cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2263
Views
0
Helpful
2
Replies

VPN License

Echo Chan
Level 1
Level 1

Hi

We are designing a solution for our customer, they plan to connect 5 site to their main office, on the main office, they use CISCO2911, branch use CISCO1921, so my question is:

1, If I want to use IPSec VPN connect branch and main office, apart from the router, I only need to buy the Security pack, like SL-19-SEC-K9/SL-29-SEC-K9, no need to buy SL-19-DATA-K9/SL-29-DATA-K9, am I right?

2, If I want to use SSL VPN connect branch and main office, aprt from the router and SL-19-SEC-K9/SL-29-SEC-K9, I only need to buy L-FL-SSLVPN10-K9 for CISCO2911 in main office, no need to buy L-FL-SSLVPN10-K9 for branch as each CISCO1921 has two default SSL license?

Thanks very much.

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

1. Yes, you are right. You only need to buy Security pack for IPSec VPN, ie: SL-19-SEC-K9/SL-29-SEC-K9 for branch and main respectively.

2. No, if you want to SSL VPN to CISCO1921, you would also need to purchase the SSL VPN license as on the router it doesn't come with the default 2 SSL License. Only ASA firewall comes with default 2 SSL license. If you need to terminate SSL VPN on the Cisco1921, you would also need to purchase the SSL license.

You can check out Table 4 on the SSL license per platform:

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6657/product_data_sheet0900aecd80405e25.html

Hope that helps.

View solution in original post

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

1. Yes, you are right. You only need to buy Security pack for IPSec VPN, ie: SL-19-SEC-K9/SL-29-SEC-K9 for branch and main respectively.

2. No, if you want to SSL VPN to CISCO1921, you would also need to purchase the SSL VPN license as on the router it doesn't come with the default 2 SSL License. Only ASA firewall comes with default 2 SSL license. If you need to terminate SSL VPN on the Cisco1921, you would also need to purchase the SSL license.

You can check out Table 4 on the SSL license per platform:

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6657/product_data_sheet0900aecd80405e25.html

Hope that helps.

Your point 2) sounds if you want to use SSL-VPN for the site-to-site connection. That won't work. SSL can only be used for Remote-Access. Your S2S has to be build with IPSec.

Sent from Cisco Technical Support iPad App