cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1269
Views
0
Helpful
7
Replies

ASA License question

startx001
Level 1
Level 1

Hi All,

I have two ASA 5500 in failover mode. 

I want to upgrade license on one ASA with

ASA   5500 SSL VPN 250 to 500 Premium User Upgrade License

Does i need to upgarde IOS , and how will they work in failover  if license is put only on one ASA and not on other  .

Thanks

VZ

7 Replies 7

Collin Clark
VIP Alumni
VIP Alumni

With version 8.3 and greater, a failover pair will share the license. If your 8.2 or earlier you would have to buy a license for each device.

Collin already polinted out the important changes in 8.3. If you are still on ASA version 8.2 or even lower, then upgrading the ASA (which often needs a memory-upgrade) is likely less expensive then bying two times the licenses you need what was needed with the older versions.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Yes , thx .

Can i put license to Active unit when is version 8.2 , and after that if i upgrade Active and standby to 8.3  , will license be shared ? Can i share license then ?

Up to version 8.2 the licenses have to be identical. So if you have 2*250 Premium licenses on your ASAs now, the moment you upgrade to 8.3 you have 500.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

So just to confirm .

I will put license to Active unit first , then upgrade to 8.3.1 or later ( both units )  and license from Active will be shared to standby  ?

You first have to upgrade (don't use 8.3, better go to the latest 8.4). After that you can apply a license to you primary ASA if you still need the license.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Like Karsten implied - if you put the license only on the Active unit of a failover pair while still running 8.2, the failover pair will break as they will detect non-identical licenses.

That's why you upgrade first (or do without redundancy until you do so).

Review Cisco Networking for a $25 gift card