cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
2731
Views
0
Helpful
8
Replies

ASA-5506X in HA - Base Licence v Security Plus Licence

scawlding1
Level 1
Level 1

Hi,

I have 2 x Cisco ASA-5506X, one has a Base Licence and one has a Security Plus Licence, am I able to use these devices in a Active/Standby HA solution?

I've spotted on other feeds (as below) that the licences transfer between devices and I can't see much online about these needing to match but rather Model, Version and Interface number needs to be the same?

 

Both units must have the Security Plus license.

 

 

I opened a case with Cisco licensing and here was their response.

"I completely understand what your concern is however you got the failover concept just a little bit false. The failover works on the secondary HA it is configured to by mirroring or copying what licenses are on the primary but it doesnā€™t take the license of the primary at all. The licenses stays on the primary but it is also being used by the secondary so all you need to do is configuration. Remove the old secondary from the HA or failover configuration and then add the new secondary on to the failover configuration."

I told him that prior to the purchase of the second ASA there was only a single firewall.

 

 

2 Accepted Solutions

Accepted Solutions

yes i would expect to be Mirror of the both the device.

 

HA - why we looking HA ? means if one of the device fails, other one become active and do the job as expected with out any further issue.

 

So being said, how if they have 2 different images or different configuration or specification works as expected. Guidelines always suggest to have same 100% similar for better outcome.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Hope information help you, if no further assitance required can we close the issue or you looking any further help on this context ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

8 Replies 8

@scawlding1 Answered on the other thread you responded to, but....

5506-X requires the Security Plus License for HA

https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/configuration/general/asa-910-general-config/ha-failover.html#ID-2107-00000379

 

Model

License Requirement

ASA 5506-Xā€Ø and ASA 5506W-X

  • Active/Standbyā€”Security Plus License.

  • Active/Activeā€”No Support.

Note 

Each unit must have the same encryption license.

Thanks Rob,

So just to confirm, some failover units do no require the same licence on each unit but in the case of ASA-5506x, this does require the same Security Plus encryption licence on both units for HA to work?

 

Cheers

@scawlding1 from that link provided "Failover units do not require the same license on each unit. If you have licenses on both units, they combine into a single running failover cluster license. There are some exceptions to this rule. See the following table for precise licensing requirements for failover. "......the ASA 5506 is an exception.

 

The ASA software version and hardware must be identical versions.

balaji.bandi
Hall of Fame
Hall of Fame

it required and always HA

 

1. both device to be same

2. same Code running

3. Same License.

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/ha-failover.html#ID-2107-000003fe

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi balaji.bandi

Thanks for confirming on the licencing and sorry to check something else, but is that also the case with the OS?

One device is Firepower Extensible Operating System Version 2.6

Other device is SSP Operating System Version 2.8

 

Thanks 

yes i would expect to be Mirror of the both the device.

 

HA - why we looking HA ? means if one of the device fails, other one become active and do the job as expected with out any further issue.

 

So being said, how if they have 2 different images or different configuration or specification works as expected. Guidelines always suggest to have same 100% similar for better outcome.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you for the clarification

Hope information help you, if no further assitance required can we close the issue or you looking any further help on this context ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card