cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3745
Views
10
Helpful
9
Replies

Issue with ASDM and ASA5506 w/o 3DES/AES license

saiiven07
Level 1
Level 1

Hi,

I'm trying to figure out which versions of ASA and ASDM software will allow me to successfully launch ASDM on my PC taking into account that the ASA doesn't have a 3DES/AES license. At the moment I'm running 9.7(1)4 on ASA 5506 with ASDM asdm-771.bin. I've already tried almost all Java versions and even 1.6 versions of JAVA just hang with the message "Software update completed" and then nothing happens. It seems like I'll have to downgrade ASA/ASDM software to make it work. Has anyone encountered such an issue and which versions of ASA/ASDM/Java you would recommend? Thanks.

1 Accepted Solution

Accepted Solutions

No smartnet is required for this license. Just the ASA serial number and access to the software.cisco.com portal to enter in the serial number and get the PAK back.

View solution in original post

9 Replies 9

Marvin Rhoads
Hall of Fame
Hall of Fame

Unless you are working in an export-controlled region there's no reason not to install and use the free 3DES-AES license.

 

The problem is that the Java SSL libraries that are required by any modern ASDM version will not negotiate a common cipher with an ASA that does not support at least 3DES encryption as what is proposed by the ASA will have no overlap with the proposal from the client. 

Hi, Marvin.
Unfortunately, since I'm preparing the ASA for a customer, I'm not able to tie the AES/3DES license to the device because the SMARTnet contract is not associated with my account, etc. I'll probably try to downgrade or finish configuring it by using the console/SSH. Thanks for the advice regarding the free AES/3DES license.

No smartnet is required for this license. Just the ASA serial number and access to the software.cisco.com portal to enter in the serial number and get the PAK back.


Where specifically do you go once you're logged into the software central page? Every "PAK" based option i go to or licensing tells me i require a smartnet account.

You don't need Smartnet but you do need a cisco.com account.

Go to https://software.cisco.com and log in. Then click License > Traditional Licensing. Then click Licenses > Get Licenses > "IPS, Crypto or Other". Choose "Security Products" and then "Cisco ASA 3DES/AES License". Click "Next", provide your serial number and the "Next" again.

They will email you an  activation key and also provide the opportunity to download it directly from there.

does this license still exist? as it appears to be missing now.

You can find it, just type 3DES and should appear.

@lcc I just checked and it it still there.

3DES-AES license.PNG

Review Cisco Networking for a $25 gift card