cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
18225
Views
5
Helpful
6
Replies

Cisco ASA 5510 License

jneves100
Level 1
Level 1

Hi everyone,

I bought a Cisco ASA 5510 (P/N: ASA5510-BUN-K9) and i would like to know if i have to buy some license!

What i mean is, for the basics, it still being necessary aquire some license?

Best regards,

JL

2 Accepted Solutions

Accepted Solutions

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

To my understanding it should be enough as it is.

Addiotional Licenses would allow you to have more VPN users and to my understanding also allow use some of the ASA ports asa GigabitEthernet.

Heres a quote from a Cisco document

Table 2. Cisco ASA 5510 Adaptive Security Appliance Platform Capabilities and Capacities

Feature

Description

Firewall Throughput

Up to 300 Mbps

Maximum Firewall and IPS Throughput

• Up to 150 Mbps with AIP SSM-10

• Up to 300 Mbps with AIP SSM-20

VPN Throughput

Up to 170 Mbps

Concurrent Sessions

50,000; 130,0001

IPsec VPN Peers

250

Premium AnyConnect VPN Peer License Levels2

2,10, 25, 50, 100, or 250

Security Contexts

Up to 53

Interfaces*

5 Fast Ethernet ports; 2 Gigabit Ethernet + 3 Fast Ethernet*

Virtual Interfaces (VLANs)

50; 100*

Scalability*

VPN clustering and load balancing

High Availability

Not supported; Active/Active4, Active/Standby*

1Upgrade available with Cisco ASA 5510 Security Plus license

2Separately licensed feature; includes two with the base system

3Separately licensed feature; includes two with the Cisco ASA 5510 Security Plus license

4Available for the firewall feature set

Performance numbers tested and validated with Cisco ASA Software Release 7.2.

Link to document:

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html

- Jouni

View solution in original post

Hi Jose,

It depends what features you want to implement. For such features as NAT, ACL etc. you don't need additional licenses. You can check your licenses using this this command:

"sh version"

Under section "Licensed features for this platform:" you will see what options do you have.

Please rate helpful posts

Best Regards,

Eugene

View solution in original post

6 Replies 6

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

To my understanding it should be enough as it is.

Addiotional Licenses would allow you to have more VPN users and to my understanding also allow use some of the ASA ports asa GigabitEthernet.

Heres a quote from a Cisco document

Table 2. Cisco ASA 5510 Adaptive Security Appliance Platform Capabilities and Capacities

Feature

Description

Firewall Throughput

Up to 300 Mbps

Maximum Firewall and IPS Throughput

• Up to 150 Mbps with AIP SSM-10

• Up to 300 Mbps with AIP SSM-20

VPN Throughput

Up to 170 Mbps

Concurrent Sessions

50,000; 130,0001

IPsec VPN Peers

250

Premium AnyConnect VPN Peer License Levels2

2,10, 25, 50, 100, or 250

Security Contexts

Up to 53

Interfaces*

5 Fast Ethernet ports; 2 Gigabit Ethernet + 3 Fast Ethernet*

Virtual Interfaces (VLANs)

50; 100*

Scalability*

VPN clustering and load balancing

High Availability

Not supported; Active/Active4, Active/Standby*

1Upgrade available with Cisco ASA 5510 Security Plus license

2Separately licensed feature; includes two with the base system

3Separately licensed feature; includes two with the Cisco ASA 5510 Security Plus license

4Available for the firewall feature set

Performance numbers tested and validated with Cisco ASA Software Release 7.2.

Link to document:

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html

- Jouni

Hi Jose,

It depends what features you want to implement. For such features as NAT, ACL etc. you don't need additional licenses. You can check your licenses using this this command:

"sh version"

Under section "Licensed features for this platform:" you will see what options do you have.

Please rate helpful posts

Best Regards,

Eugene

Dear Eugene, 

Is this item a ASA5510-SSL250-K9 or ASA5510-SEC-BUN-K9?

It is really deficult to compare cause already AnyConnect Essentials             : 250            perpetual

if it would be disable, the item is then a ASA5510-SEC-BUN-K9...but now i am just confused..

"ciscoasa> sh ver

Cisco Adaptive Security Appliance Software Version 9.1(4)
Device Manager Version 7.1(5)100

Compiled on Thu 05-Dec-13 19:37 by builders
System image file is "disk0:/asa914-k8.bin"
Config file at boot was "startup-config"

ciscoasa up 19 mins 40 secs

Hardware:   ASA5510, 1024 MB RAM, CPU Pentium 4 Celeron 1600 MHz,
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xfff00000, 1024KB

Encryption hardware device : Cisco ASA-55xx on-board accelerator (revision 0x0)
                             Boot microcode        : CN1000-MC-BOOT-2.00
                             SSL/IKE microcode     : CNLite-MC-SSLm-PLUS-2_05
                             IPSec microcode       : CNlite-MC-IPSECm-MAIN-2.09
                             Number of accelerators: 1

 0: Ext: Ethernet0/0         : address is xxxxxxxx
 1: Ext: Ethernet0/1         : address is xxxxxxxx
 2: Ext: Ethernet0/2         : address is xxxxxxxxx
 3: Ext: Ethernet0/3         : address is xxxxxxxxxx
 4: Ext: Management0/0       : address is xxxxxxxx
 5: Int: Not used            : irq 11
 6: Int: Not used            : irq 5

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 100            perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Active/Active  perpetual
Encryption-DES                    : Enabled        perpetual
Encryption-3DES-AES               : Enabled        perpetual
Security Contexts                 : 2              perpetual
GTP/GPRS                          : Disabled       perpetual
AnyConnect Premium Peers          : 2              perpetual
AnyConnect Essentials             : 250            perpetual
Other VPN Peers                   : 250            perpetual
Total VPN Peers                   : 250            perpetual
Shared License                    : Disabled       perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
UC Phone Proxy Sessions           : 2              perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
Intercompany Media Engine         : Disabled       perpetual
Cluster                           : Disabled       perpetual

This platform has an ASA 5510 Security Plus license.

Serial Number: 
Running Permanent Activation Key: 
Configuration register is 0x1

"

best Regards

The two part number refer to bundles that include certain software licenses in addition to the hardware appliance. The hardware is the same in either case.

If one adds different licenses later it can change the output of the "show version" or related commands.

From the output you've provided, it's most likely an ASA5510-SEC-BUN-K9 that had an addition of AnyConnect Essentials license.

It would be very unusual to see the ASA5510-SSL250-K9 "downgraded" to the much less costly Essential licenses since that would be overwriting and essentially discarding the more expensive Premium licenses that already do everything the Essentials licenses do and more.

Dear Rhoads, 

 

Thank You for the quick reply...it was really helpful

Yes,  it is a ASA5510-SEC-BUN-K9 that had an addition of AnyConnect Essentials license.

 

It is a 250 AC Essential license(ASA-AC-E-5510=) as i thought....please let me know, if i was thought wrong....

 

best Regards

 
 

jneves100
Level 1
Level 1

Thank you Jouni and Eugene for your quickly answers!

As Jouni, for my scenário the base license its enough.

Best regards,

JL

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card