Solved

Cisco ASA 5505 host license limit workaround and dhcp lease time

Posted on 2014-01-12
6
2,999 Views
Last Modified: 2014-01-18
We have a Cisco ASA 5505 with a 10 host license. For several years this tiny home office didn't need more than that. But, being in a home office, the number of business hosts as well as the family's personal inventory of smart devices (tablets, phones, smart TVs) has exceeded the host limit. The business runs on Windows SBS 2008 and we currently have an Engenius wireless access point but also have other wireless routers we could deploy.

My first question is simply this: how do I get the ASA to open up unused host connections when devices have left the building or been turned off? It seems like the machine keeps some connections a long time, even when the device has been shutdown. Is this related to DHCP lease times? If so, do I just need to shorten the lease time to something like 600 seconds (10 minutes)?

Will a short lease time create excessive overhead traffic?

The second question is: Should I set up a separate home network on another wireless router and use NAT to keep that traffic on a single address going to the ASA since it generally should not need to see any of the business LAN devices? We have a Comcast business Internet gateway, so maybe I can just plug that other router straight into the cable modem... guess I better look at the box and see if it has more LAN ports for that.
0
Comment
Question by:Shannon Mollenhauer
  • 3
  • 3
6 Comments
 
LVL 50

Expert Comment

by:Don Johnston
ID: 39774840
Had the exact same issue with my 10 user license ASA. Those personal wireless devices add up fast!  :-)

I ended up getting a 50 user license.

But in the interm, I created a separate wireless network that NATed to the ASA. So all wireless devices only counted as one device as far as the ASA was concerned.  

IIRC, the command to clear an existing connection is "clear local-host <ip address>".
0
 

Author Comment

by:Shannon Mollenhauer
ID: 39774999
Thanks for the suggestion. I'm not going to be using CLI repeatedly, but I'll use the clear command to test the release of connections. I'd still appreciate anyone's advice on whether the dhcp lease time being much shorter will accomplish the same clearing effect.
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 39775008
Oh... Sorry. I didn't see where you were going with the DHCP lease idea.

I don't think that's going to help since the DHCP table is separate from the connection table.
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 

Author Comment

by:Shannon Mollenhauer
ID: 39791269
We ended up putting a cheap netgear wireless router on another port on the Comcast gateway and moving non-business devices to that network. Still evaluating whether to upgrade the licenses on the Cisco ASA, replace it, or keep things as-is. Shortened lease time might have helped the ASA recognize that a device has been off the network for a while and not actively using a connection, but I can't verify that with my limited knowledge of the device. Closing the question for now.
0
 

Author Comment

by:Shannon Mollenhauer
ID: 39791356
I've requested that this question be closed as follows:

Accepted answer: 0 points for smollenhauer's comment #a39791269

for the following reason:

Suggestions by others didn't answer the original question. Workaround in place for now.
0
 
LVL 50

Accepted Solution

by:
Don Johnston earned 250 total points
ID: 39791350
I believe that I answered both questions.

Changing the DHCP lease will not affect the connection table.  And adding a second network using NAT will reduce the number of connections against the license.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question