Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Do I need a Security Plus license on my ASA for multiple external IP's?

Posted on 2009-07-08
5
437 Views
Last Modified: 2012-05-07
I have a client who wants to upgrade from their basic license on their ASA 5505 so that they can have multiple External IP's.

I wasn't sure if this was necessary(cisco doesn't list anything like that in their side by side comparison). Can someone clarify?
0
Comment
Question by:swrighthm
5 Comments
 
LVL 1

Accepted Solution

by:
ForsakenSA earned 150 total points
ID: 24808351
Cisco ASA 5505 Security Plus license provides stateless Active/Standby high availability, dual ISP support, DMZ support, VLAN trunking support, and increased session and IPSec VPN peer capacities.
0
 
LVL 9

Assisted Solution

by:Donboo
Donboo earned 100 total points
ID: 24808802
If you mean multiple external IP as in IP addresses from2 different ISP then yes else no.
0
 
LVL 1

Assisted Solution

by:ForsakenSA
ForsakenSA earned 150 total points
ID: 24808839
Agreed, as if they are coming from same ISP, the routing will be the same.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 24810033
Like everyone above is saying,
If they are getting multiple IP addresses from the same ISP, then they do not need the upgrade.
If they are getting IP addresses from multiple ISP's, then yes, they need the upgrade.
0
 
LVL 7

Expert Comment

by:Boilermaker85
ID: 24813357
Perhaps what the original question is asking is this:

Can the ASA 5505 be configured with an interface IP, and also proxy arp for additional IPs associated with Static statements. Ie., when you want to expose an internal web server, you create these:
static (inside,outside) outside_ip inside_ip netmask 255.255.255.255
access-list acl_outside_in permit tcp any host outside_ip eq www
The ASA will now accept connections on port 80 to the outside_ip, which is in the same subnet as the ASA outside interface IP, but the ASA translates the sessions to the internal IPs. Now an ASA is using multiple IPs on the outside interface.  (note, you must have a subnet assigned to you from your ISP that you can use the addl addresses for these Static statements)
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question