cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2371
Views
0
Helpful
4
Replies

ASA 5515-X IPS module license disable

Ibrahim Bhuiyan
Level 1
Level 1

Hello,

After installing a demo license of IPS module it shows: IPS Module : Disabled  perpetual

Note: I uploaded the license file through ASDM and instlled successfully. but in "Show verson" I can see it is disable.

Can anyone tell me what ist the problem?

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

Not sure what went wrong - how did you got the License ? is that tied with UID ? as mentioned below

 

 

https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200376-Obtain-the-License-Key-for-a-Firepower-D.html

 

can you show modules and show version, show license to understand.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yes, its tied with UID. But as not like that below. Because this is IPS module. It does not show License key as like Firepower module.

Check the log below. and suggest me what to do?

 

FIREWALL-Primary/act# show module

Mod Card Type Model Serial No.
---- -------------------------------------------- ------------------ -----------
0 ASA 5515-X with SW, 6 GE Data, 1 GE Mgmt, AC ASA5515 FCH2042XXXX
ips ASA 5515-X IPS Security Services Processor ASA5515-IPS FCH2042XXXX
cxsc Unknown N/A FCH2042XXXX
sfr Unknown N/A FCH2042XXXX

Mod MAC Address Range Hw Version Fw Version Sw Version
---- --------------------------------- ------------ ------------ ---------------
0 a0e0.af52.cacf to a0e0.af52.cad6 3.0 2.1(9)8 9.12(3)12
ips a0e0.af52.cacd to a0e0.af52.cacd N/A N/A 7.1(7)E4
cxsc a0e0.af52.cacd to a0e0.af52.cacd N/A N/A
sfr a0e0.af52.cacd to a0e0.af52.cacd N/A N/A

Mod SSM Application Name Status SSM Application Version
---- ------------------------------ ---------------- --------------------------
ips IPS Up 7.1(7)E4
cxsc Unknown No Image Present Not Applicable
sfr Unknown No Image Present Not Applicable

Mod Status Data Plane Status Compatibility
---- ------------------ --------------------- -------------
0 Up Sys Not Applicable
ips Up Up
cxsc Unresponsive Not Applicable
sfr Unresponsive Not Applicable

Mod License Name License Status Time Remaining
---- -------------- --------------- ---------------
ips IPS Module Disabled perpetual

FIREWALL-Primary/act#

 

 

FIREWALL-Primary/act# sh ver

Cisco Adaptive Security Appliance Software Version 9.12(3)12
SSP Operating System Version 2.6(1.198)
Device Manager Version 7.2(2)1

Compiled on Fri 17-Apr-20 10:50 PDT by builders
System image file is "disk0:/asa9-12-3-12-smp-k8.bin"
Config file at boot was "startup-config"

FIREWALL-Primary up 3 hours 34 mins
failover cluster up 75 days 13 hours

Hardware: ASA5515, 8192 MB RAM, CPU Clarkdale 3058 MHz, 1 CPU (4 cores)
ASA: 4096 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Boot microcode : CNPx-MC-BOOT-2.00
SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005
IPSec microcode : CNPx-MC-IPSEC-MAIN-0026
Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4


0: Int: Internal-Data0/0 : address is a0e0.af52.cacf, irq 11
1: Ext: GigabitEthernet0/0 : address is a0e0.af52.cad3, irq 10
2: Ext: GigabitEthernet0/1 : address is a0e0.af52.cad0, irq 10
3: Ext: GigabitEthernet0/2 : address is a0e0.af52.cad4, irq 5
4: Ext: GigabitEthernet0/3 : address is a0e0.af52.cad1, irq 5
5: Ext: GigabitEthernet0/4 : address is a0e0.af52.cad5, irq 10
6: Ext: GigabitEthernet0/5 : address is a0e0.af52.cad2, irq 10
7: Int: Internal-Data0/1 : address is 0000.0001.0002, irq 0
8: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0
9: Int: Internal-Data0/2 : address is 0000.0001.0003, irq 0
10: Ext: Management0/0 : address is a0e0.af52.cacf, irq 0
11: Int: Internal-Data0/3 : address is 0000.0100.0001, irq 0

Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 100 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
Carrier : Disabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 250 perpetual
Total VPN Peers : 250 perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Shared License : Disabled perpetual
Total TLS Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
IPS Module : Disabled perpetual
Cluster : Enabled perpetual
Cluster Members : 2 perpetual

This platform has an ASA 5515 Security Plus license.


Failover cluster licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 100 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 4 perpetual
Carrier : Disabled perpetual
AnyConnect Premium Peers : 4 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 250 perpetual
Total VPN Peers : 250 perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Shared License : Disabled perpetual
Total TLS Proxy Sessions : 4 perpetual
Botnet Traffic Filter : Disabled perpetual
IPS Module : Disabled perpetual
Cluster : Enabled perpetual

This platform has an ASA 5515 Security Plus license.

Serial Number: FCH2042XXXX
Running Permanent Activation Key: 0x431bfc7b 0xb09cd7d4 0x91c0fdb0 0xd4503868 0x060ce4a5
Configuration register is 0x1

Image type : Release
Key version : A

Configuration last modified by enable_1 at 12:37:17.254 BDT Wed Sep 9 2020
FIREWALL-Primary/act#

Show License command not working!!

Marvin Rhoads
Hall of Fame
Hall of Fame

I didn't think they still offered IPS Demo license since this product has been end of life for 2 years.

Why would you want to spend time trying to make it work? It's not useful for any real security purpose in the current threat landscape and not even included on any current certification exam.

Yes marvin I agree with you. But this is pending work of a client. nothing to do actually. We are getting purchase a IPS License from cisco asap. before this action we need to check with demo license. So have any way ?

Review Cisco Networking for a $25 gift card