cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1757
Views
5
Helpful
4
Replies

ASA 5505 how to refresh user|connections when I disconnect a device after it reaches user limit

of1980
Level 1
Level 1

I have a problem that when users or connections reach the user license limit, I disconnect one device to let another device connect to Internet. How can I make sure it works. Sometimes it's hard for a new device to connect successfully, or wait for so long time. Is there command to refresh the user or connection to release the occupancy of user?

Thanks a lot.

4 Replies 4

Rahul Govindan
VIP Alumni
VIP Alumni

You can use the "show local-host" to see the current hosts and host-limit. You can use the "clear local-host x.x.x.x" to clear a specific host from talking up a license. This clears connections and xlates that the host holds. More on that command here:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/c3.html#pgfId-2249465

Thank you for your help.

"show local-host" give out too much details of connections.

While "show local-host connection | inc licensed" give only the count of host.

Current host count: 10, towards licensed host limit of: 10

I wonder if some commands can test  whether the inside ip is on line after I unplug Ethernet cable or shut down a device to release connection.

Or, the command can filter inside ip and clear the connection of it.

You can use "show local-host brief" just to see brief information per host. A host is not going to go away from host table once unplugged from the network. The connections that the ASA has for that host should timeout or be cleared manually. A "clear local-host x.x.x.x" should clear all that for a particular host.

Hi Rauhul,

Is there a way to change the "local-host " timeout timer? 

Some of my VPN clients disconnected from network but the local-host connection is still showing up and stayed in the table for around 3 minutes then ASA removed it from the table.  I want to speed up the removal process, is there a way to do that?

Thanks

Review Cisco Networking for a $25 gift card