04-06-2010 03:19 PM - last edited on 03-25-2019 05:44 PM by ciscomoderator
Hello,
Recently, I have bougth a bundle of ASA5540 with licence vpn premium and i checked two ASAs and i found this:
In the version 7.0
First ASA5540
show version
Cisco Adaptive Security Appliance Software Version 7.0(7)
Device Manager Version 5.0(7)
Compiled on Fri 06-Jul-07 10:37 by builders
System image file is "disk0:/asa707-k8.bin"
Config file at boot was "startup-config"
ciscoasa up 35 secs
Hardware: ASA5540, 1024 MB RAM, CPU Pentium 4 2000 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xffe00000, 1024KB
Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
Boot microcode : CNlite-MC-Boot-Cisco-1.2
SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.04
0: Ext: GigabitEthernet0/0 : address is 001d.a22c.6e58, irq 9
1: Ext: GigabitEthernet0/1 : address is 001d.a22c.6e59, irq 9
2: Ext: GigabitEthernet0/2 : address is 001d.a22c.6e5a, irq 9
3: Ext: GigabitEthernet0/3 : address is 001d.a22c.6e5b, irq 9
4: Ext: Management0/0 : address is 001d.a22c.6e5c, irq 11
5: Int: Not used : irq 11
6: Int: Not used : irq 5
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited
Maximum VLANs : 200
Inside Hosts : Unlimited
Failover : Active/Active
VPN-DES : Enabled
VPN-3DES-AES : Enabled
Security Contexts : 2
GTP/GPRS : Disabled
VPN Peers : 5000
This platform has an ASA 5540 VPN Premium license.
Serial Number: xxxxxxxx
Running Activation Key: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Configuration register is 0x1
Configuration has not been modified since last system restart.
Second ASA5540
Cisco Adaptive Security Appliance Software Version 7.0(8)
Device Manager Version 5.0(8)
Compiled on Sat 31-May-08 23:48 by builders
System image file is "disk0:/asa708-k8.bin"
Config file at boot was "startup-config"
ciscoasa up 2 mins 24 secs
Hardware: ASA5540, 1024 MB RAM, CPU Pentium 4 2000 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xffe00000, 1024KB
Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
Boot microcode : CNlite-MC-Boot-Cisco-1.2
SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.05
0: Ext: GigabitEthernet0/0 : address is 001d.70df.312c, irq 9
1: Ext: GigabitEthernet0/1 : address is 001d.70df.312d, irq 9
2: Ext: GigabitEthernet0/2 : address is 001d.70df.312e, irq 9
3: Ext: GigabitEthernet0/3 : address is 001d.70df.312f, irq 9
4: Ext: Management0/0 : address is 001d.70df.3130, irq 11
5: Int: Not used : irq 11
6: Int: Not used : irq 5
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited
Maximum VLANs : 200
Inside Hosts : Unlimited
Failover : Active/Active
VPN-DES : Enabled
VPN-3DES-AES : Disabled
Security Contexts : 2
GTP/GPRS : Disabled
VPN Peers : 5000
This platform has an ASA 5540 VPN Premium license.
Serial Number: xxxxxxxxxxxxxxxx
Running Activation Key: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Configuration register is 0x1
Configuration has not been modified since last system restart.
When i upgrade
In the version 8.0
First ASA5540
Cisco Adaptive Security Appliance Software Version 8.0(5)
Device Manager Version 6.2(5)53
Compiled on Mon 02-Nov-09 21:22 by builders
System image file is "disk0:/asa805-k8.bin"
Config file at boot was "startup-config"
ciscoasa up 1 min 46 secs
Hardware: ASA5540, 1024 MB RAM, CPU Pentium 4 2000 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xffe00000, 1024KB
Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
Boot microcode : CN1000-MC-BOOT-2.00
SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.05
0: Ext: GigabitEthernet0/0 : address is 001d.a22c.6e58, irq 9
1: Ext: GigabitEthernet0/1 : address is 001d.a22c.6e59, irq 137
2: Ext: GigabitEthernet0/2 : address is 001d.a22c.6e5a, irq 9
3: Ext: GigabitEthernet0/3 : address is 001d.a22c.6e5b, irq 9
4: Ext: Management0/0 : address is 001d.a22c.6e5c, irq 11
5: Int: Not used : irq 11
6: Int: Not used : irq 5
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited
Maximum VLANs : 200
Inside Hosts : Unlimited
Failover : Active/Active
VPN-DES : Enabled
VPN-3DES-AES : Enabled
Security Contexts : 2
GTP/GPRS : Disabled
VPN Peers : 5000
WebVPN Peers : 2
AnyConnect for Mobile : Disabled
AnyConnect for Linksys phone : Disabled
Advanced Endpoint Assessment : Disabled
UC Proxy Sessions : 2
This platform has an ASA 5540 VPN Premium license.
Serial Number: xxxxxxxxxxxxxxx
Running Activation Key: xxxxxxxxxxxxxxxxxxxxxxxxxx
Configuration register is 0x1
Configuration last modified by enable_15 at 07:58:19.609 UTC Tue Apr 6 2010
Second ASA5540
Cisco Adaptive Security Appliance Software Version 8.0(5)
Device Manager Version 6.2(5)53
Compiled on Mon 02-Nov-09 21:22 by builders
System image file is "disk0:/asa805-k8.bin"
Config file at boot was "startup-config"
ciscoasa up 58 secs
Hardware: ASA5540, 1024 MB RAM, CPU Pentium 4 2000 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xffe00000, 1024KB
Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
Boot microcode : CN1000-MC-BOOT-2.00
SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.05
0: Ext: GigabitEthernet0/0 : address is 001d.70df.312c, irq 9
1: Ext: GigabitEthernet0/1 : address is 001d.70df.312d, irq 9
2: Ext: GigabitEthernet0/2 : address is 001d.70df.312e, irq 9
3: Ext: GigabitEthernet0/3 : address is 001d.70df.312f, irq 9
4: Ext: Management0/0 : address is 001d.70df.3130, irq 11
5: Int: Not used : irq 11
6: Int: Not used : irq 5
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited
Maximum VLANs : 200
Inside Hosts : Unlimited
Failover : Active/Active
VPN-DES : Enabled
VPN-3DES-AES : Disabled
Security Contexts : 2
GTP/GPRS : Disabled
VPN Peers : 5000
WebVPN Peers : 2
AnyConnect for Mobile : Disabled
AnyConnect for Linksys phone : Disabled
Advanced Endpoint Assessment : Disabled
UC Proxy Sessions : 2
This platform has an ASA 5540 VPN Premium license.
Serial Number: JMX1232L228
Running Activation Key: 0x25125461 0x20eec438 0x20a381e4 0xa1fc2c70 0x4f1aa8b1
Configuration register is 0x1
This is a problem or the bundlen is OK? or I have to create the case in TAC? and i want to configure failover, will have any problem with this configuration?
Best Regards
04-06-2010 04:43 PM
License needs to be the same if you are going to run them in failover pair. You can get the 3DES license online, or alternatively you can contact the licensing team who can cut you the activation key for 3DES license.
04-06-2010 05:05 PM
Go to this link: https://tools.cisco.com/SWIFT/Licensing/PrivateRegistrationServlet?DemoKeys=Y
click on Cisco ASA 3DES/AES License
Fill in your info. and provide the serial number of this ASA that does not have VPN 3DES license.
-KS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide