cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
30357
Views
40
Helpful
29
Replies

ASA 5506 lic question

Mariusz00001
Level 1
Level 1

1. Will I get ANY subscriptions in ASA5506-SEC-BUN-K9 pls? There is no info o cisco.com and all on-line shops just say it is ASA5506-SEC-BUN-K9...

2. What the difference between ASA5506-SEC-BUN-K9 and asa5506-fpwr-bun. I am after IPS...

3. Is it true that there are no switchports on this firewall?

2 Accepted Solutions

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

ASA5506-SEC-BUN-K9 includes the Security Plus license. The other one does not.

Both include the software module with FirePOWER image pre-loaded and the base Control license (ASA5506-CTRL-LIC). To actually use the FirePOWER IPS features you'd need to add a minimum of the IPS license. (L-ASA5506-TA-1Y for one year, -3Y and -5Y also available). 

The 5506 FirePOWER can be managed using ASDM, so a separate FireSIGHT Management Center license is not strictly required (tho advised for greatest functionality).

Both SKUs also include the no-cost ASA 5500 Strong Encryption License (3DES/AES).

View solution in original post

You're welcome.

The ASA5506-K9 (base license) comes with the same licenses as the ASA5506-FPWR-BUN. It even has the same FirePOWER software module image pre-installed and includes the CTRL license.

The difference is when your reseller or partner configures the FirePOWER bundle SKU in the Cisco Commerce Workspace (CCW - Cisco's configuration and ordering tool) they are prompted to add the optional add-on term-based FirePOWER licenses and FireSIGHT Management Center.

Either one can have the IPS license added later - same part number and same cost.

I hope this answers your question. Please mark as answered if it does.

View solution in original post

29 Replies 29

Marvin Rhoads
Hall of Fame
Hall of Fame

ASA5506-SEC-BUN-K9 includes the Security Plus license. The other one does not.

Both include the software module with FirePOWER image pre-loaded and the base Control license (ASA5506-CTRL-LIC). To actually use the FirePOWER IPS features you'd need to add a minimum of the IPS license. (L-ASA5506-TA-1Y for one year, -3Y and -5Y also available). 

The 5506 FirePOWER can be managed using ASDM, so a separate FireSIGHT Management Center license is not strictly required (tho advised for greatest functionality).

Both SKUs also include the no-cost ASA 5500 Strong Encryption License (3DES/AES).

Thank you Marvin.

 

What about ASA5506-K9 (base license) pls?

 

Will it support the IPS license later on?

You're welcome.

The ASA5506-K9 (base license) comes with the same licenses as the ASA5506-FPWR-BUN. It even has the same FirePOWER software module image pre-installed and includes the CTRL license.

The difference is when your reseller or partner configures the FirePOWER bundle SKU in the Cisco Commerce Workspace (CCW - Cisco's configuration and ordering tool) they are prompted to add the optional add-on term-based FirePOWER licenses and FireSIGHT Management Center.

Either one can have the IPS license added later - same part number and same cost.

I hope this answers your question. Please mark as answered if it does.

Marvin, a quick one. I read somewhere I'd need to add an SSD to run Firepower features. Is it true?

I just bought ASA5506-K9. Does it arrive with an SSD?

 

I am especially interested in IPS but AMP would be great as well.

 

Is it enought o purchase L-ASA5506-TA= as you said?

 

Thx

Yes, it's built-in on all the new SMB ASAs. 

The 5506, 5506W, and 5506H all have a 50 Gb mSATA SSD drive (100 GB on the new 5516-X). It's not an option like it is on the larger models (and those use a 120 GB SSD). See table 3 in the data sheet.

Also, they all come with the FirePOWER image preinstalled. You should be able to see the software image as up from the cli with "show module" where you will see a "sfr" module type.

Thx. Appreciate your quick reply. My ASA arrives in a couple of days so will play with it

So what is the purpose of buying the SEC PLUS, what does it have that the other versions do not, as its more expensive?

Security Plus features are outlined in the tables of the product data sheet:

http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html

Basically you get the ability to have:

a. more concurrent sessions

b. more site-site and remote access VPN peers

c. more VLANs

d. High Availability (Active-Standby)

 

So should all Sec-Plus boxes come with a default feature pack? Is that listed anywhere as to what you get so you can compare it to what you should have.

can you help me please:

__i have a cisco asa 5506-x and

i want to increase the number of connections anyconnect vpn (the equipement have only 4 connexion)

 

__and what services can be added using the asa5506_sec-pl certificate

 

If you require more AnyConnect users then buy AnyConnect licenses.

The features of SEC-PLUS are as noted earlier in this thread and in the linked datasheet.

Hi Marvin,

I have ASA5506-K9 with base license and unfortunately it only supports 5 VLANs. Is it possible to upgrade the ASA5506-K9 with secure plus license. What is the  part number for secure plus license.

Thanks

That would be part number "ASA5506-SEC-PL".

We typically don't sell a lot of those since the pricing n it usually makes it more attractive to move up to one of the higher models that does not require the separate license for the features provided with Security Plus.

Thanks Martin.

Unfortunately we ordered firewall with base licence and then realized it has a limitation of 5 VLANs. So now need to upgrade the firewall to secure plus. The part number for secure plus licence is L-ASA5506-SEC-PL=. Thanks for a quick response.

Review Cisco Networking for a $25 gift card