Hi Marvin,
Thanks a lot for your reply.
So in my ASA HA pair I've to activate the license only on the acitve ASA as I am running version 9.1(5)19. So to upgrade to premium license i have to do as follows-
1. Deactivate essential license
conf t
webvnp
no anyconnect-essentials
2. Activate premium licesnse.
conf t
activation-key xxxxxxxx xxxxxxxx xxxxxxxx xxxxxxxx xxxxxxxx
Also to confirm i dont need to reload to upgrade to premium anyconnect license?
could you please calrify on the above points? thanks
... View more
Hi Marvin,
Currently I have cisco ASA HA Pair with default premium license. I have got the PAK code for ASA5500-SSL-250=, but I hve been advseid that part ASA5500-SSL-250= is not eh right one for upgrading from default 2 to 250 premium vpn ayconnect. I need to buy upgrade license. Is that true? if yes what would be the part number and upgrade process from 2 to 250 premium vpn anyocnnect on this HA pair.
Could you pleaes advise which license shoudl I buy for this upgrade_
show run ffrom the ha pair-
Cisco Adaptive Security Appliance Software Version 9.1(5)19 Device Manager Version 7.2(2)
Compiled on Thu 23-Oct-14 14:14 PDT by builders System image file is "disk0:/asa915-19-smp-k8.bin" Config file at boot was "startup-config"
ahpra-syd-au-hacasa1 up 249 days 1 hour failover cluster up 349 days 5 hours
Hardware: ASA5525, 8192 MB RAM, CPU Lynnfield 2393 MHz, 1 CPU (4 cores) ASA: 4096 MB RAM, 1 CPU (1 core) Internal ATA Compact Flash, 8192MB SSL/IKE microcode : CNPx-MC-SSL-PLUS-T020 IPSec microcode : CNPx-MC-IPSEC-MAIN-0026 Number of accelerators: 1 Baseboard Management Controller (revision 0x1) Firmware Version: 2.4
Licensed features for this platform: Maximum Physical Interfaces : Unlimited perpetual Maximum VLANs : 200 perpetual Inside Hosts : Unlimited perpetual Failover : Active/Active perpetual Encryption-DES : Enabled perpetual Encryption-3DES-AES : Enabled perpetual Security Contexts : 2 perpetual GTP/GPRS : Disabled perpetual AnyConnect Premium Peers : 2 perpetual AnyConnect Essentials : 750 perpetual Other VPN Peers : 750 perpetual Total VPN Peers : 750 perpetual Shared License : Enabled perpetual AnyConnect for Mobile : Enabled perpetual AnyConnect for Cisco VPN Phone : Disabled perpetual Advanced Endpoint Assessment : Disabled perpetual UC Phone Proxy Sessions : 2 perpetual Total UC Proxy Sessions : 2 perpetual Botnet Traffic Filter : Disabled perpetual Intercompany Media Engine : Disabled perpetual IPS Module : Enabled perpetual Cluster : Enabled perpetual Cluster Members : 2 perpetual
This platform has an ASA5525 VPN Premium license.
Failover cluster licensed features for this platform: Maximum Physical Interfaces : Unlimited perpetual Maximum VLANs : 200 perpetual Inside Hosts : Unlimited perpetual Failover : Active/Active perpetual Encryption-DES : Enabled perpetual Encryption-3DES-AES : Enabled perpetual Security Contexts : 4 perpetual GTP/GPRS : Disabled perpetual AnyConnect Premium Peers : 4 perpetual AnyConnect Essentials : 750 perpetual Other VPN Peers : 750 perpetual Total VPN Peers : 750 perpetual Shared License : Enabled perpetual AnyConnect for Mobile : Enabled perpetual AnyConnect for Cisco VPN Phone : Disabled perpetual Advanced Endpoint Assessment : Disabled perpetual UC Phone Proxy Sessions : 4 perpetual Total UC Proxy Sessions : 4 perpetual Botnet Traffic Filter : Disabled perpetual Intercompany Media Engine : Disabled perpetual IPS Module : Enabled perpetual Cluster : Enabled perpetual
This platform has an ASA5525 VPN Premium license.
thanks
... View more
Hi, For configuring the management interface IP for Cisco Ironport device, should it be on the public IP address or private IP address? Could you please confirm the IP address desing for the ironport management interface? thanks arman
... View more
Hi, To connect 10 sites to head office whcih technology would be better VPLS or MPLS? I would add more sites later on and it should have voice, video and critical application qos support. I know MPLS is better than VPLS in some respect. But VPSL comes into play where its simple network VPN deployment. I am looking for suggestion about VPLS/MPLS deployment scenario and their advantages and disadvantages. regards, arman
... View more
Code version: System image file is "flash:c3750-ipservicesk9-mz.122-50.SE3/c3750-ipservicesk9-mz.122-50.SE3.bin" I don’t have any etherchannel running from the switch. It is connected to vmware machines which are on DMZ. rgds, arman
... View more
Hi, We have got cisco 3759 switch where the followign line was configrued only ip arp inspection vlan 6,100 And on those vlans no arp inspection trust was configrued. DMZ and backup servers were connected on that switch. Switch got restarted wihtin 5 minutes for the power outage and when the swithc came online it was denying all the packets coming through the vlan 100 adn 6 althought it was allowing packets before the power outage. It took me 30 minutes to find out that arp inspection was enables which might cause the issue, but I am still unsue why it would block all packets for vlan 100 & 6.After taking out the command ' ip arp inspection vlan 6,100' all started working fine. What is the reason the switch had this issue? Is there any resolution for this? thanks FYI: The error messages- 0:48:32: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Gi1/0/1, vlan 6.([001e.0b5f.3a8c/220.233.31.177/0000.0000.0000/220.233.31.182/14:48:32 AEST Sun Feb 28 1993]) 00:48:33: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Gi1/0/3, vlan 6.([000c.2915.1abe/220.233.31.184/0000.0000.0000/220.233.31.177/14:48:32 AEST Sun Feb 28 1993]) 00:48:33: %SW_DAI-4-DHCP_SNOOPING_DENY: 2 Invalid ARPs (Req) on Gi1/0/1, vlan 6.([001e.0b5f.3a8c/220.233.31.177/0000.0000.0000/220.233.31.178/14:48:33 AEST Sun Feb 28 1993]) 00:48:33: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Gi1/0/1, vlan 6.([001e.0b5f.3a8c/220.233.31.177/0000.0000.0000/220.233.31.184/14:48:33 AEST Sun Feb 28 1993]) Regards, Arman
... View more
I have just did a factory reset on this device to install form the scratch to see whether that message come up. If it doesn't show up then it would be an issue with my config. So far it looks good.
... View more
Hi Glenn, Thanks for your reply. It will be a single stand alone access point for two conference rooms only for guest access. I am planning to use either one of these Aps- Option 1- Cisco WAP4400N Wireless-N Access Point: PoE Part No. WAP4400N http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps10047/ps10051/data_sheet_c78-501857.pdf Option 2- Cisco AP 541N Wireless Access Point, Part no.AP541N-N-K9 http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps10047/ps10051/data_sheet_c78-501857.pdf I think option 1 will be cheaper than option 2? Am I right? Regards Arman
... View more