05-04-2015 09:11 AM - edited 03-11-2019 10:52 PM
1. Will I get ANY subscriptions in ASA5506-SEC-BUN-K9 pls? There is no info o cisco.com and all on-line shops just say it is ASA5506-SEC-BUN-K9...
2. What the difference between ASA5506-SEC-BUN-K9 and asa5506-fpwr-bun. I am after IPS...
3. Is it true that there are no switchports on this firewall?
Solved! Go to Solution.
08-10-2016 08:24 AM
You're welcome. Please mark the answer as helpful it it helped.
08-23-2016 12:29 PM
I am Looking for an advice before Purchase. I need to Block Download, Especially Torrents otherthan the security features, also Want to see Bandwidth/internet usage per device. If i go for ASA5506-FPWR-BUN and L-ASA5506-TAMC= is this will do those things.? [50Mbps internet speed and 30-40 Devices in the Network]
08-23-2016 01:34 PM
Functionally the 5506 with TAMC license can do what you are asking.
Note that you can see but not control bandwidth usage at this time (with FirePOWER software version 6.0.x).
You would be right at the edge of its performance with all features active if you sustain 50 Mbps throughput.
08-25-2016 02:02 AM
Thank You Very Much. Appreciate your Response..
10-02-2017 05:52 PM
Hi Guys,
I can see that for the 5506 to support HA the security plus license is needed. My question is, do we need to buy 2 x L-ASA5506-SEC-PL= ? i.e one for each device?. The documentation is not very explicit in this regard. ASA Licensing
10-23-2017 09:49 PM
10-23-2017 11:29 PM
Part number L-ASA5506-SEC-PL= is just a license to add Security Plus to an existing ASA 5506.
If you want a new ASA 5506, you need to choose several things such as:
- ASA vs. FTD software,
- Security Plus license or not,
- licenses for Firepower service module or not,
- AnyConnect clients (and what type - Plus, Apex or VPN only) and
- what support level you require.
I recommend working directly with a Cisco reseller or systems engineer to make sure you get the right part numbers. It's a bit more nuanced than one can simply lay out prescriptively in a forum posting.
02-11-2016 09:35 AM
Marvin do you have the sku for the FireSIGHT ? So we run the firepower via the 5506, but if we want to run it off the 5506, there is an additional license?
03-09-2016 05:19 AM
Marvin, I didn't get the L-ASA5506-TA-1Y for 1 year IPS, I picked up a PROMO pack , which is coded as L-ASA5506-TAMC-1PR, Showed it has having IPS, URL, and AMP. So when I got my PAK, and did the license, it only had 2 sets of codes to add, one for URL and one for MALWARE. When I opened a TAC, they said the license feature on the PAK was fine, and MALWARE and URL would be a single file, and that the IPS features is not documented since that license will be updates based on the Protect and Control feature. So my question is would this be the same for IPS if I would of purchased the code you mentioned for just IPS? I haven't worked with the new ASA to much, and I want to make sure I have the IPS features, so I can learn and update my skill set. With the 5505 5510 with the IPS module I thought you ended up with and actual IPS menu on the left column to open, so with the 5506, I don't see anything that states IPS. I do see I have Protect and Control and the other 2 licenses active.
03-09-2016 05:57 AM
The Protect and Control (included with every ASA with FirePOWER service module) license enables you to use AVC and IPS features on the module.
The IPS license ("TA" - can be combined with other license type and may or may not be part of a "-PR" promo package) is actually a subscription that entitles you to keep your IPS definitions current (i.e. download and apply VDB and Geolocation updates). Confusingly, it isn't enforced via technical means like the old Cisco IPS was. (That product checked your serial number against internal Cisco contract entitlement system.)
03-09-2016 07:01 AM
See attached, this is clipped from the bottom of my PAK, so wouldn't one conclude that this does, as the vendor told me it does include the subscription? After applying it how will I know its actually active and able to update. The second on shows the URL and MALWARE with subscription end dates, I would expected to see and IPS one there as well.
03-09-2016 07:22 AM
Yes I agree it would be useful if Cisco showed you the subscription status - either in the license, the PAK or anywhere.
Unfortunately they do not currently do so for that particular feature.
Since they do not prevent downloads even without a current valid subscriptions, the only way (that I know of) you can actually find out if your entitlement is current is by asking your vendor to check in the Cisco Service Contract Center (CSCC) portal.
03-09-2016 07:55 AM
Ok, thank you for the information.
03-09-2016 08:35 AM
May as well ask, so using the FirePower services on the 5506 vs using the Firesight VM to manage it, is there a big cost to move to the Firesight platform?
03-09-2016 10:56 AM
The entry level FirePOWER Management Center VMs (2-device and 10-device licenses) are pretty inexpensive at US$500 and US$2000 list price respectively.
If you add Smartnet support (i.e part number CON-SAU-VMWSW2 for example), it's list price is about US$100/year.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide