05-08-2011 06:27 PM
We have (4) ASA in our environment. From it, Two ASA, each holds the 5000 user licenses. One is setup as primary and other one is backup. The other (2) ASA points to primary and backup for license. We are shutting off the primary due the site being closed. When I take the primary license server off network, we are getting login failed message on the other (2) ASA's. Shouldn't the backup take over, if the primary is not reachable. Do I need need to make any modification on other (2) ASA's.
05-08-2011 10:43 PM
Hi,
I am not quite sure of the Licensing part you talking here.
But of what i understand. you want the RA VPN users to fall back on the secondary ASA when primary is not reachable.
If so, then you will need to configure the two ASA's in failover.
Also IPsec VPN session is not transfered when failover happens.
the user will have to reconnect and the RA VPN Connection will come up.
Hope this helps.
Regards,
Anisha
P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.
05-09-2011 06:21 AM
When I shut down the primary ASA I get following message on other ASA's
Shared License server inactive, License server not responding
Shared License server request failed, Reason: server is not active.
Here's the out from Primary ASA:
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 250 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
VPN-DES : Enabled perpetual
VPN-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
GTP/GPRS : Disabled perpetual
SSL VPN Peers : 2 perpetual
Total VPN Peers : 5000 perpetual
Shared License : Enabled perpetual
Shared SSL VPN Peers : 5000 perpetual
AnyConnect for Mobile : Enabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
AnyConnect Essentials : Disabled perpetual
Advanced Endpoint Assessment : Enabled perpetual
UC Phone Proxy Sessions : 100 perpetual
Total UC Proxy Sessions : 100 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
This platform has an ASA 5550 VPN Premium license.
This platform is a shared license server.
license-server backup 10.40.9.42 backup-id JXXXXXXXE
license-server secret *****
license-server refresh-interval 10
license-server enable Outside
license-server enable Inside
Here's the License info from other asa, which is where I see the error if I shut the primary server off.
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 250 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
VPN-DES : Enabled perpetual
VPN-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
GTP/GPRS : Disabled perpetual
SSL VPN Peers : 2 perpetual
Total VPN Peers : 5000 perpetual
Shared License : Enabled perpetual
AnyConnect for Mobile : Enabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
AnyConnect Essentials : Disabled perpetual
Advanced Endpoint Assessment : Enabled perpetual
UC Phone Proxy Sessions : 100 perpetual
Total UC Proxy Sessions : 100 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
This platform has an ASA 5550 VPN Premium license.
Failover cluster licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 250 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
VPN-DES : Enabled perpetual
VPN-3DES-AES : Enabled perpetual
Security Contexts : 4 perpetual
GTP/GPRS : Disabled perpetual
SSL VPN Peers : 4 perpetual
Total VPN Peers : 5000 perpetual
Shared License : Enabled perpetual
AnyConnect for Mobile : Enabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
AnyConnect Essentials : Disabled perpetual
Advanced Endpoint Assessment : Enabled perpetual
UC Phone Proxy Sessions : 200 perpetual
Total UC Proxy Sessions : 200 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
This platform has an ASA 5550 VPN Premium license.
Here's the license server info from it:
license-server address 10.130.5.42 secret *****
license-server backup address 10.40.9.42
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide