<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Licensing -Security Contexts on ASA5585-X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188143#M361421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to split the 20 Security Contexts between 2 differents ASAs then you are looking at configuring a&amp;nbsp; Active/Active Failover environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want all Security Contexts to be Active only on one physical ASA at a time (while the other is there to take over when the main one fails) then you are looking at configuring a Active/Standby Failover enviroment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in other words&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Each units 10 Security Context license will be combined between the units&lt;/LI&gt;&lt;LI&gt;You can either use 20 Security Contexs on a single physical unit at a time in Active/Standby&lt;/LI&gt;&lt;LI&gt;OR you can divide the 20 Security Contexts between the 2 Physical ASAs in Active/Active&lt;UL&gt;&lt;LI&gt;For example 10 Active in ASA1 and 10 Active in ASA2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also heres a partial quote from the Cisco document&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;H3&gt; Failover License Requirements and Exceptions &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp2003781"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Failover units do not require the same license on each unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp2003785"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Older versions of ASA software required that the licenses match on each&amp;nbsp; unit. Starting with Version 8.3(1), you no longer need to install&amp;nbsp; identical licenses. Typically, you buy a license only for the primary&amp;nbsp; unit; for Active/Standby failover, the secondary unit inherits the&amp;nbsp; primary license when it becomes active. If you have licenses on both&amp;nbsp; units, they combine into a single running failover cluster license. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt; How Failover or ASA Cluster Licenses Combine &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp2004878"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; For failover pairs or ASA clusters, the licenses on each unit are&amp;nbsp; combined into a single running cluster license. If you buy separate&amp;nbsp; licenses for each unit, then the combined license uses the following&amp;nbsp; rules: &lt;/P&gt;&lt;P&gt; &lt;A name="wp1320372"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For example, for failover: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You&amp;nbsp; have two ASA 5540 ASAs, one with 20 contexts and the other with 10&amp;nbsp; contexts; the combined license allows 30 contexts. For Active/Active&amp;nbsp; failover, the contexts are divided between the two units. One unit can&amp;nbsp; use 18 contexts and the other unit can use 12 contexts, for example, for&amp;nbsp; a total of 30. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Feb 2013 18:50:42 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-02-25T18:50:42Z</dc:date>
    <item>
      <title>Licensing -Security Contexts on ASA5585-X</title>
      <link>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188142#M361420</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer with 2 ASA 5585-X and they are looking at running a total of 20 Security contexts in failover mode on these two firewalls. From a licensing perspective, Can I get 10 security contexts on each of these firewalls and that gives me a cumulative context number of 20.I am not sure though if I will be able to run all 20 contexts in failover mode on both firewalls. &lt;/P&gt;&lt;P&gt;This is the document I am reading but not very clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa90/license/license_management/license.html#wp1345944" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa90/license/license_management/license.html#wp1345944&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188142#M361420</guid>
      <dc:creator>Pratibha Bhasin</dc:creator>
      <dc:date>2019-03-12T01:05:22Z</dc:date>
    </item>
    <item>
      <title>Licensing -Security Contexts on ASA5585-X</title>
      <link>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188143#M361421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to split the 20 Security Contexts between 2 differents ASAs then you are looking at configuring a&amp;nbsp; Active/Active Failover environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want all Security Contexts to be Active only on one physical ASA at a time (while the other is there to take over when the main one fails) then you are looking at configuring a Active/Standby Failover enviroment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in other words&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Each units 10 Security Context license will be combined between the units&lt;/LI&gt;&lt;LI&gt;You can either use 20 Security Contexs on a single physical unit at a time in Active/Standby&lt;/LI&gt;&lt;LI&gt;OR you can divide the 20 Security Contexts between the 2 Physical ASAs in Active/Active&lt;UL&gt;&lt;LI&gt;For example 10 Active in ASA1 and 10 Active in ASA2&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also heres a partial quote from the Cisco document&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;H3&gt; Failover License Requirements and Exceptions &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp2003781"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Failover units do not require the same license on each unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp2003785"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Older versions of ASA software required that the licenses match on each&amp;nbsp; unit. Starting with Version 8.3(1), you no longer need to install&amp;nbsp; identical licenses. Typically, you buy a license only for the primary&amp;nbsp; unit; for Active/Standby failover, the secondary unit inherits the&amp;nbsp; primary license when it becomes active. If you have licenses on both&amp;nbsp; units, they combine into a single running failover cluster license. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt; How Failover or ASA Cluster Licenses Combine &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp2004878"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; For failover pairs or ASA clusters, the licenses on each unit are&amp;nbsp; combined into a single running cluster license. If you buy separate&amp;nbsp; licenses for each unit, then the combined license uses the following&amp;nbsp; rules: &lt;/P&gt;&lt;P&gt; &lt;A name="wp1320372"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For example, for failover: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You&amp;nbsp; have two ASA 5540 ASAs, one with 20 contexts and the other with 10&amp;nbsp; contexts; the combined license allows 30 contexts. For Active/Active&amp;nbsp; failover, the contexts are divided between the two units. One unit can&amp;nbsp; use 18 contexts and the other unit can use 12 contexts, for example, for&amp;nbsp; a total of 30. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2013 18:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188143#M361421</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-25T18:50:42Z</dc:date>
    </item>
    <item>
      <title>Licensing -Security Contexts on ASA5585-X</title>
      <link>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188144#M361428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What if you are trying to do some contexts Active on one firewall and standby on the second one.&lt;/P&gt;&lt;P&gt;eg- if&amp;nbsp; I have 4 contexts - c1, c2,c3 and c4&lt;/P&gt;&lt;P&gt;FW1 -- C1 and C2 (active)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; c3 and c4 (failover)&lt;/P&gt;&lt;P&gt;FW2 - c1 and c2 (failover)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; c3 and c4 (active)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in this scenario, technically do I need (4) context licenses on each of these firewalls to work ? or just a total of 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2013 19:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188144#M361428</guid>
      <dc:creator>Pratibha Bhasin</dc:creator>
      <dc:date>2013-02-25T19:30:55Z</dc:date>
    </item>
    <item>
      <title>Licensing -Security Contexts on ASA5585-X</title>
      <link>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188145#M361431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you are talking about is Active/Active Failover. A failover setup what utilises both ASA devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically what controls where the Security Contexts are Active is the Failover Group configuration. You always configure 2 Failover Groups. Each have their own ASA set as Active firewall unit. Then you will just assign each Security Contexts to the Failover Group you want them to be in. This will let you define the Active roles of each device in the way you mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to have a total of 4 Security Contexts in a Failover pair you just need a combined license that amounts to total&amp;nbsp; of 4 Security Contexts. Actually the ASAs default to having 2 Security Contexts&amp;nbsp; (most models) so when 2 ASA units are combined in Failover it actually has (atleast) 4 Security Contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully the information has been helpfull &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2013 19:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/licensing-security-contexts-on-asa5585-x/m-p/2188145#M361431</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-25T19:39:48Z</dc:date>
    </item>
  </channel>
</rss>

