05-30-2012 08:03 AM - edited 02-21-2020 06:06 PM
Solved! Go to Solution.
09-02-2015 09:28 AM
Hello!
I want to deploy a cluster of two Cisco ASA 5555-X. Cluster must accept up to 2500 connections for IPSec VPN, SSL VPN and Web (clientless) of VPN clients.
For the first ASA in cluster I want to purchase the following licences:
1. ASA-VPNS-2500 - Premium Shared VPN Server License - 2500 users
2. ASA-VPNP-5555 - Premium Shared VPN Participant License - ASA 5555-X
For the second ASA in cluster I want to purchase the following license:
1. ASA-VPNP-5555 - Premium Shared VPN Participant License - ASA 5555-X
Tell me, please, enough these licenses for above-mentioned requirements?
Thank you in advance for the answer.
09-02-2015 09:37 AM
The old license types are now end of sales.
See this announcement which confirms the last possible order date for them was 31 August 2015.
Going forward you would order AnyConnect 4.x licenses - Apex type is equivalent to the old Premium licenses. You no longer need to order the VPN Shared Server and Participant license types as you are licensed per unique user and the activation-keys can be generated for multiple ASA serial numbers - whether they are in HA, cluster or totally separate modes.
So you would need 2500 Apex licenses. They are term-based so you need to decide on 1- 3- or 5-year term and order accordingly.
09-03-2015 03:36 AM
Hello, Marvin!
Thanks for the link on Any Connect ordering guide. There everything is clearly described enough.
If it is possible, one more question. Here the quote from the ordering Guide:
"Apex and Plus licenses can be mixed in the same environment".
I correctly understand that if, for example, it is necessary to provide connection to a cluster of 100 SSL VPN users and 100 Web VPN users , I have to order for the each device in cluster 100 of the licenses Any Connect Plus and 100 licenses Any Connect Apex.
Thanks.
06-25-2014 05:36 AM
Hello Marvin,
I have ASA5510 with v8.2 with base lic, which says " IPsec VPN Peers = 250".
Does "IPsec VPN Peers" means "both site-to-site and remote access IPSec VPN client" or does it mean only site-to-site vpn?
If I want the users to connect using Any-connect client, do i need to buy extra lic or it will be utilized from =250?
If I have two Cisco ASA 5510 in HA with Security Plus lic, and one of the ASA has L-ASA-SSL-250 lic installed in it, do i need to buy L-ASA-SSL-250 for the other fail-over device or its not required? as after fail-over primary lic will be transferred to secondary unit?
Thanks in advance,
acm
06-25-2014 08:02 AM
@acm,
"IPsec VPN peers" means as you noted in your question. It does not include AnyConnect client-based remote access VPN (either SSL or IPsec IKEv2 mode).
In an HA pair, the L-ASA-SSL-250 license is only required on one member (as of ASA 8.3 or later).
06-25-2014 11:04 PM
@Marvin,
Thank you for help.... few queries though,
Please find my current ASA details in brackets:-
[System image file is "disk0:/asa825-k8.bin"
Config file at boot was "startup-config"
ASA up 53 mins 32 secs
Hardware: ASA5510, 1024 MB RAM, CPU Pentium 4 Celeron 1599 MHz
Internal ATA Compact Flash, 256MB]
1] I have ASA v8.2 - will i need 2nos. of L-ASA-SSL-250 in HA pair?
2]Should i upgrade my ASA from v8.2 to v8.3 and then buy 1qty. of L-ASA-SSL-250 ? What do you suggest?
3]While upgrading my ASA from v8.2 to v8.3(or later) will I need to upgrade my ASA RAM/FLASH? Kindly go though my ASA HW details above.
thanks in advance,
acm
06-26-2014 11:54 AM
You're welcome.
1. If you wanted to stay with 8.2 then yes you would need identical licenses purchased separately on both units.
2. I would suggest upgrading. I would skip 8.3(x) altogether. 8.4(7) or 9.0(3) are the currently recommend "most stable" releases for that platform. Reference.
3. An ASA 5510 with 1 GB of RAM can run the later versions of software (8.3 all the way through 9.1(5) - 9.2+ is not being developed for the older non-SMP hardware except the 5505). Reference.
One question - if you're adding a second 5510 is it one you have on hand already? I ask because those were end of sales since last year.
06-26-2014 10:05 PM
Hello Marvin
Yes, you are correct. We have second ASA5510 in our stock.
Thanks again for your great help.
regards,
acm
06-27-2014 07:40 AM
You're welcome. Thanks for the ratings.
08-18-2014 08:25 PM
Hello friends!
Please, allow me to resurect this old post.
Marvin, would you please explain for what the ASA-ADV-END-SEC license is used for? Also for what is the ASA5505-SEC-PL license used for?
Regards!
Alex
08-21-2014 06:38 AM
Alex,
ASA-ADV-END-SEC is used to enable the Advanced Endpoint Assessment feature. AEA allows one to inspect clients for many features and even direct them with remediation messages etc. to validate compliance with standards (OS type, patch level, antivirus status,etc.) prior to allowing network access.
SEC-PL is Security Plus and allows several things such as high availability setup etc. on an ASA-5505. The 5510 and 5512-X have an equivalent offering. All higher models have the abilities built-in to their base licenses
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide