You can use either the Secure Firewall ASA or the Secure Firewall Threat Defense (formerly Firepower Threat Defense) operating system on your hardware platform:
ASA—The ASA is a traditional, advanced stateful firewall and VPN concentrator.
You may want to use the ASA if you do not need the advanced capabilities of the threat defense, or if you need an ASA-only feature that is not yet available on the threat defense. Cisco provides ASA-to-threat defense migration tools to help you convert your ASA to the threat defense if you start with ASA and later reimage to threat defense.
Threat Defense—The threat defense is a next-generation firewall that combines an advanced stateful firewall, VPN concentrator, and next generation IPS. In other words, the threat defense takes the best of ASA functionality and combines it with the best next-generation firewall and IPS functionality.
We recommend using the threat defense over the ASA because it contains most of the major functionality of the ASA, plus additional next generation firewall and IPS functionality.
To reimage between the ASA and the threat defense, see the Cisco Secure Firewall ASA and Secure Firewall Threat Defense Reimage Guide.