04-20-2020 08:13 AM
Dear All,
I obtained a "AnyConnect Plus/Apex(ASA) Demo License and Emergency COVID-19 Security Appliance activation key". I activated this key on my ASA 5505 and it shows the right number of (time limited) AnyConnect licenses. However if more than 2 users try to connect, the 3rd connection fails. Debug aaa shim states "license limit reached 2" and "Error failed to update license"
output of show activation key says that 25 connections are licenced.
Whats wrong and what else can I check?
Thanks in advance
Peer
Licensed features for this platform:
Maximum Physical Interfaces : 8 perpetual
VLANs : 3 DMZ Restricted
Dual ISPs : Disabled perpetual
VLAN Trunk Ports : 0 perpetual
Inside Hosts : 50 perpetual
Failover : Disabled perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
AnyConnect Premium Peers : 25 74 days
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 10 perpetual
Total VPN Peers : 25 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Enabled 74 days
AnyConnect for Cisco VPN Phone : Enabled 74 days
Advanced Endpoint Assessment : Enabled 74 days
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
Cluster : Disabled perpetual
Output of debug AAA shim while open the 3rd connection:
AAA/SHIM: creating new ctx
AAA/SHIM: Created context
AAA/SHIM: Lookup ctx
AAA/SHIM: caller sleeping
AAA/SHIM: Fiber started
AAA/SHIM: handle open success
AAA/SHIM: build request attributes
AAA/SHIM: authenticating testuser, tgroup=DefaultWEBVPNGroup
AAA/SHIM: AAA response=ACCEPT
AAA/SHIM: license limit reached 2
AAA/SHIM: Error failed to update license
AAA/SHIM - fc: wakeup caller
AAA/SHIM: Request End
AAA/SHIM: closing session
AAA/SHIM: closed handle
04-20-2020 11:01 AM - edited 04-20-2020 11:06 AM
04-21-2020 12:51 AM
04-21-2020 01:58 AM
dont you have a support contract with cisco? ASA software for 5505 9.1.7 is interim 2018 worth trying it.
if you do not have a support contract with cisco as your cisco gold partner or cisco representative they will help you on this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide