cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
923
Views
0
Helpful
2
Replies

Licensing Issue on ASA

gadatiah1
Level 1
Level 1

We have (4) ASA in our environment.  From it, Two ASA, each holds the 5000 user licenses.  One is setup as primary and other one is backup.  The other (2) ASA points to primary and backup for license.  We are shutting off the primary due the site being closed.  When I take the primary license server off network, we are getting login failed message on the other (2) ASA's.  Shouldn't the backup take over, if the primary is not reachable.  Do I need need to make any modification on other (2) ASA's.

2 Replies 2

andamani
Cisco Employee
Cisco Employee

Hi,

I am not quite sure of the Licensing part you talking here.

But of what i understand. you want the RA VPN users to fall back on the secondary ASA when primary is not reachable.

If so, then you will need to configure the two ASA's in failover.

Also IPsec VPN session is not transfered when failover happens.

the user will have to reconnect and the RA VPN Connection will come up.

Hope this helps.

Regards,

Anisha

P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.

When I shut down the primary ASA I get following message on other ASA's

Shared License server inactive, License server not responding

Shared License server request failed, Reason:  server is not active.

Here's the out from Primary ASA:

Licensed features for this platform:
Maximum Physical Interfaces    : Unlimited      perpetual
Maximum VLANs                  : 250            perpetual
Inside Hosts                   : Unlimited      perpetual
Failover                       : Active/Active  perpetual
VPN-DES                        : Enabled        perpetual
VPN-3DES-AES                   : Enabled        perpetual
Security Contexts              : 2              perpetual
GTP/GPRS                       : Disabled       perpetual
SSL VPN Peers                  : 2              perpetual
Total VPN Peers                : 5000           perpetual
Shared License                 : Enabled        perpetual
  Shared SSL VPN Peers         : 5000           perpetual
AnyConnect for Mobile          : Enabled        perpetual
AnyConnect for Cisco VPN Phone : Disabled       perpetual
AnyConnect Essentials          : Disabled       perpetual
Advanced Endpoint Assessment   : Enabled        perpetual
UC Phone Proxy Sessions        : 100            perpetual
Total UC Proxy Sessions        : 100            perpetual
Botnet Traffic Filter          : Disabled       perpetual
Intercompany Media Engine      : Disabled       perpetual

This platform has an ASA 5550 VPN Premium license.
This platform is a shared license server.

license-server backup 10.40.9.42 backup-id JXXXXXXXE 
license-server secret *****
license-server refresh-interval 10
license-server enable Outside
license-server enable Inside

Here's the License info from other asa, which is where I see the error if I shut the primary server off.

Licensed features for this platform:
Maximum Physical Interfaces    : Unlimited      perpetual
Maximum VLANs                  : 250            perpetual
Inside Hosts                   : Unlimited      perpetual
Failover                       : Active/Active  perpetual
VPN-DES                        : Enabled        perpetual
VPN-3DES-AES                   : Enabled        perpetual
Security Contexts              : 2              perpetual
GTP/GPRS                       : Disabled       perpetual
SSL VPN Peers                  : 2              perpetual
Total VPN Peers                : 5000           perpetual
Shared License                 : Enabled        perpetual
AnyConnect for Mobile          : Enabled        perpetual
AnyConnect for Cisco VPN Phone : Disabled       perpetual
AnyConnect Essentials          : Disabled       perpetual
Advanced Endpoint Assessment   : Enabled        perpetual
UC Phone Proxy Sessions        : 100            perpetual
Total UC Proxy Sessions        : 100            perpetual
Botnet Traffic Filter          : Disabled       perpetual
Intercompany Media Engine      : Disabled       perpetual

This platform has an ASA 5550 VPN Premium license.


Failover cluster licensed features for this platform:
Maximum Physical Interfaces    : Unlimited      perpetual
Maximum VLANs                  : 250            perpetual
Inside Hosts                   : Unlimited      perpetual
Failover                       : Active/Active  perpetual
VPN-DES                        : Enabled        perpetual
VPN-3DES-AES                   : Enabled        perpetual
Security Contexts              : 4              perpetual
GTP/GPRS                       : Disabled       perpetual
SSL VPN Peers                  : 4              perpetual
Total VPN Peers                : 5000           perpetual
Shared License                 : Enabled        perpetual
AnyConnect for Mobile          : Enabled        perpetual
AnyConnect for Cisco VPN Phone : Disabled       perpetual
AnyConnect Essentials          : Disabled       perpetual
Advanced Endpoint Assessment   : Enabled        perpetual
UC Phone Proxy Sessions        : 200            perpetual
Total UC Proxy Sessions        : 200            perpetual
Botnet Traffic Filter          : Disabled       perpetual
Intercompany Media Engine      : Disabled       perpetual

This platform has an ASA 5550 VPN Premium license.

Here's the license server info from it:

license-server address 10.130.5.42 secret *****
license-server backup address 10.40.9.42