<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505 Inside Hosts limit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848463#M459144</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More than 10 users going to the internet trough the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nop, that is not posible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do a show local-host and you will see a report of the local users connection and please notice the first line saying that you reach the maximum number of host due to the license restriction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in this case you will need to get the proper license to do it ( 50 user license or UL (unlimit license)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 19 Feb 2012 21:58:04 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-02-19T21:58:04Z</dc:date>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848459#M459140</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA5505 I am working with has this from the show version:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : 8&lt;BR /&gt;VLANs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3, DMZ Restricted&lt;BR /&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;Inside Hosts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;Failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&lt;BR /&gt;VPN-DES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;BR /&gt;VPN-3DES-AES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;BR /&gt;VPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10&lt;BR /&gt;WebVPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&lt;BR /&gt;Dual ISPs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&lt;BR /&gt;VLAN Trunk Ports&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;This platform has a Base license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the Insides Hosts&amp;nbsp; :10 line mean that only 10 devices can be connected to the firewall at one time? I would like to connect an AP to one of the PoE ports and have possibly more than 10 connected. Is this possible with this ASA5505?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Pat.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848459#M459140</guid>
      <dc:creator>Patrick McHenry</dc:creator>
      <dc:date>2019-03-11T22:32:01Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848460#M459141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-indent: -24px;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"In routed mode, hosts on the inside (Business and Home VLANs) count towards the limit when they communicate with the outside (Internet VLAN), including when the inside initiates a connection to the outside as well as when the outside initiates a connection to the inside. Note that even when the outside initiates a connection to the inside, outside hosts are &lt;/P&gt;&lt;P&gt; &lt;EM style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 10px; text-indent: -24px; background-color: #ffffff;"&gt;not&lt;/EM&gt;&lt;/P&gt;&lt;P&gt; counted towards the limit; only the inside hosts count. Hosts that initiate traffic between Business and Home are also not counted towards the limit. The interface associated with the default route is considered to be the outside Internet interface. If there is no default route, hosts on all interfaces are counted toward the limit. In transparent mode, the interface with the lowest number of hosts is counted towards the host limit. See the &lt;/P&gt;&lt;P&gt; &lt;STRONG style="font-weight: bold; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 10px; text-indent: -24px; background-color: #ffffff;"&gt;show local-host &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;command to view host limits."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to answer your question, you're ok if you will connect an AP, the limit is refering to the hosts that need access from inside to outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 13:22:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848460#M459141</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-02-19T13:22:15Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848461#M459142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like users - possibly more than 10 at a time to be able to connect to the Internet. I was going to connect the 5505 to a Comcast Business Internet circuit and hang a couple of 1260 APs from the PoE interfaces. Now I am wondering if this is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One line in your post is confusing me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Hosts that initiate traffic between Business and Home are also not counted towards the limit."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you mean to say:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hosts that initiate traffic between Business and Home are also counted towards the limit. ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Pat.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 14:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848461#M459142</guid>
      <dc:creator>Patrick McHenry</dc:creator>
      <dc:date>2012-02-19T14:54:17Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848462#M459143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The text as it is, if taken from ASA Command Line Configuration :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/specs.html#wp1012343"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/specs.html#wp1012343&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My undestanding is that only traffic from any inside hosts that generate traffic to outside counts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 17:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848462#M459143</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-02-19T17:13:23Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848463#M459144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More than 10 users going to the internet trough the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nop, that is not posible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do a show local-host and you will see a report of the local users connection and please notice the first line saying that you reach the maximum number of host due to the license restriction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in this case you will need to get the proper license to do it ( 50 user license or UL (unlimit license)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 21:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848463#M459144</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-19T21:58:04Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848464#M459145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know approximately how much a 50 user license would be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Pat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848464#M459145</guid>
      <dc:creator>Patrick McHenry</dc:creator>
      <dc:date>2012-02-19T22:02:37Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848465#M459146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not at all, I work for the security team so I do not handle prices &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But here are both licenses, so you can call your re-seller and ask him about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5505-50-BUN-K9 = 50 user bundle&lt;/P&gt;&lt;P&gt;ASA5505-UL-BUN-K9 = Unlimit users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848465#M459146</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-19T22:10:55Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848466#M459147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julio one more question,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 3 VLAN limit is slightly confusing. I know the outside interface will be VLAN 1 and the inside interface will be VLAN 2, but will I be able to create a 3rd VLAN. I would like to use this Internet circuit for our own IT staff and Vendors that might work in different locations in the building and keep them seperate via an access-list. I will be able to move the APs where ever I want via a non-routed VLAN and we were doing this with a Linksys router and some other routers acting as APs but, it wasn't reliable thus the reason we are trying to use a little higher grade equipment without breaking the bank. We had this 5505 lying around.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848466#M459147</guid>
      <dc:creator>Patrick McHenry</dc:creator>
      <dc:date>2012-02-19T22:20:47Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848467#M459148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can create 3 vlans like inside, outside and dmz however as you have dmz restricted license you would not be able to initiate the communication between all of them. f&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; For example, you have one VLAN assigned to the outside for Internet&amp;nbsp; access, one VLAN assigned to an inside work network, and a third VLAN&amp;nbsp; assigned to your home network. The home network does not need to access&amp;nbsp; the work network, so you can use the &lt;STRONG&gt;no forward interface&lt;/STRONG&gt; command on the home VLAN; the work network can access the home network, but the home network cannot access the work network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1931372"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; If you already have two VLAN interfaces configured with a &lt;STRONG&gt;nameif&lt;/STRONG&gt; command, be sure to enter the&lt;STRONG&gt; no forward interface &lt;/STRONG&gt;command before the &lt;STRONG&gt;nameif&lt;/STRONG&gt; command on the third interface; the security appliance does not allow&amp;nbsp; three fully functioning VLAN interfaces with the Base license on the ASA&amp;nbsp; 5505 adaptive security appliance. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 13:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848467#M459148</guid>
      <dc:creator>Amit Rai</dc:creator>
      <dc:date>2012-02-21T13:48:46Z</dc:date>
    </item>
    <item>
      <title>ASA5505 Inside Hosts limit</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848468#M459149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that if I create this third interface and do as you say, will I be able to communicate betwwen the third VLAN and the outside VLAN? Because if I can't, then there would be no reason for this as I want both the inside VLAN and the third VLAN to got to the Internet. Also,if they can, will I be able to have more than 10 users going to the Internet at once?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Pat.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 12:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-inside-hosts-limit/m-p/1848468#M459149</guid>
      <dc:creator>Patrick McHenry</dc:creator>
      <dc:date>2012-02-22T12:39:45Z</dc:date>
    </item>
  </channel>
</rss>

