ASA AnyConnect Licensing

AID: 7569
  • Status: Published

2820 points

  • Bytomago
  • TypeFAQs
  • Posted on2011-09-12 at 12:08:05
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes.

"site-to-site" VPNs
The first are the "site-to-site" VPNs that come with all ASAs.  For the 5505, this is 10 for the base OS and 25 for the Security Plus OS.  5510s are 250, 5520s are 750, etc...  These licenses are not AnyConnect licenses.  They are restricted to IPSec only and client-wise are only compatible with the Cisco VPN Client.  

This Cisco VPN Client is the old platform from the PIX/VPN Concentrator days, so they worked for my migration.  However, a Cisco SE informed me that the Cisco VPN Client platform is EOL'd and when a hotfix/service pack is released that breaks the client, it will not be fixed.

AnyConnect Premium
At this point I started looking into the new AnyConnect platform for my user/client-based VPNs.  AnyConnect comes in two flavors.  One is AnyConnect Premium.  All ASAs comes with 2 licenses of AnyConnect Premium.  These licenses are unrestricted and allow for client-based and client-less VPNs along with some advanced security features like Endpoint Assessments and Remote Host Scans.  The AnyConnect Premium scheme is tiered.  So the licensing starts at the 2 the ASA comes with.  You can then upgrade to 10, 25, 50, 100, 250, etc... until you reach the box max.

AnyConnect Essentials
The other option in the AnyConnect world is AnyConnect Essentials.  The Essentials license is restricted to client-based only VPNs and is a direct replacement for the old Cisco VPN Client.  You cannot do anything with this license other than the IPSec or SSL based VPN connections, limited to fat-client-based VPNs.  No clientless, no advanced security features.  These Essentials licenses are platform licenses, so purchase qty 1 of the Essentials license for a 5505 would give you the box max for concurrent AnyConnect VPNs (which is 25 on a 5505).  Qty 1 of the Essentials license on a 5510 would give you 250 concurrent client-based AnyConnect VPNs, 750 on a 5520, etc....

The OS of the ASA has a software switch in the VPN config that only allows for the ASA to be in one scheme or the other at any one time so you cannot have both and Essentials and Premium license active at the same time.

I would also like to point out that with AnyConnect, you cannot connect iPads/iPhones/etc... out of the box.  All ASAs, by default, will reject a VPN request from a mobile device.  To change this, I needed to install qty 1 of the AnyConnect Mobile license.  This then allowed the VPN requests from the mobile devices to be accepted and it then pulled a VPN license from my AnyConnect license pool (either Essentials or Premium, whichever is active).  

Some of the wording in the Cisco documentation led me to believe I needed one mobile license for each mobile device, but that is NOT the case.  The mobile license is not a VPN license, it is just to allow the ASA to accept VPN requests from mobile devices.  The VPN licenses for the mobile devices were then pulled from my normal AnyConnect licensing pool (as I stated above).
Asked On
2011-09-12 at 12:08:05ID7569
Tags

ASA

,

AnyConnect

,

Licensing

,

Cisco

,

Adaptive Security Appliance

,

SSL VPN

Topic

Cisco PIX Firewall

Views
1514

Comments

Expert Comment

by: Garry-G on 2011-09-16 at 09:54:25ID: 31629

add to that the Anyconnect Mobile license, which requires at least the essentials ... this is necessary for certain features or mobile devices to get a VPN connection to the ASA ... cost is the same as for the essentials ...

Expert Comment

by: amatson78 on 2011-12-04 at 11:34:59ID: 33511

Just to clarify if I have an ASA 5505 with a base license and the stock 2 SSL VPN peers this is the Premium SSL correct? If so then for the mobile license I just need part #L-ASA-AC-M-5505= to enable my iPhone to connect?

Expert Comment

by: Garry-G on 2011-12-04 at 11:43:28ID: 33512

SSL VPN != AnyConnect !!! The 2 trial SSL VPN licenses are just for the basic SSL connect via webbrowser, not a VPN ...

Expert Comment

by: Garry-G on 2011-12-04 at 11:47:01ID: 33513

Run "show version" to get the overview over the available licenses:

Licensed features for this platform:
[..]
SSL VPN Peers                  : 2      <-- that's the trial SSL licenses
[..]
AnyConnect for Mobile          : Disabled    <-- what you want/need for your mobile clients
AnyConnect for Cisco VPN Phone : Disabled
AnyConnect Essentials          : Disabled    <-- what you need before you can use AnyConnect Mobile

Author Comment

by: tomago on 2011-12-04 at 13:58:14ID: 33515

@amatson78:  Yes, the 2 SSL VPN that come with the ASA are AnyConnect Premium.  If you only need two concurrent VPN sessions from mobile devices, all you have to do is purchase the AnyConnect mobile license and you're all set.  By default the ASA is going to look for the Essentials license so in the WebVPN config just type "no anyconnect-essentials" and it will change it from the essentials licensing scheme to the premium licensing scheme.

@Garry-G:  Incorrect, you AnyConnect mobile requires EITHER essential OR premium.  Also, the trial licenses are AnyConnect Premium and not just a "basic SSL connect".  

Expert Comment

by: amatson78 on 2011-12-04 at 14:23:14ID: 33516

@Tomago,

Awesome that is what I expected but wanted to clarify for me and anyone else who comes across this helpful article. I am only using the ASA for a lab so the 2 license are perfect I just wanted mobile access. :) I can confirm I can access the VPN via both clientless portal and the anyconnect which confirms they should be the "Premium" license included. Kudos on the guide.

Author Comment

by: tomago on 2011-12-04 at 14:30:24ID: 33517

Good to hear amatson78.  If you wanted to get started now, there is a free trial of the mobile license on the Cisco site.  http://www.cisco.com/go/license   -> sign in with your CCO ID then click on "If you do not have a PAK, please click here for Demo and Evaluation licenses."

Expert Comment

by: amatson78 on 2011-12-04 at 18:30:27ID: 33522

@ Tomago, Awesome thanks for the heads up, I did just that and have a 90 day trial license installed onto the ASA and just successfully connected to my lab from my iPhone. Thx again one of the best guides yet. :)

Add your Comment

Please Sign up or Log in to comment on this article.

Join Experts Exchange Today

Gain Access to all our Tech Resources

Get personalized answers

Ask unlimited questions

Access Proven Solutions

Search 3.2 million solutions

Read In-Depth How-To Guides

1000+ articles, demos, & tips

Watch Step by Step Tutorials

Learn direct from top tech pros

And Much More!

Your complete tech resource

See Plans and Pricing

30-day free trial. Register in 60 seconds.

Loading Advertisement...

Top Cisco PIX/ASA Experts

  1. erniebeek

    122,361

    Master

    0 points yesterday

    Profile
    Rank: Genius
  2. PeteLong

    64,083

    Master

    0 points yesterday

    Profile
    Rank: Genius
  3. fgasimzade

    54,292

    Master

    0 points yesterday

    Profile
    Rank: Wizard
  4. Kvistofta

    51,576

    Master

    0 points yesterday

    Profile
    Rank: Sage
  5. jmeggers

    37,798

    0 points yesterday

    Profile
    Rank: Sage
  6. nazsky

    36,832

    0 points yesterday

    Profile
    Rank: Wizard
  7. lruiz52

    33,783

    0 points yesterday

    Profile
    Rank: Guru
  8. MikeKane

    30,788

    0 points yesterday

    Profile
    Rank: Genius
  9. donjohnston

    29,020

    0 points yesterday

    Profile
    Rank: Genius
  10. lrmoore

    27,412

    0 points yesterday

    Profile
    Rank: Savant
  11. TimotiSt

    21,109

    0 points yesterday

    Profile
    Rank: Master
  12. The_Warlock

    20,300

    0 points yesterday

    Profile
    Rank: Wizard
  13. ArneLovius

    18,640

    0 points yesterday

    Profile
    Rank: Wizard
  14. henkva

    18,216

    0 points yesterday

    Profile
    Rank: Master
  15. ikalmar

    18,108

    10 points yesterday

    Profile
    Rank: Genius
  16. mat1458

    16,796

    0 points yesterday

    Profile
    Rank: Master
  17. harbor235

    16,375

    0 points yesterday

    Profile
    Rank: Genius
  18. jodylemoine

    16,300

    0 points yesterday

    Profile
    Rank: Sage
  19. eeRoot

    14,618

    0 points yesterday

    Profile
    Rank: Wizard
  20. max_the_king

    14,311

    0 points yesterday

    Profile
    Rank: Master
  21. kenboonejr

    14,220

    0 points yesterday

    Profile
    Rank: Sage
  22. Soulja

    14,100

    0 points yesterday

    Profile
    Rank: Genius
  23. craigbeck

    14,000

    0 points yesterday

    Profile
    Rank: Sage
  24. JZeolla

    13,975

    0 points yesterday

    Profile
  25. Netty

    12,436

    0 points yesterday

    Profile
    Rank: Guru

Hall Of Fame