12-11-2023 05:12 AM
Hi,
We've got Cisco Firepower 1120, with standard tier licensing.
Can I use that device for remote access VPN?
We don't have Strong Encryption License purchased.
12-11-2023 05:13 AM - edited 12-11-2023 05:14 AM
@IrakliG you need to purchase AnyConnect/Secure Client license for RAVPN functionality.
12-11-2023 10:41 AM
We have Standard tier license. Does it include AnyConnect feature?
12-11-2023 01:21 PM
AnyConnect 4.x and 5.x doesn't negotiate DES anymore and it's unlikely you will want to use AnyConnect 3. Versions below AnyConnect 3.1.05187 support DES.
For ASA running on Firepower the RA VPN licensing model is trust-based, i.e. you don't install AnyConnect licenses to FP1120 running ASA. VPN is unlocked up to entire hardware capacity by default.
For FTD this is more complicated, because GUI managers impose their own restrictions. They may refuse to deploy configuration if the feature is unlicensed, although I don't want to comment on this more. @Rob Ingram can shed some more light on this. I can only mention that different parts of Cisco documentation contradict to each other.
E.g., for FMC:
There is no specific licensing for enabling Secure Firewall Threat Defense VPN, it is available by default.
You can configure remote access VPN using the Secure Client and standards-based IPSec/IKEv2.
To enable remote access VPN, you must purchase and enable one of the following licenses: Secure Client Advantage, Secure Client Premier, or Secure Client VPN Only. You can select Secure Client Advantage and Secure Client Premier if you have both licenses and you want to use them both. The Secure Client VPN Onlylicense cannot be used with Apex or Plus. The Secure Client license must be shared with the Smart Account. For more instructions, see http://www.cisco.com/c/dam/en/us/products/collateral/security/anyconnect-og.pdf.
You cannot deploy the remote access VPN configuration to the device if the specified device does not have the entitlement for a minimum of one of the specified Secure Client license types. If the registered license moves out of compliance or entitlements expire, the system displays licensing alerts and health events.
While using remote access VPN, your Smart Account must have the export controlled features (strong encryption) enabled. The threat defense requires strong encryption (which is higher than DES) for successfully establishing remote access VPN connections with Secure Clients.
You cannot deploy remote access VPN if the following are true:
Smart Licensing on the management center is running in evaluation mode.
Your Smart Account is not configured to use export-controlled features (strong encryption).
For FDM:
Your base device license must meet export requirements before you can configure remote access VPN. When you register the device, you must do so with a Smart Software Manager account that is enabled for export-controlled features. You also cannot configure the feature using the evaluation license.
In addition, you need to purchase and enable a remote access VPN license, any of the following: AnyConnect Plus, AnyConnect Apex, or AnyConnect VPN Only. These licenses are treated the same for threat defense devices, even though they are designed to allow different feature sets when used with ASA Software-based headends.
To enable the license, select Device > Smart License > View Configuration, then select the appropriate license in the RA VPN License group. You need to have the license available in your Smart Software Manager account. For more information about enabling licenses, see Enabling or Disabling Optional Licenses.
For more information, see the Cisco AnyConnect Ordering Guide, http://www.cisco.com/c/dam/en/us/products/collateral/security/anyconnect-og.pdf. There are also other data sheets available on http://www.cisco.com/c/en/us/products/security/anyconnect-secure-mobility-client/datasheet-listing.html.
12-12-2023 05:42 AM - edited 12-12-2023 05:43 AM
Standard tier license does not include AnyConnect.
You must have your system smart licensed using a token that is enabled for Strong encryption (this is just an option when registering, not a purchased license). That applies to either FTD or ASA on Firepower hardware. You then add on the AnyConnect license - via the GUI for FTD (either FMC, FDM or CDO) or via the cli for ASA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide