02-09-2016 02:21 AM - last edited on 03-25-2019 05:58 PM by ciscomoderator
Hi,
I have recently been given a second ASA 5510 firewall and was wondering how the licensing works for using this in a failover solution ?
I already have a ASA 5510 firewall which has Security Plus license and is under maintenance and wanted to try to understand the mud pile which is licensing as there seems to be conflicting information from Cisco Partners regarding this.
Also is it possible in a failover configuaration to have one internet connection on one firewall and another on the other firewall and this failover based on internet connection stats rather than just fialover the firewall itself ?
Thanks
Ed
02-09-2016 03:04 AM
Hello!
To use failover you need to have SEC Plus license on boths ASAs. SEC Plus license gives you an opportunity to configure Active/Standby and Active/Active failover.
To use IPS redundancy, from my point of view, it is better to connect both ISPs to every ASA in failover. You can configure dual ISP on ASA, using this guide:
02-09-2016 03:14 AM
Thanks for this - thats not actually a bad idea.
License wise how does this work if I have been given the ASA 5510 ??
02-09-2016 03:50 AM
So, I advice you to contact with your local Cisco Partner/Reseller and order the following license:
L-ASA5510-SEC-PL= ASA 5510 Security Plus License w/ HA, GE, more VLANs + conns
After getting the Product Activation Key (PAK) you'll install the license to your new ASA and you'll be able to connect two ASAs in failover configuration.
02-09-2016 04:03 AM
Thanks - and if the firewall already has the PAK then its fine to use it ?
02-09-2016 04:07 AM
If you mean, PAK for SEC Plus license, sure, you can just use it on
www.cisco.com/go/license
and get license-key.
02-09-2016 04:15 AM
Sorry I meant the firewall already has the license when I got it.
02-09-2016 04:26 AM
Ah, ok, no problem. So no additional licenses are required. You can try to configure failover.
02-09-2016 04:30 AM
So this doesn't break any licensing conditions or restrictions.
02-09-2016 04:37 AM
There is one thing, I forgot to mention. If you have IOS version 8.3 and higher - no problem, the majority of licenses will be copied from first ASA to the second one. For example, if you have Anyconnect Essentials and Anyconnect mobile licenses on the first gear, you don't need to buy them for the second ASA in failover.
But, if your IOS version is 8.2 or lower, you need to have absolutely identical set of license on both gears to be able to make a failover.
If we speak about newer gears, for example ASA 5512, ASA5515, those gears can be equipped with additional software modules: older CX module (already End-of-SALE), or newer SFR (SourceFIRE) module. For those additional software modules you have to buy separate set of licenses for every ASA in failover.
02-09-2016 04:47 AM
OK - so all I need is the hardware for the second one and not worry about the license ?
I was given the firewall by another charity and just trying to move around the minefield that is Cisco licensing.
Thanks again
Ed
02-09-2016 04:49 AM
You need software for the first and the second one to be higher then 8.3 version. What is the software version of the first ASA?
02-09-2016 06:31 AM
8.4(6) on the first one which we bought and has a software update contract on.
I have the latest 9.1 to put on soon.
02-09-2016 06:33 AM
Ok, great, so you can upgrade the first one and the second ASA to 9.1 and create a failover pair. No issues with licenses.
02-09-2016 06:58 AM
Excellent thanks for you help!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide