Solved

CISCO ASA 5505 IPSEC link 2 devices to enable 50 simultaneous users

Posted on 2013-01-01
5
457 Views
Last Modified: 2013-01-03
Can I interlink a second ASA 5505 licensed for 25 IPSEC users to my existing ASA 5505 IPSEC with 25 concurrent users for a total of 50 concurrent users capacity ?

Who to contact to provide remote configuration service of the second device ?
0
Comment
Question by:am5240
5 Comments
 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 100 total points
ID: 38735419
You could potentially allow IPSec to pass through to the second ASA, and have the VPN client configured with a failover peer ip. This would require that you have 2 public IPs available.

However, there is no license linking to allow a single 5505 to have 50 IPSec connections that I'm aware of. That limit is more of a hardware thing, not just licensing.
0
 
LVL 17

Assisted Solution

by:lruiz52
lruiz52 earned 100 total points
ID: 38735506
Cisco ASA 5505 has a max limit of 25 concurrent sessions if you need more concurrent connections you need to upgrade to the ASA 5510 which has a concurrent connection limit of 250
0
 
LVL 13

Assisted Solution

by:Sandy
Sandy earned 100 total points
ID: 38735757
No, You need to upgrade the license.
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 100 total points
ID: 38735904
No (easy) way that I can think of. As said before, better upgrade the license or the device. Even if you have both devices up and running (with their own public IP), the simple fact of the default gateway for the network already gives you issues: you can only have one. So you can use the device that isn't the DG to connect to through VPN but you won't be able to get anywhere.

However......

Perhaps if the second ASA uses a separate IP range to hand out to the VPN client (which it should) you can add an additional route on your network to that range through the IP of the second ASA. That way you can use all 50 sessions, only not combined. So some users would have to connect to the first ASA's public IP and other users to the second ASA's public IP.

Depending on what your needs are exactly that might be worth giving a try.
0
 
LVL 36

Assisted Solution

by:ArneLovius
ArneLovius earned 100 total points
ID: 38736525
as per lruiz52

if you had a load balancer and were only using the SSL VPN client, you could theoretically distribute inbound traffic across both ASAs...
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now