cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1686
Views
0
Helpful
12
Replies

ASA AnyConnect License (HA setup)

Mr_Jones
Level 1
Level 1

Hi All 

 

quick question, I have added a new license to my ASA for more users to connect to the vpn (this has been added to the primary asa) - but the failover ASA is not showing the same activation key

 

am i correct in thinking once the device fails over it will show the new Activation key i added onto the primary device

 

Just to make you aware the devices are setup as HA

12 Replies 12

The secondary ASA can not show the activation-key as the key is bound to the serial-number of the primary ASA. But this is no problem as in HA, both ASAs share the licenses. Only if you want to operate the secondary ASA alone, you need to generate a new activation-key in the licensing portal based on the secondary serial-number.

Thank you for that, I got worried 

 

as a test i failed over the Firewall so the HA secondary became active but it still showed a different licence key (was worried it never migrated the licnese from the PRIMARY)

balaji.bandi
Hall of Fame
Hall of Fame


"Starting with Version 8.3(1), you do not have to have matching licenses on both units. Typically,
you buy a license only for the primary unit; the secondary unit inherits the primary license when it
becomes active"

https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/intro-license.pdf

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you, i get that

 

im running asa 9.9 (2) but when i failed over the HA and ran from the Secondary (now active) the license on show Ver hadn't updated so i was a little confused 

When the primary up and running, Secondary you do basic config, and rest all will be sync with Primary automatically.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

correct i get that - but i was under the impression that the license would show on the Secondary once its failed-over as the active connection - which it doesnt under show ver or show activation-key

Hi,

 

    It's more of a "cosmetic" bug, which i think will not be fixed, based on how the ASA licensing model started; behind the scenes though, it works as expected.

 

Regards,

Cristian Matei.

well thank you all for the confirmation :)

Agreed its not end of the world as long as it is operational and working as expected as business point of view.

 

I can understand your concern, some time cisco developpers try hard to meet the fast phase of coding, if you keen to resolve more depeth, open a Cisco TAC case (if you have smartnet contract).

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

hi All

 

just to confirm all, If im updating the license key (number of users) but have all the same features - I wont need to reload will i?

as we are getting no additional features?

yes as per the License concern yes it should work as expected after license applied (no reboot required).

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help