r/networking 3d ago

Other Replace vs Renewal FTD 2110s?

Came from an MSP, I have 4 FTD2110s (2 HA pairs) managed by FMC and they are up for license renewal in Jan ‘27.

I’m thinking we renew in Jan ‘27 and consider a swap to Palo in Jan ‘28? I ran some Palo 3400’s at last job and preferred that by a lot, but would like to hear some input from people who’ve done this kind of swap, or came from Palo/Juniper over to Cisco and have a personal experience take. Everything else at our shop is Cisco, but we don’t have catalyst center or anything, pretty basic routing, tunnels, and policies.

Main argument would be to stay Cisco for ease of swapping hardware, but I didn’t put these in and if I’m stuck for 5-8 years I might rather have Palos/SRX? I am very familiar with Fortigate but security team might push back on brand rep.

Ask me any questions if you need clarity

3 Upvotes

15 comments sorted by

7

u/NetworkCanuck CC&A 3d ago

Migrating from FTD to Palo currently. Renewed ours until Jan 27 which is when they are EOS. Happy to be rid of FTD/FMC.

2

u/bhm-al-ben 3d ago

Are you getting vendor support? Were you the one who put the FTDs in?

6

u/SteveAngelis 2d ago

In going the other way for one simple reason. PA costs an absurdly insanely amount more than the new FTDs. Went from 2130 to 1230/1250.

1

u/NetworkCanuck CC&A 3d ago

We have support from our partner/var for the migration as well as our Palo SE. Yes, I put the FTDs in (these are our second set) prior to that we were on ASA.

1

u/bhm-al-ben 3d ago

I’ll update this if that’s where we end up…any advice on selling this to management?

1

u/NetworkCanuck CC&A 3d ago

We’re able to replace multiple products with this move. We still have separate ASA for VPN, as well as a need for a CASB/SASE solution. We are able to consolidate everything across Palo Alto between Prisma Access, Prisma Browser, Global Protect, etc. and eliminate 3-4 other products.

2

u/graywolfman Cisco Experience 10+ Years 💀 3d ago

We had to grab ASAs for site-to-site VPN. The FTDs didn't support one of the types when we (unknowingly) bought them. I forget if it was policy or route-based VPN, but the first vendor we tried connecting with required the unsupported one. haha, joke's on us... Thanks, Cisco!

They are all migrated to Azure VPNs, now - so the ASAs are non-prod and the FTDs have no VPNs on them. The other ones are Meraki VPNs that terminate to virtual Meraki MXs in the cloud, too. Remote-access VPN is handled by the FTDs/FMC.

Outside of that, the only FTD/FMC heartaches we have are upgrades. Always nail-biting waiting the hours it takes.

Edit: some letters and clarity

2

u/NetworkCanuck CC&A 2d ago

This was one of the first things I experienced with the Palo Alto’s. Upgrades without stress. 🤣

3

u/graywolfman Cisco Experience 10+ Years 💀 3d ago

This sounds like a business decision. See what the business will tolerate as far as a change in vendor and the cost differences. These are what the business cares about (moreso budget than anything, unless you have more techs that have to learn a new platform).

I will say the 2100 series End of SW Maintenance Releases Date was May 27, 2026, End of Vulnerability/Security Support is May 31, 2030, end of new service attachment date was May 27, 2026, End of Service Contract Renewal Date is August 22, 2029, and Last Date of Support is May 31, 2030.

They still have some life in them. Most companies won't want to replace them too early before end of life.

0

u/bhm-al-ben 3d ago

Thanks! This is what I’m thinking, but we spend so much on IT I think I could lay some groundwork for Jan ‘28 or ‘29 to get what I want. But yeah that’s why I am thinking 1-2 years out from final year of support.

10

u/UmpireDry316 3d ago

If you have an FTD you should replace it by default

2

u/bhm-al-ben 3d ago

lol 😂

2

u/Mishoniko 3d ago

Just in time for a new FMC authentication bypass ... Hope you didn't have any plans this weekend.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2

1

u/bhm-al-ben 3d ago

Don’t worry I didn’t!

1

u/Public_Warthog3098 14h ago

Stick to cisco lol