12-26-2017 10:30 AM - edited 02-21-2020 10:42 AM
The asa is configured as cluster of 2.
It was working fine and out of nowhere the users cannot login to any-connect anymore.
The asa reports the session limit of 2 error.
The license shows:
PCVST-ASA# sh activation-key
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 100 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
Carrier : Disabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 250 perpetual
Total VPN Peers : 250 perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Shared License : Disabled perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
IPS Module : Enabled perpetual
Cluster : Enabled perpetual
Cluster Members : 2 perpetual
This platform has an ASA 5515 Security Plus license.
Is this a bug and requires reboot?
PCVST-ASA# sh ve
Cisco Adaptive Security Appliance Software Version 9.6(1)10
Device Manager Version 7.4(1)
Compiled on Tue 09-Aug-16 17:51 PDT by builders
System image file is "disk0:/asa961-10-smp-k8.bin"
Config file at boot was "startup-config"
PCVST-ASA up 111 days 22 hours
failover cluster up 1 year 304 days
Hardware: ASA5515, 8192 MB RAM, CPU Clarkdale 3058 MHz, 1 CPU (4 cores)
ASA: 4104 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB
Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Boot microcode : CNPx-MC-BOOT-2.00
SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005
IPSec microcode : CNPx-MC-IPSEC-MAIN-0026
Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4
Solved! Go to Solution.
01-02-2018 01:11 PM
The asa was setup as a failover pair and 1 member of the failover pair was dead.
Rebooting it fixed the issue.
12-26-2017 02:22 PM
Based on the show-output, you don't have a license for more then two concurrent AnyConnect-connections. If it was licensed before, apply the original licenses again. If you don't have them any more, write to licensing@cisco.com. They usually help quite fast. And in a failover-scenario, a reboot can always be tried.
12-26-2017 04:09 PM
I will reboot and check if it works.
thx
01-02-2018 01:11 PM
The asa was setup as a failover pair and 1 member of the failover pair was dead.
Rebooting it fixed the issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide