your own IdP via OIDC/SAML for SSO.
- Week 2, pilot group in parallel with AnyConnect: Distribute the NetBird client via Intune or another MDM to a pilot group.[16] Both clients coexist on the same device, with AnyConnect as fallback. Rebuild your access rules as group-based policies and enable posture checks.
- Week 3, site-to-site: Replace the ASA's IPsec site couplings with routing peers and networks in the overlay. How this works without MPLS-style constructs is shown in connecting sites without MPLS.
- Week 4, cutover: Switch the remaining users, uninstall AnyConnect via MDM and disable the ASA's VPN portal. If the ASA temporarily stays on as a pure firewall, it is no longer reachable from the internet; its EoL status remains a reason to plan its replacement.
For regulated companies, the timing also matters from a compliance perspective: a VPN without vendor patches is hard to defend in NIS2 risk management, see NIS2 and VPN: network security requirements for details. This article is not legal advice; involve your data protection or legal counsel for specific questions.
Decision Matrix: New Cisco Hardware or Architecture Change?
The Cisco path (Secure Firewall plus Secure Client 5) fits if:
- you are deeply invested in the Cisco stack (ISE, Umbrella, Duo) and have certified Cisco expertise in house,
- the appliance is primarily needed as an NGFW and VPN is only a secondary function,
- your procurement policies require a vendor support contract for every component.
The architecture change to NetBird with birdhost fits if:
- the ASA mainly served as a VPN dial-in point for home office and field staff and for site coupling,
- neither budget nor staff for an appliance project is available before the deadline,
- you want Zero Trust capabilities such as posture checks, SSO and granular policies without add-on licenses,
- data sovereignty matters: control plane and data in Germany instead of with a US provider.
The last point deserves honest context, because NetBird is not the only modern alternative. Tailscale runs its own comparison page against the Cisco Secure Client, a clear signal of how contested the AnyConnect switchers are.[17] Tailscale and Twingate, however, are US SaaS offerings with the well-known CLOUD Act questions we analyze in GDPR-compliant VPN: the US cloud compliance risk. The detailed comparisons: NetBird vs. Tailscale and Twingate alternative 2026.
Managed NetBird from Germany: birdhost
As managed NetBird hosting from Germany, birdhost runs your own NetBird instance: backups, patches, updates and 24/7 monitoring included, which is exactly the operational coverage that disappeared with the EoL device. Hosting is available in Germany in ISO 27001 and BSI C5 certified data centers (certification held by the data center operator), a DPA is available, and 8 regions are on offer in total: Germany, the Netherlands, the USA, Canada, Singapore, Japan, Australia and India.
Pricing is based on the support tier. In Germany, Essential costs EUR 99.90 per month, Business EUR 199.90, Priority EUR 249.90 and Enterprise EUR 449.90, all net. Users and devices are not limited by count. Business responds within 4 hours and Priority within 1 hour, both daily from 07:00 to 18:00 CET/CEST. Enterprise responds within 60 minutes around the clock. Germany includes 20 TB of traffic, while the other seven regions include 4 TB. The trial runs for seven days, requires a credit card and then automatically converts to the selected paid subscription.
Transparency: birdhost is not an official NetBird product and is not affiliated with NetBird GmbH. Cisco, ASA, AnyConnect and Secure Client are trademarks of their respective owners.
Conclusion: Four Weeks Are Enough for the Start, Not for a Hardware Project
31 August 2026 is not the end of the world, but it is a hard date: after it, you operate a firewall and a VPN client without any vendor support, in a threat landscape where appliance backdoors demonstrably survive patches. Staying with Cisco is legitimate, but it is a hardware project with procurement, licenses and migration effort. The architecture change to NetBird is feasible in four weeks: create the instance, run a pilot group in parallel with AnyConnect, couple sites via routing peers, cut over. The public VPN portal disappears entirely, and operations sit with a managed service in Germany. Start with the inventory; the rest is craftsmanship.
Sources
- [[1]] Cisco: End-of-Sale and End-of-Life Announcement ASA 5506 series (c51-744797)
- [[2]] Cisco: End-of-Sale and End-of-Life Announcement ASA 5508-X/5516-X (c51-744798)
- [[3]] Cisco: Release Notes for the ASA Series 9.17(x) (no support for 5506-X/5508-X/5516-X from 9.17(1))
- [[4]] Cisco: End-of-Life Announcement AnyConnect Secure Mobility Client 4.x
- [[5]] Cisco: Release Notes for Cisco Secure Client 5.0 (SAML External Browser, TLS 1.3, HostScan)
- [[6]] NVD: CVE-2025-20333 (CVSS 9.9, KEV since 25 September 2025)
- [[7]] NVD: CVE-2025-20362 (Cisco CVSS 6.5, NVD 8.6, KEV since 25 September 2025)
- [[8]] CISA: Emergency Directive ED 25-03 incl. update from 23 April 2026 (hard power cycle, persistence patch)
- [[9]] CISA: Update Implementation Guidance for ED 25-03 (12 November 2025)
- [[10]] CISA/NCSC: Malware Analysis Report AR26-113A, FIRESTARTER backdoor (23 April 2026)
- [[11]] BSI: Cybersecurity warning version 1.1 "Cisco firewalls infected with persistent malware" (24 April 2026)
- [[12]] Bitsight: Security Alert FortiBleed (18 June 2026)
- [[13]] NetBird GitHub Releases (v0.73.0 from 18 June 2026, v0.76.1 from 31 July 2026)
- [[14]] NetBird LICENSE (BSD-3-Clause, AGPL-3.0 for management/, signal/, relay/, combined/)
- [[15]] NetBird Docs: Posture Checks
- [[16]] NetBird Docs: Intune deployment
- [[17]] Tailscale: compare page vs. Cisco Secure Client
Frequently Asked Questions
What happens to my Cisco ASA 5506-X, 5508-X or 5516-X after 31 August 2026?▼
Can I keep using AnyConnect 4.x after the end of support?▼
What distinguishes a WireGuard mesh like NetBird from a classic VPN gateway?▼
Why are CISA and the BSI warning about Cisco ASA firewalls?▼
Does NetBird completely replace my Cisco ASA firewall?▼
Can I run NetBird in parallel with AnyConnect?▼
How do I roll out the NetBird client across the company?▼
Is NetBird really open source?▼
What does birdhost cost compared to buying new Cisco hardware?▼
How fast can I still migrate before the deadline?▼
Written by
Timo Wevelsiep
Founder, merkaio
Founder of merkaio. Managed NetBird VPN hosting. Focused on network security, zero-trust architecture and scalable VPN infrastructure.
LinkedIn