cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
378
Views
0
Helpful
2
Replies

ASA5515-K9 ASA5510-SEC-BUN-K9 VPN

Ahmad Khalifa
Level 1
Level 1

hi i have 10 Firewalls they are in different location all of them are supporting IPsec 250 Sessions 

to implement one into the HQ and the other 9 into the branches can i configure Site-to-Site VPN from each branch connected to the HQ i mean dose these number of Concurrent  connection to the HQ  Firewall covered by the total Number of 250 or i have to have another kind of license to the HQ Firewall.

thanks 

2 Replies 2

Adeolu Owokade
Level 1
Level 1

I believe you are covered with your current licenses. As you said, they support 250 VPN sessions which is more than enough.

The actual license includes Site-to-site IPsec and IKEv1 remote access (which is used by the legacy EasyVPN-client). So you are fine with your actual license. Only if you plan to use AnyConnect RA-VPN, then you need additional licenses.

The config will be quite easy if you need pure hub-and-spoke. For spoke-to-spoke-traffic through the hub, it is a little bit more complex. For this scenario you can consult the following document:

https://supportforums.cisco.com/document/12015091/cisco-asa-vpn-spoke-spoke-communication-hub

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: