04-26-2018 08:10 PM - edited 03-12-2019 05:14 AM
Hi All,
Just want to know how many anyconnect Plus/Apex License do i need to buy for a FTD HA pair ?
one each anyconnect License for FTD in a HA pair, or just buy one for the FTD primary ?
Thanks!
Solved! Go to Solution.
05-03-2019 08:01 AM
Remote access VPN ("AnyConnect") on ASA can be configured to use SSL or IPsec (with IKEv2). Those both require AnyConnect licenses.
IPsec IKEv1 can be configured but it uses the legacy (long end of sales and not supported) Cisco VPN client (or a 3rd party client like Shrewsoft) .
05-06-2019 05:18 PM
Thank you so much for your answer. What about IPsec-IKEv2 with anyconnect? Can I chose only that option (no chosing SSL) for creating an anyconnect vpn profile on FTD? should I chose both SSL and IPsec-IKEv2 for anyconnect vpn works? I've been trying to do that but anyconnect client always said "connection attempt failed".
05-06-2019 07:02 PM - edited 05-21-2019 10:35 PM
Whatever transport protocol you use, it requires AnyConnect licensing on the FTD appliance.
It is possible to use IPsec IKEv2 only (albeit still with licenses); but it's generally much more challenging as some bits that we normally take for granted (such as the web portal for initial connection and client profile updates) rely on SSL/TLS and disabling that altogether makes those components non-functional.
05-21-2019 09:36 AM
Hi, Marvin
Thank you for your answer. It's more clear now.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide