Solved

Cisco ASA 5505 Security Bundle SSL VPN Licenses

Posted on 2013-10-28
3
1,226 Views
Last Modified: 2013-10-29
I was wondering if anyone knew the details of the licensing for the Cisco ASA 5505 with the security bundle.  

What I am asking in particular is if the SSL VPNs that come with it (Cisco states 2 SSL VPN peers) can be used by a multitude of users, but if the firewall will accept any two users concurrently.  Or is it license or certificate based and can only be installed on two machines (mobile or whatever)

Thanks!
0
Comment
Question by:adrienne73
3 Comments
 
LVL 18

Assisted Solution

by:fgasimzade
fgasimzade earned 50 total points
ID: 39608353
2 SSL VPN license means 2 concurrent connections
0
 
LVL 61

Accepted Solution

by:
btan earned 300 total points
ID: 39608490
For Cisco ASA 5505, any security bundle [1] example such as ASA5505-SEC-BUN-K9, it simply means 10 IPSec VPN peers and 2 SSL VPN peers. The 2 SSL VPN peers mean 2 concurrent SSL VPN connections (AnyConnect or Clientless/Webvpn).

 If you need more SSL VPN concurrent users, then you can add on with either ASA5500-SSL-10 or ASA5500-SSL-25 (max). Understand [2] for 5505, its Maximum concurrent AnyConnect or clientless VPN sessions and Maximum concurrent site-to-site and IPsec IKEv1 VPN sessions are both 25


[1] http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80402e36.html
[2] http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80402e39.html

In short, the base default is 2 x concurrent users to ASA at any one time.
Below are note for the limit description for info on IPSEC as well as SSL VPN

e.g.  The total concurrent IPsec and SSL (clientless and tunnel-based) VPN sessions may not exceed the maximum concurrent IPsec session count.

e.g. The SSL/IPsec IKEv2 VPN session number (clientless or AnyConnect client) may also not exceed the number of licensed sessions on the device.
0
 

Author Closing Comment

by:adrienne73
ID: 39609267
I had to award the first answer with points, since my question was answered, but the second answer was very comprehensive, therefore more helpful.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now