?
Solved

Cisco ASA 5505 Licensing Question

Posted on 2014-04-30
4
Medium Priority
?
679 Views
Last Modified: 2014-05-06
Hi folks!

We are looking to purchase a Cisco ASA 5505 unit to replace our outdated Cisco PIX 515E firewall. I have a question concerning the licensing.

I see that there are different license levels based on the number of users -- 10, 50, unlimited. However, our situation is that we'll only have a handful of users inside the network making connections out through the firewall. The vast majority of our traffic is incoming to our servers from the outside (e.g. web traffic, FTP traffic, etc.).

Does that mean that we could get by with a lower number of licensed users, such as 10, or are incoming connections counted and we, therefore, need an unlimited user license?

Thanks,
Ithizar
0
Comment
Question by:Ithizar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 2000 total points
ID: 40032283
Host limits shouldn't apply to the outside interface.

Keep in mind though that the number of hosts on the inside is counted, not the number of users.
So even if you only have eight users, you might have 15 devices connection to the internet which might give you issues then.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 40032293
Also have a look at:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/license_standalone/license_management/license.html#wp1450337

Quote:
In routed mode, hosts on the inside (Business and Home VLANs) count towards the limit when they communicate with the outside (Internet VLAN), including when the inside initiates a connection to the outside as well as when the outside initiates a connection to the inside. Note that even when the outside initiates a connection to the inside, outside hosts are not counted towards the limit; only the inside hosts count. Hosts that initiate traffic between Business and Home are also not counted towards the limit. The interface associated with the default route is considered to be the outside Internet interface. If there is no default route, hosts on all interfaces are counted toward the limit. In transparent mode, the interface with the lowest number of hosts is counted towards the host limit. See the show local-host command to view host limits.
0
 

Author Comment

by:Ithizar
ID: 40032394
Thank you! That makes a lot of sense. My only other question is this:

Do you know how it treats virtual devices?

For example, if we have a VMware ESXi server that is running 3 virtual servers does that count as one device? Three devices? Four devices?

Thanks again.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 40032419
Everything that connects through the ASA is counted,  so four in worst case.
If a machine doesn't need an Internet connection,  remove the default gateway.  That should take care of it.
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month12 days, 7 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question