I bought an ASA 5505 with a 10 user license to be used for maintenance purposes as a back-door entry into our network. In its intended operation there would be only 1 or 2 VPN connections from remote laptops. In testing this device, it appears to abruptly stop functioning at times. In examining the log, the following entry indicates the reason for the apparent failure:
Deny traffic for protocol 1 src outside:192.168.128.192/10
24 dst inside:192.168.128.10/0, licensed host limit of 10 exceeded.
(There are many of these log entries.)
In numerous discussions with Cisco TAC, they admit that I have indeed exceeded the 10 user license limit with only a single human user. Their short-term solution is a license upgrade which should reduce this problem. As a customer, I maintain the position that Cisco has mis-represented the capabilities of the ASA5505 with the basic 10 user license and this limitation is a design defect that should be fixed.
Am I wrong in expecting this device to service (VPN session) one or maybe two simultaneous users without limitation?