SSHGuard is designed to support this. Since the blocking backends are modular, you can make it block with firewalls other than those shipping with the code. Local or remote does not matter as long as you can reach/control it from the attacked host.
You have two options:
you submit an extension request. If the team considers the firewall is relevant enough (Cisco ASA surely is), they're happy to add it. See the Request New link in the home page.
He has stepped back in front of journalists. Then he had reproposed the same rule with different formulation