Solved

ASA 5501 - Security Bundle License - how many concurrent users can access the internet?

Posted on 2008-06-13
9
2,036 Views
Last Modified: 2010-04-21
I have a ASA 5501 with the Security Bundle License...  How many concurrent users can access the internet?  I'm running ASA version 8.0.3 and ASDM 6.2.  
0
Comment
Question by:gopher_49
  • 5
  • 3
9 Comments
 
LVL 6

Expert Comment

by:raptorjb007
ID: 21784141
ASA5505 max concurrent connections without S+ license is 10000

Source:
Cisco ASA 5500 Series Adaptive Security Appliances Models Comparison
http://cisco.com/en/US/products/ps6120/prod_models_comparison.html
0
 

Author Comment

by:gopher_49
ID: 21784163
Does this stand true for hosts on the inside interface accessing the internet?
0
 
LVL 6

Accepted Solution

by:
raptorjb007 earned 500 total points
ID: 21784177
Connection count and hosts count are two separate entities. Each host can open many connections, however depending on your license you may be limited to 10, 50, or unlimited hosts. Host count is determined by the number of internal devices that have an open connection to the outside interface. You can enter the "show local" command to get an accurate report on the number of hosts currently with an open connection.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 

Author Comment

by:gopher_49
ID: 21784197
gotcha...  I didn't purchase an additional license for concurrent connection counts...  I'm assuming I have a 10 concurrent license..  

I have another question that pertains to the subnet on the inside interface...  I can open a new question if needed...  The inside interface address is 10.0.0.1 255.255.255.0 (this was preconfigured on the old firewall).  When creating the nat (inside) 1 10.0.0.0 255.255.255.0 rule I originally entered in nat (inside) 1 10.0.0.1 255.255.255.0 .  It stripped the '1' off of 10.0.0.1.  It mentioned that the IP address and subnet was inconsistent...  Will this still work?
0
 
LVL 16

Expert Comment

by:btassure
ID: 21784783
If you do a show version it should tell you how many hosts you can have there. Otherwise it will tell you in "About-> About ASA" in ASDM and also from the system dashboard.
0
 

Author Comment

by:gopher_49
ID: 21785472
btassure,

the show version commmand show a total of 'unlimited' for inside hosts, however, to my knowledge that only pertains to the number of host connected to the switch.  This does not pertain to concurrent hosts to access the internet from the inside interface through the specified route.  The about asa menu shows the same information that the 'show version' command does...  I'm still not 100% sure to how many concurrent users can access the internet....  By default I think it's 10, however, the version 8 ASA os doesn't state this on the release notes....  
0
 
LVL 6

Assisted Solution

by:raptorjb007
raptorjb007 earned 500 total points
ID: 21785688
In the show version command you should see an output as listed below. The "Inside Hosts" line is what describes the number of licensed hosts. This number will be 10,50, or unlimited. If unlimited there is no practical host limit other than the number connections licensed or that the hardware can handle. As explained, the inside host count is calculated based on the number of hosts on the interface connection with an active connection to the outside interface. If you have 30 computers, up to 10 can access the internet at any one time, the others would be unable to establish a connection until one of the 10 host slots are freed.
Licensed features for this platform:
Maximum Physical Interfaces  : 8
VLANs                        : 3, DMZ Restricted
Inside Hosts                 : 10
Failover                     : Disabled
VPN-DES                      : Enabled
VPN-3DES-AES                 : Enabled
VPN Peers                    : 10
WebVPN Peers                 : 2
Dual ISPs                    : Disabled
VLAN Trunk Ports             : 0
AnyConnect for Mobile        : Disabled
AnyConnect for Linksys phone : Disabled
Advanced Endpoint Assessment : Disabled
 
This platform has a Base license.

Open in new window

0
 

Author Comment

by:gopher_49
ID: 21785716
I'm showing unlimited for the number of inside hosts....  I guess I'm good to go then...  When I purchased this 5505 they had a promotion on the security bundle that gave me extra VPN connections and other security interface options..   I think one being the ability to create virtual interfaces...  Anyway, I guess I'm good to go then...  My concern was that I have 15 hosts that will be accessing the internet at all times...  I was worried that if I delopyed it I would have problems with connectivity due to licensing..  If you're sure that the inside hosts represents how many inside hosts can access the internet then I'm good to go....

Thanks!
0
 

Author Closing Comment

by:gopher_49
ID: 31467140
I spit the points for the first solution sent me in the right direction and made me understand how the licensing works and the second solution proved it and clarified it for me.  Thanks for the great support...
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
The purpose of using BGP 33 100
Cisco ASA 3 27
Install SSL certificate on Cisco ASA 5506 6 25
How do I allow multiple VLANs internet access on a Cisco ASA 5505? 8 13
Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question