Back to Blog|VPN Guides

Cisco AnyConnect Alternative 2026: ASA Support Ends, the Migration Plan to NetBird

August 1, 2026
Timo WevelsiepTimo Wevelsiep
birdhost

Cisco AnyConnect Alternative 2026: ASA Support Ends, the Migration Plan to NetBird

Cisco ASA support ends on 31 August 2026 and AnyConnect 4.x gets no patches. Migration plan to NetBird: WireGuard, Zero Trust, hosted in Germany.

birdhost.de Blog

Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.

On 31 August 2026, Cisco support for the ASA 5506-X, 5508-X and 5516-X ends for good: no patches, no TAC, and the signature release expires as well. The accompanying VPN client, AnyConnect 4.x, has already received no security fixes since 31 March 2024. Cisco's official successor, Secure Client 5.x, is available, but key features require ASA software that will never run on the end-of-life models: staying with Cisco effectively means new hardware plus a license migration for these devices. At the same time, the FIRESTARTER backdoor documented in April 2026 shows that compromised VPN appliances can survive even applied patches. This article delivers the complete EoL timeline, puts the security situation into sober context and lays out a migration plan that gets you there in four weeks without buying hardware: from AnyConnect to WireGuard-based Zero Trust networking with NetBird, run as a managed service hosted in Germany.

Quick Comparison: Cisco ASA/AnyConnect vs. NetBird

If you are facing the "new Cisco hardware or architecture change" decision, these are the two paths in essence:

Criterion Cisco path (Secure Firewall + Secure Client 5) NetBird (birdhost)
Required investment New appliance, licenses, migration project Software rollout, from €99.90/month, no hardware
VPN architecture Central gateway, publicly reachable VPN portal WireGuard mesh, peer-to-peer, no public portal
AnyConnect replacement Secure Client 5.x, full feature set only with newer ASA software NetBird client, centrally deployable via MDM
Site-to-site IPsec between appliances Routing peers and networks in the overlay
Zero Trust Add-on products (ISE, Duo, SSE) Access policies, posture checks, SSO built in
Operations and patches Own team or partner Managed: backups, patches, updates, 24/7 monitoring
Firewall functions (NAT, IPS, inspection) Included Not included, remain separate
Data location and control Depends on setup Your own instance, Germany or 7 more regions
Open source No Yes (BSD-3-Clause, server components AGPL-3.0)

The Deadline: What Ends on 31 August 2026

The ASA 5500-X series was for years the default firewall and VPN choice in small and midsize companies, which is why this date hits so many networks: on 31 August 2026, the ASA 5506-X (including 5506H-X and 5506W-X), 5508-X and 5516-X reach their Last Date of Support.[1][2] The complete timeline from the two Cisco end-of-life notices:

Milestone Date
End-of-sale (last day to order) 2 August 2021
Last ship date 31 October 2021
End of routine failure analysis 2 August 2022
End of new service attachment 2 August 2022
End of service contract renewal 28 October 2025
End of signature release 31 August 2026
Last Date of Support 31 August 2026

What does Last Date of Support mean? It is the day from which Cisco ends all support for the product: no TAC support, no software fixes, no workarounds. From this date the device is considered obsolete.

Equally important for planning: the last software version for these models is ASA 9.16. The ASA 9.17 release notes explicitly drop support for the 5506-X, 5506H-X, 5506W-X, 5508-X and 5516-X from version 9.17(1).[3] There is no upgrade path to current software for this hardware, regardless of the support contract.

AnyConnect 4.x: No Security Patches Since March 2024

The second half of the problem sits on the endpoints. Cisco's AnyConnect 4.x end-of-life notice is unambiguous: after 31 March 2024 there are no more patches and no maintenance releases; formal support ends on 31 March 2027.[4] Anyone still running AnyConnect 4.x on one of these ASAs operates a combination in which neither client nor appliance receives security updates.

Cisco's migration path is Secure Client 5.x. The catch for owners of the EoL models: key features of the new client require ASA software that will never run on these devices. The Secure Client 5 release notes spell out the requirements:[5]

Secure Client 5 feature Minimum requirement On 5506/5508/5516 (max. ASA 9.16)
SAML External Browser ASA 9.17.x and ASDM 7.17.x Not possible
TLS 1.3 ASA 9.19(1) Not possible
HostScan 4.x with Secure Client 5.0.x Not supported Not applicable

"Just update the client" is therefore not a solution. For this hardware generation, staying in the Cisco ecosystem means a new Secure Firewall appliance plus license migration plus a project. That is a legitimate path for organizations deeply invested in the Cisco stack. If your ASA mainly served as a VPN dial-in point, the underlying architecture question is worth a look.

CVE-2025-20333, FIRESTARTER, FortiBleed: The Pattern Behind Appliance VPNs

The EoL deadline falls into a phase in which publicly reachable VPN appliances are under pressure across the industry. The events of the past twelve months, documented neutrally:

September 2025: Cisco publishes advisories for two ASA/FTD vulnerabilities. CVE-2025-20333 is a critical buffer overflow rated CVSS 9.9 that allows remote code execution with root privileges.[6] Cisco rates CVE-2025-20362 at CVSS 6.5; the NVD rates the same vulnerability at 8.6.[7] Both were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 25 September 2025.[6][7]

Emergency Directive ED 25-03 (25 September 2025): CISA required US federal agencies to identify all ASA and Firepower devices, submit memory images for forensics and, where compromise was detected, disconnect the devices immediately without powering them off.[8] An important scoping detail: the permanent disconnect order applied only to ASA models with end of support on or before 30 September 2025. For the 5506-X, 5508-X and 5516-X, supported until 31 August 2026, the order was to patch by 26 September 2025 and apply all subsequent updates within 48 hours.[8]

November 2025: In its updated implementation guidance, CISA reports that several organizations believed they had applied the necessary updates but had in fact not updated to the minimum software version.[9]

April 2026: On 23 April 2026, CISA and the UK's NCSC publish malware analysis report AR26-113A on the FIRESTARTER backdoor: a Linux ELF backdoor on Cisco Firepower and Secure Firewall devices (ASA/FTD) that hooks the LINA data plane, sits below the ASA software and survives reboots as well as firmware updates unless a hard power cycle occurs.[10] The attackers used FIRESTARTER in March 2026 to regain access without re-exploiting the original vulnerabilities and to redeploy the LINE VIPER malware on already patched devices; the report documents the compromise of a US federal agency that had patched in accordance with ED 25-03.[10] Eviction required a physical hard power cycle, meaning unplugging the power supply because a reboot is not sufficient, plus a Cisco patch released in April 2026 against this specific persistence mechanism, with a deadline of 30 April 2026.[8]

24 April 2026: Germany's BSI updates its cybersecurity warning "Cisco firewalls infected with persistent malware" to version 1.1, naming CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363 as well as the FIRESTARTER persistence.[11]

This is not a Cisco-specific problem. On 18 June 2026, Bitsight documented, under the name FortiBleed, more than 73,000 potentially affected internet-facing FortiGate firewalls, around 50 percent of all reachable devices across 194 countries: admin passwords remained stored as weak SHA-256 hashes after upgrades until the administrator logs in again, and attackers cracked them with a 45-GPU offline infrastructure.[12] The full analysis of that case, including immediate actions, is in FortiBleed: what the FortiGate leak reveals about SSL VPN appliances. We covered the history at other vendors in Fortinet VPN alternative 2026 and Sophos VPN alternative 2026.

Why Patching Alone Is No Longer Enough

The real pattern is architectural: a publicly reachable VPN portal on a proprietary appliance is a permanently exposed, rewarding target. FIRESTARTER shifts the debate further, because if a backdoor survives patches and reboots, "patch faster" no longer suffices as a strategy. The structural answer is to remove the attack surface rather than mend it ever faster. That is where a WireGuard overlay without a publicly listening portal comes in, a line of thought we also explore in OpenVPN alternative 2026.

The Alternative: WireGuard Mesh and Zero Trust with NetBird

NetBird is an open-source overlay network built on WireGuard. Instead of terminating all connections at a central gateway, devices connect directly peer-to-peer; a management plane consisting of management, signal and relay services handles authentication, key distribution and policies. Our guide setting up WireGuard in the enterprise explains the technical foundations.

Architecture: Peer-to-Peer Instead of a Public Portal

The decisive difference for the Cisco migration: there is no publicly reachable VPN portal left for attackers to grind against. Connections run directly between peers; a relay steps in only when no direct connection is possible. This removes exactly the attack surface exploited in the documented appliance campaigns of 2025 and 2026. That is an architecture statement, not a security superlative: a mesh network also needs to be configured cleanly, monitored and kept up to date.

Zero Trust Building Blocks: Policies, Posture Checks, SSO

What required add-on products with the ASA comes with NetBird as a platform feature: group-based access policies, SSO integration with your identity provider, and posture checks that tie access to conditions. Checks can cover the NetBird client version, country and region, peer network range (IPv4 and IPv6), operating system or kernel version, and running processes, for example an EDR agent.[15]

The client does not have to hide behind AnyConnect for enterprise rollout either: NetBird officially documents Intune deployment,[16] and since version 0.73.0 from 18 June 2026 the client supports MDM configuration profiles via the Windows Registry and macOS plist.[13] The development pace is also notable: four releases shipped in July 2026 alone, with v0.76.1 from 31 July 2026 being current.[13] That is the contrast to a client that has received no updates since March 2024. License-wise, NetBird is open source under BSD-3-Clause; the server directories management/, signal/, relay/ and combined/ are licensed under AGPL-3.0.[14]

Honest Scoping: What NetBird Replaces and What It Does Not

NetBird replaces the ASA's VPN functions: remote access for employees and site-to-site coupling via routing peers and networks. It does not replace the firewall functions: NAT, IDS/IPS, traffic inspection and web filtering remain a separate task. If you use your ASA primarily as a next-generation firewall, you are planning a firewall replacement, not a VPN replacement. And if regulations require certified IPsec gateways in special environments, evaluate that separately. For everyone else: the future firewall no longer has to expose a VPN portal and can be correspondingly simpler and cheaper.

Migration Plan: From AnyConnect to NetBird in Four Weeks

Four weeks until the deadline are not enough for a hardware procurement project, but they are enough for an orderly architecture change. A proven sequence:

  1. Week 1, inventory: Record what the ASA actually does today: who dials in via AnyConnect, which sites are coupled via site-to-site, which firewall functions (NAT, IPS, filtering) must stay? This list separates the VPN replacement from the firewall topic.
  2. Week 1, instance and identity: Create the birdhost instance and connect your identities. The Startup plan includes an integrated identity provider (Dex); on the Business plan you connect your own IdP via OIDC/SAML for SSO.
  3. Week 2, pilot group in parallel with AnyConnect: Distribute the NetBird client via Intune or another MDM to a pilot group.[16] Both clients coexist on the same device, with AnyConnect as fallback. Rebuild your access rules as group-based policies and enable posture checks.
  4. Week 3, site-to-site: Replace the ASA's IPsec site couplings with routing peers and networks in the overlay. How this works without MPLS-style constructs is shown in connecting sites without MPLS.
  5. Week 4, cutover: Switch the remaining users, uninstall AnyConnect via MDM and disable the ASA's VPN portal. If the ASA temporarily stays on as a pure firewall, it is no longer reachable from the internet; its EoL status remains a reason to plan its replacement.

For regulated companies, the timing also matters from a compliance perspective: a VPN without vendor patches is hard to defend in NIS2 risk management, see NIS2 and VPN: network security requirements for details. This article is not legal advice; involve your data protection or legal counsel for specific questions.

Decision Matrix: New Cisco Hardware or Architecture Change?

The Cisco path (Secure Firewall plus Secure Client 5) fits if:

  • you are deeply invested in the Cisco stack (ISE, Umbrella, Duo) and have certified Cisco expertise in house,
  • the appliance is primarily needed as an NGFW and VPN is only a secondary function,
  • your procurement policies require a vendor support contract for every component.

The architecture change to NetBird with birdhost fits if:

  • the ASA mainly served as a VPN dial-in point for home office and field staff and for site coupling,
  • neither budget nor staff for an appliance project is available before the deadline,
  • you want Zero Trust capabilities such as posture checks, SSO and granular policies without add-on licenses,
  • data sovereignty matters: control plane and data in Germany instead of with a US provider.

The last point deserves honest context, because NetBird is not the only modern alternative. Tailscale runs its own comparison page against the Cisco Secure Client, a clear signal of how contested the AnyConnect switchers are.[17] Tailscale and Twingate, however, are US SaaS offerings with the well-known CLOUD Act questions we analyze in GDPR-compliant VPN: the US cloud compliance risk. The detailed comparisons: NetBird vs. Tailscale and Twingate alternative 2026.

Managed NetBird from Germany: birdhost

As managed NetBird hosting from Germany, birdhost runs your own NetBird instance: backups, patches, updates and 24/7 monitoring included, which is exactly the operational coverage that disappeared with the EoL device. Hosting is available in Germany in ISO 27001 and BSI C5 certified data centers (certification held by the data center operator), a DPA is available, and 8 regions are on offer in total: Germany, the Netherlands, the USA, Canada, Singapore, Japan, Australia and India.

Pricing is based on the support tier. In Germany, Essential costs EUR 99.90 per month, Business EUR 199.90, Priority EUR 249.90 and Enterprise EUR 449.90, all net. Users and devices are not limited by count. Business responds within 4 hours and Priority within 1 hour, both daily from 07:00 to 18:00 CET/CEST. Enterprise responds within 60 minutes around the clock. Germany includes 20 TB of traffic, while the other seven regions include 4 TB. The trial runs for seven days, requires a credit card and then automatically converts to the selected paid subscription.

Transparency: birdhost is not an official NetBird product and is not affiliated with NetBird GmbH. Cisco, ASA, AnyConnect and Secure Client are trademarks of their respective owners.

Conclusion: Four Weeks Are Enough for the Start, Not for a Hardware Project

31 August 2026 is not the end of the world, but it is a hard date: after it, you operate a firewall and a VPN client without any vendor support, in a threat landscape where appliance backdoors demonstrably survive patches. Staying with Cisco is legitimate, but it is a hardware project with procurement, licenses and migration effort. The architecture change to NetBird is feasible in four weeks: create the instance, run a pilot group in parallel with AnyConnect, couple sites via routing peers, cut over. The public VPN portal disappears entirely, and operations sit with a managed service in Germany. Start with the inventory; the rest is craftsmanship.

Sources

Frequently Asked Questions

What happens to my Cisco ASA 5506-X, 5508-X or 5516-X after 31 August 2026?
The devices keep running technically, but Cisco ends all support: no TAC support, no patches, and the signature release also ends on 31 August 2026. The last runnable software remains ASA 9.16, because from version 9.17(1) Cisco no longer supports these models. Any vulnerability discovered in the future will therefore remain permanently open, regardless of what your support contract said. That is no reason to panic, but a clear reason to replace the ASA's VPN role in an orderly way.
Can I keep using AnyConnect 4.x after the end of support?
Technically yes, formal support only ends on 31 March 2027. However, security patches and maintenance releases have not been provided since 31 March 2024, so the client has been frozen for over two years. New operating system versions no longer receive adapted 4.x builds, and from a compliance perspective a VPN client without security fixes is hard to defend. If you still run AnyConnect 4.x in production today, do not postpone the replacement until 2027.
What distinguishes a WireGuard mesh like NetBird from a classic VPN gateway?
A classic remote-access VPN like AnyConnect terminates all connections at a central, publicly reachable gateway, in the ASA's case directly at the firewall. NetBird instead establishes direct WireGuard connections from peer to peer; a management plane handles authentication, key distribution and policies. There is no publicly listening VPN portal and no central bottleneck; a relay only steps in when no direct connection is possible.
Why are CISA and the BSI warning about Cisco ASA firewalls?
In September 2025, CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362 were actively exploited, and CISA issued Emergency Directive ED 25-03. In April 2026, the malware analysis report AR26-113A documented the FIRESTARTER backdoor: a Linux ELF backdoor on Firepower and Secure Firewall devices (ASA/FTD) that hooks the LINA data plane and survives reboots. Attackers used it in March 2026 to re-compromise devices that had already been patched. Germany's BSI warned on 24 April 2026 about Cisco firewalls infected with persistent malware. Both warnings are factual situation reports, not vendor bashing.
Does NetBird completely replace my Cisco ASA firewall?
No. NetBird replaces the ASA's VPN functions: remote access for employees and site-to-site connections via routing peers. NetBird does not replace firewall functions such as NAT, IDS/IPS, traffic inspection or web filtering. If you also use the ASA as an edge firewall, you still need a firewall for that. It no longer has to run a publicly reachable VPN portal, though, and can therefore be considerably simpler.
Can I run NetBird in parallel with AnyConnect?
Yes. The NetBird client runs alongside AnyConnect on the same device. This allows a step-by-step migration: a pilot group switches first, AnyConnect stays active as a fallback, and only after successful validation is the ASA's VPN portal disabled. A big-bang switch shortly before the deadline is not necessary.
How do I roll out the NetBird client across the company?
Via your existing MDM. NetBird provides official deployment documentation for Microsoft Intune, and since version 0.73.0 from 18 June 2026 the client supports MDM configuration profiles via the Windows Registry and macOS plist. Settings can therefore be distributed centrally and policy-based, much like you know it from AnyConnect package distribution.
Is NetBird really open source?
Yes. The source code is on GitHub under the BSD-3-Clause license; the server directories management/, signal/, relay/ and combined/ are licensed under AGPL-3.0. The accurate statement is: open source under BSD-3-Clause, with server components under AGPL-3.0. The project is developed at a high cadence, most recently version 0.76.1 from 31 July 2026.
What does birdhost cost compared to buying new Cisco hardware?
birdhost Startup costs from €99.90 per month, Business from €199.90 per month (both Germany region, plus VAT), Enterprise on request. All plans include unlimited users and devices; Startup is recommended for up to 25 and Business for up to 100 users. There is no hardware investment at all. The Cisco path, by contrast, requires a new appliance, licenses and a migration project; concrete prices depend on model and partner and can only be quoted seriously per offer.
How fast can I still migrate before the deadline?
A birdhost instance is created in a few minutes, and the 7-day free trial covers the pilot (credit card required). A four-week plan is realistic: week 1 inventory and pilot instance, week 2 client rollout via MDM to a pilot group, week 3 site-to-site via routing peers, week 4 cutover and deactivation of the ASA VPN portal. On the Business plan, a personal onboarding call supports the start.
Timo Wevelsiep

Written by

Timo Wevelsiep

Founder, merkaio

Founder of merkaio. Managed NetBird VPN hosting. Focused on network security, zero-trust architecture and scalable VPN infrastructure.

LinkedIn

Request Managed NetBird

We operate your dedicated NetBird instance including hosting, updates, monitoring and support. Tell us how many users, sites or devices you want to connect. We'll get back to you within 24 hours with a suitable proposal.

Timo Wevelsiep

Your Contact

Timo Wevelsiep

Founder, merkaio

Discuss your project with Timo

By submitting, you agree to our Privacy Policy.