03-25-2019 04:56 AM
Hi there,
I have two ASA 5525-X running as active/standby failover. AnyConnect works ok when connecting from laptops but If we try to connect with a smartphone we get a message indicating that the security gateway has rejected the communication attempt because there is no license.
This is my config:
Licensed features for this platform: Maximum Physical Interfaces : Unlimited perpetual Maximum VLANs : 200 perpetual Inside Hosts : Unlimited perpetual Failover : Active/Active perpetual Encryption-DES : Enabled perpetual Encryption-3DES-AES : Enabled perpetual Security Contexts : 2 perpetual Carrier : Disabled perpetual AnyConnect Premium Peers : 2 perpetual AnyConnect Essentials : Disabled perpetual Other VPN Peers : 750 perpetual Total VPN Peers : 750 perpetual AnyConnect for Mobile : Disabled perpetual AnyConnect for Cisco VPN Phone : Disabled perpetual Advanced Endpoint Assessment : Disabled perpetual Shared License : Disabled perpetual Total TLS Proxy Sessions : 2 perpetual Botnet Traffic Filter : Disabled perpetual IPS Module : Disabled perpetual Cluster : Enabled perpetual Cluster Members : 2 perpetual This platform has an ASA5525 VPN Premium license. Failover cluster licensed features for this platform: Maximum Physical Interfaces : Unlimited perpetual Maximum VLANs : 200 perpetual Inside Hosts : Unlimited perpetual Failover : Active/Active perpetual Encryption-DES : Enabled perpetual Encryption-3DES-AES : Enabled perpetual Security Contexts : 4 perpetual Carrier : Disabled perpetual AnyConnect Premium Peers : 4 perpetual AnyConnect Essentials : Disabled perpetual Other VPN Peers : 750 perpetual Total VPN Peers : 750 perpetual AnyConnect for Mobile : Disabled perpetual AnyConnect for Cisco VPN Phone : Disabled perpetual Advanced Endpoint Assessment : Disabled perpetual Shared License : Disabled perpetual Total TLS Proxy Sessions : 4 perpetual Botnet Traffic Filter : Disabled perpetual IPS Module : Disabled perpetual Cluster : Enabled perpetual This platform has an ASA5525 VPN Premium license.
I need to buy a license but honestly I haven't been able to figure out exactly which I need. Which part number do I need to enable the AnyConnect VPN from mobiles? Do I need to buy two licenses (one for each Firewall) or just only one is enough?
I know there are two models:
AnyConnect PLUS on a per-user basis and VPN-Only. I would go for the first one but I am not sure if I only need the AnyConnect PLUS license or any other (because on the show version command it indicates the lack of a "mobile license").
Thanks in advance.
03-25-2019 05:49 AM
Hi,
"AnyConnect mobile" license needs to be combined with either the AnyConnect Essential license or AnyConnect Premium license.
Regards,
Deepak Kumar
03-26-2019 09:26 AM
AnyConnect for Mobile as a separate license is end of sales. (even though it does show up in "show version") It was deprecated as of the introduction of AnyConnect 4.x several years ago.
The current AnyConnect 4.x license types (VPN only, Plus and Apex; term or perpetual) all include the AnyConnect for Mobile feature.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide