Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 685
  • Last Modified:

CISCO ASA 5505 VPN license

I have a cisco ASA 5505. The vpn license is 25.. does this means the total users I can create for vpn or it's the number of max users can connect to the router through vpn during the session? And how do I upgrade the license so it can support more users?

vpn
0
okamon
Asked:
okamon
  • 5
  • 4
3 Solutions
 
MattCommented:
This means you can have up to 25 concurrent VPN sessions (aka VPN clients) at the same time. For ASA 5505 this is the maximum number allowed. See this chart:

http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/prod_brochure0900aecd80402e39.html
0
 
lruiz52Commented:
It means that you can have 25 concurrent Any Connect or Clientless VPN Sessions and 25 Concurrent Site-to-site and IPsec sessions. If you need more Sessions, you would have to upgrade your ASA to ASA5510.
0
 
okamonAuthor Commented:
thanks! if I get a new 5515 model, is it easy to carry over all my current configuration? Can I just copy and paste the configuration from the existing ASA 5505?
0
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

 
MattCommented:
No, you have to take care of port settings. 5515 has different number of ports, also which ASA SW are you running on 5505 box?

5515-X is a slightly different network animal :)
0
 
okamonAuthor Commented:
the one running on 5505 is 8.2(5). So basically I have to do it from scratch on 5515?!
0
 
MattCommented:
I think so unfortunatelly. You can have ASA 5505 config as a "template" but in reality you can't copy-paste and expect to work. 5515-X is running newer SW, SW 8.2 for example is having old style NAT configuration, everything above 8.2 has NAT completely rewritten.
0
 
okamonAuthor Commented:
Thanks Matt. Do you know if I purchase the cisco maintenance support contract, will they be able to help me to configure the new router? or it's just for troubleshooting?
0
 
MattCommented:
Uf I don't know about that, you can check but maybe it would be much easier to get local CISCO guru. You can of course ask CISCO but they Will charge you for every...

Do you have at your place any CISCO support company?
0
 
okamonAuthor Commented:
thanks Matt. If I were to get local Cisco guru (From outsourced IT), do you see if it's still necessary to buy the cisco support contract?
0
 
MattCommented:
No no, of course not. He/she will be able to help you without CISCO support contract. This you might need only if you have multiple locations with CISCO devices and you would want to make a radical change in config, for example help to upgrade ASA config from "old-NAT" style 8.2 to the newer 8.3 or higher.

If you need help only once in a time, it's just a waste of money to buy CISCO support contract and if you don't use it. The only big advantage is that you are eligible to new SW releases (if you really need it) and if you have Smartnet, you can replace faulty device for example.
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

  • 5
  • 4
Tackle projects and never again get stuck behind a technical roadblock.
Join Now