07-13-2020 01:16 PM
Seeking guidance on an ASA licensing concern. Currently a customer of mine has an RA VPN solution utilizing two 5555-X ASAs that are already paired in HA. New licenses were recently acquired and need to be installed. There has been back and forth with TAC on the process. I was advised that the following process would work:
Login to primary
Break HA (no failover)
Activate lic key
Login to standby
Activate lic key
Back to primary
Enable HA (failover)
Test & confirm
I was also advised that this will result in no service interruption. However, it was also mentioned that we "may" need to reboot. I will be on site for this task in case there are any emergency issues with the RA VPN since most are teleworking. Can anyone confirm the process to activate the new licenses on each ASA while they are already paired in HA or provide suggestions if there is an easier way. Thanks in advance!!
Solved! Go to Solution.
07-14-2020 11:57 AM
I have nevery encountered this particular scenario, but I do not foresee an issue when the time-based license expires. You can deactivate the time-based license by adding the "deactivate" keyword at the end of the activation-key command.
show activation-key
activation-key xxxxx deactivate !(replace xxxxx with the actual key)
You can deactivate the time-based key and then issue a show version on the standby unit. If you want to test, perform a failover to the standby unit.
https://www.ciscopress.com/articles/article.asp?p=2209314&seqNum=2
07-13-2020 01:45 PM - edited 07-13-2020 01:49 PM
What license are you going to install?
And what ASA version are you running?
07-13-2020 01:58 PM
07-13-2020 02:08 PM
If you are only adding the AnyConnect license then I do not understand why TAC suggested to break the HA pair.
You need to only add the license to the primary active ASA and the license will sync to the standby. I suggest having a service window for this change, however, there should not be any noticable impact on the users. I have never had to do a restart of an ASA when adding an AnyConnect license, but there is a first time for everything.
07-13-2020 07:14 PM
My experience matches that of @Marius Gunnerud . I've installed over a hundred AnyConnect license activation keys over the years and never had to touch the HA configuration or reboot.
In ha the licenses sync but f you want to have an independent key on the Secondary unit you can also use your PAK to get an activation-key for it as well.
07-14-2020 05:48 AM
07-14-2020 10:52 AM - edited 07-14-2020 11:01 AM
Adding additional info: TAC recently changed their original response as I think there was confusion between us. They claim that once the temporary lic expires the secondary unit will consume the permanent key and there will be no issues. Can you confirm this? Lastly, is there any way to confirm this is true prior to expiration? Would a force failover trigger the activation of the new key on the standby unit? Can I manually remove the current temp lic on the standby unit? TIA
07-14-2020 11:57 AM
I have nevery encountered this particular scenario, but I do not foresee an issue when the time-based license expires. You can deactivate the time-based license by adding the "deactivate" keyword at the end of the activation-key command.
show activation-key
activation-key xxxxx deactivate !(replace xxxxx with the actual key)
You can deactivate the time-based key and then issue a show version on the standby unit. If you want to test, perform a failover to the standby unit.
https://www.ciscopress.com/articles/article.asp?p=2209314&seqNum=2
07-15-2020 06:32 AM
@Marius Gunnerud thanks for the additional info. The deactivation as you suggested of the temp license worked as expected and now both units are running the new licenses! Thanks for the assistance.
07-13-2020 02:11 PM
Some documentation if you want to read:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide