cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1944
Views
5
Helpful
6
Replies
Highlighted
Participant

Botnet Traffic filter temporary license on failover units


Hi, I want to evaluate Botnet Traffic Filter on ASA. I have two units with Failover Active / Standby, I have received one temporary license for the Active unit.

Do I need another temporary license for the standby pair for evaluating?

I read in the Configuration Guide “Because the temporary license continues to count down for as long as it is activated on a failover unit, we do not recommend using a temporary license in a permanent failover installation; when the temporary license expires, failover will no longer work”

What does it means? It sounds very dangerous

Can I apply my temporary license to the active unit or not?

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted

You can't delete a license, you can only overwrite it.  So, make sure you keep the current permanent key that you have and when done just reapply it.

Rgs,

PK

View solution in original post

6 REPLIES 6
Highlighted
Cisco Employee

You canNOT apply the licence JUST to the active unit. The failover units need to have the same licence in order for failover to be enabled.

For botnet testing I would suggest taking the secondary unit off line, apply the licence and test on the primary and when you are done clear the key and re-enable failover.

I hope it helps.

PK

Highlighted

Thank you very much, but how I clear the key before it expires?

Thanks

Highlighted

You can't delete a license, you can only overwrite it.  So, make sure you keep the current permanent key that you have and when done just reapply it.

Rgs,

PK

View solution in original post

Highlighted

OK, I have evaluated the Botnet Traffic Filter, and if now I want to buy the license and put into production, do I need to pay an anual license for the standby unit that it never get active?

Thanks

Highlighted

Hi JMPrats,

I have similar setup too. May I ask how did you go about doing this on a fail-over set-up?

Did you alsopaid for the botnet filter for the standby device?

Hope to hear from you soon.

Thank you.

Regards,

Novice

Highlighted

Hi, I only need one license

In Version 8.3(1) and later, failover units do not require the same license on each unit.

http://www.cisco.com/en/US/docs/security/asa/asa83/license_standalone/license_management/license.html#wp1455081

Failover License Requirements

Failover units do not require the same license on each unit.

Older versions of adaptive security appliance software required that the licenses match on each unit. Starting with Version 8.3(1), you no longer need to install identical licenses. Typically, you buy a license only for the primary unit; for Active/Standby failover, the secondary unit inherits the primary license when it becomes active. If you have licenses on both units, they combine into a single running failover cluster license.

Content for Community-Ad