<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Paired ASA HA License Activation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117928#M1071998</link>
    <description>&lt;P&gt;Seeking guidance on an ASA licensing concern. Currently a customer of mine has an RA VPN solution utilizing two 5555-X ASAs that are already paired in HA. New licenses were recently acquired and need to be installed. There has been back and forth with TAC on the process. I was advised that the following process would work:&lt;BR /&gt;Login to primary&lt;BR /&gt;Break HA (no failover)&lt;BR /&gt;Activate lic key&lt;BR /&gt;Login to standby &lt;BR /&gt;Activate lic key&lt;BR /&gt;Back to primary &lt;BR /&gt;Enable HA (failover)&lt;BR /&gt;Test &amp;amp; confirm &lt;BR /&gt;I was also advised that this will result in no service interruption. However, it was also mentioned that we "may" need to reboot. I will be on site for this task in case there are any emergency issues with the RA VPN since most are teleworking. Can anyone confirm the process to activate the new licenses on each ASA while they are already paired in HA or provide suggestions if there is an easier way. Thanks in advance!!&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 20:16:57 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2020-07-13T20:16:57Z</dc:date>
    <item>
      <title>Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117928#M1071998</link>
      <description>&lt;P&gt;Seeking guidance on an ASA licensing concern. Currently a customer of mine has an RA VPN solution utilizing two 5555-X ASAs that are already paired in HA. New licenses were recently acquired and need to be installed. There has been back and forth with TAC on the process. I was advised that the following process would work:&lt;BR /&gt;Login to primary&lt;BR /&gt;Break HA (no failover)&lt;BR /&gt;Activate lic key&lt;BR /&gt;Login to standby &lt;BR /&gt;Activate lic key&lt;BR /&gt;Back to primary &lt;BR /&gt;Enable HA (failover)&lt;BR /&gt;Test &amp;amp; confirm &lt;BR /&gt;I was also advised that this will result in no service interruption. However, it was also mentioned that we "may" need to reboot. I will be on site for this task in case there are any emergency issues with the RA VPN since most are teleworking. Can anyone confirm the process to activate the new licenses on each ASA while they are already paired in HA or provide suggestions if there is an easier way. Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 20:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117928#M1071998</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-07-13T20:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117943#M1072005</link>
      <description>&lt;P&gt;What license are you going to install?&lt;/P&gt;
&lt;P&gt;And what ASA version are you running?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 20:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117943#M1072005</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-13T20:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117946#M1072006</link>
      <description>Forgot to include that info, sorry and thanks:&lt;BR /&gt;ASA AnyConnect Term &lt;BR /&gt;SW ver: 9.12(3)7&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Jul 2020 20:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117946#M1072006</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-07-13T20:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117953#M1072007</link>
      <description>&lt;P&gt;If you are only adding the AnyConnect license then I do not understand why TAC suggested to break the HA pair.&lt;/P&gt;
&lt;P&gt;You need to only add the license to the primary active ASA and the license will sync to the standby.&amp;nbsp; I suggest having a service window for this change, however, there should not be any noticable impact on the users.&amp;nbsp; I have never had to do a restart of an ASA when adding an AnyConnect license, but there is a first time for everything.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 21:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117953#M1072007</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-13T21:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117955#M1072008</link>
      <description>&lt;P&gt;Some documentation if you want to read:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/general/asa-97-general-config/intro-license.html#ID-2148-00000a6e" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/configuration/general/asa-97-general-config/intro-license.html#ID-2148-00000a6e&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 21:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4117955#M1072008</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-13T21:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118102#M1072011</link>
      <description>&lt;P&gt;My experience matches that of &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt; . I've installed over a hundred AnyConnect license activation keys over the years and never had to touch the HA configuration or reboot.&lt;/P&gt;
&lt;P&gt;In ha the licenses sync but f you want to have an independent key on the Secondary unit you can also use your PAK to get an activation-key for it as well.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 02:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118102#M1072011</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-14T02:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118408#M1072042</link>
      <description>Attempted to install this am.  Here is my current situation:&lt;BR /&gt;Primary Serial Number: xxxx7ZXR&lt;BR /&gt;Running Permanent Activation Key: &amp;lt;key ommitted&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Standby Serial Number: xxxx70KK&lt;BR /&gt;Running Permanent Activation Key: &amp;lt;key ommitted&amp;gt;&lt;BR /&gt;Running Timebased Activation Key: &amp;lt;key ommitted&amp;gt;&lt;BR /&gt;&lt;BR /&gt;The permanent keys are the new ones getting installed which both primary and standby accepted.  However, when I issue a show ver on the standby unit the licenses depict that they expire in 15 days and there is still a running timebased activation key.  Not sure if we will be ok once it expires.  &lt;BR /&gt;&lt;BR /&gt;Primary output:&lt;BR /&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces       : Unlimited      perpetual&lt;BR /&gt;Maximum VLANs                     : 500            perpetual&lt;BR /&gt;Inside Hosts                      : Unlimited      perpetual&lt;BR /&gt;Failover                          : Active/Active  perpetual&lt;BR /&gt;Encryption-DES                    : Enabled        perpetual&lt;BR /&gt;Encryption-3DES-AES               : Enabled        perpetual&lt;BR /&gt;Security Contexts                 : 20             perpetual&lt;BR /&gt;Carrier                           : Disabled       perpetual&lt;BR /&gt;AnyConnect Premium Peers          : 5000           perpetual&lt;BR /&gt;AnyConnect Essentials             : Disabled       perpetual&lt;BR /&gt;Other VPN Peers                   : 5000           perpetual&lt;BR /&gt;Total VPN Peers                   : 5000           perpetual&lt;BR /&gt;AnyConnect for Mobile             : Enabled        perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone    : Enabled        perpetual&lt;BR /&gt;Advanced Endpoint Assessment      : Enabled        perpetual&lt;BR /&gt;Shared License                    : Disabled       perpetual&lt;BR /&gt;Total TLS Proxy Sessions          : 2              perpetual&lt;BR /&gt;Botnet Traffic Filter             : Disabled       perpetual&lt;BR /&gt;IPS Module                        : Disabled       perpetual&lt;BR /&gt;Cluster                           : Enabled        perpetual&lt;BR /&gt;Cluster Members                   : 2              perpetual&lt;BR /&gt;&lt;BR /&gt;Standby output:&lt;BR /&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces       : Unlimited      perpetual&lt;BR /&gt;Maximum VLANs                     : 500            perpetual&lt;BR /&gt;Inside Hosts                      : Unlimited      perpetual&lt;BR /&gt;Failover                          : Active/Active  perpetual&lt;BR /&gt;Encryption-DES                    : Enabled        perpetual&lt;BR /&gt;Encryption-3DES-AES               : Enabled        perpetual&lt;BR /&gt;Security Contexts                 : 12             15 days&lt;BR /&gt;Carrier                           : Disabled       perpetual&lt;BR /&gt;AnyConnect Premium Peers          : 5000           15 days&lt;BR /&gt;AnyConnect Essentials             : Disabled       perpetual&lt;BR /&gt;Other VPN Peers                   : 5000           perpetual&lt;BR /&gt;Total VPN Peers                   : 5000           perpetual&lt;BR /&gt;AnyConnect for Mobile             : Enabled        perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone    : Enabled        perpetual&lt;BR /&gt;Advanced Endpoint Assessment      : Enabled        perpetual&lt;BR /&gt;Shared License                    : Disabled       perpetual&lt;BR /&gt;Total TLS Proxy Sessions          : 2              perpetual&lt;BR /&gt;Botnet Traffic Filter             : Disabled       perpetual&lt;BR /&gt;IPS Module                        : Disabled       perpetual&lt;BR /&gt;Cluster                           : Enabled        perpetual&lt;BR /&gt;Cluster Members                   : 2              perpetual&lt;BR /&gt;&lt;BR /&gt;Please advise.  Thanks!</description>
      <pubDate>Tue, 14 Jul 2020 12:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118408#M1072042</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-07-14T12:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118622#M1072044</link>
      <description>&lt;P&gt;Adding additional info: TAC recently changed their original response as I think there was confusion between us. They claim that once the temporary lic expires the secondary unit will consume the permanent key and there will be no issues. Can you confirm this? Lastly, is there any way to confirm this is true prior to expiration? Would a force failover trigger the activation of the new key on the standby unit? Can I manually remove the current temp lic on the standby unit? TIA&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 18:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118622#M1072044</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-07-14T18:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118689#M1072045</link>
      <description>&lt;P&gt;I have nevery encountered this particular scenario, but I do not foresee an issue when the time-based license expires.&amp;nbsp; You can deactivate the time-based license by adding the "&lt;STRONG&gt;&lt;EM&gt;deactivate&lt;/EM&gt;&lt;/STRONG&gt;" keyword at the end of the activation-key command.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show activation-key&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;activation-key xxxxx deactivate&lt;/STRONG&gt; !(replace xxxxx with the actual key)&lt;/P&gt;
&lt;P&gt;You can deactivate the time-based key and then&amp;nbsp; issue a show version on the standby unit.&amp;nbsp; If you want to test, perform a failover to the standby unit.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscopress.com/articles/article.asp?p=2209314&amp;amp;seqNum=2" target="_blank"&gt;https://www.ciscopress.com/articles/article.asp?p=2209314&amp;amp;seqNum=2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 18:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4118689#M1072045</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-14T18:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Paired ASA HA License Activation</title>
      <link>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4119192#M1072066</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;thanks for the additional info.&amp;nbsp; The deactivation as you suggested of the temp license worked as expected and now both units are running the new licenses!&amp;nbsp; Thanks for the assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 13:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/paired-asa-ha-license-activation/m-p/4119192#M1072066</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-07-15T13:32:14Z</dc:date>
    </item>
  </channel>
</rss>

