×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

2x ASA 5510 -> Active/Standby Failover = 2x Licenses?

Answered Question
Apr 18th, 2012
User Badges:

Hello everybody,


something is confusing me;

i red that you need only one L-ASA5510-SEC-PL for setting up a Active/Standby Failover.

I installed the license on the 1st ASA and tried to setup the failover via the ASDM wizard.

It always fails, because the 2nd device can't have a 'base' license.


So does this mean, i really need another license?


Thanks for the conclusion.

Correct Answer by varrao about 5 years 4 months ago

Hi,


Yes you would need another security plus license for the standby unit, just to enable failover license on it. The rest of the features on the ASA can be different on the two devices, as in number of contexts, VPN peers, annyconnect mobile. These things can be different on the two boxes. And this features is only available on post 8.3 versions.


In pre 8.3, you needed to have the exact same license and features on the two ASA's, which is not the case in your issue. Licensing can be a bit difficult to understand but you can get all the information regarding your setup in this doc:


http://packetpushers.net/cisco-asa-licensing-explained/


http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.html#wp460665



Hope that helps.


Thanks,

Varun

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
varrao Wed, 04/18/2012 - 23:29
User Badges:
  • Red, 2250 points or more

Hi,


Yes, on both the ASA's you would need the exact same licenses, if you are using software version pre ASA 8.3, here are the failover requirements:


http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml



If you are using ASA version 8.3 or higher, then follow these requirements:

http://www.cisco.com/en/US/docs/security/asa/asa83/license_standalone/license_management/license.html#wp1455081



Hope that helps.


Thanks,

Varun

kakados2000 Wed, 04/18/2012 - 23:32
User Badges:

Alright, but why do i get an error message then?

The devices are on 8.4.

And what is this sentence about->

"For the ASA 5505 and 5510 adaptive security appliances, both units require the Security Plus license; the Base license does not support failover, so you cannot enable failover on a standby unit that only has the Base license."

kakados2000 Thu, 04/19/2012 - 01:03
User Badges:

Im sorry, but then it means i need another license right? i cannot share it? For me, this makes absolutely no sense.

Correct Answer
varrao Thu, 04/19/2012 - 01:24
User Badges:
  • Red, 2250 points or more

Hi,


Yes you would need another security plus license for the standby unit, just to enable failover license on it. The rest of the features on the ASA can be different on the two devices, as in number of contexts, VPN peers, annyconnect mobile. These things can be different on the two boxes. And this features is only available on post 8.3 versions.


In pre 8.3, you needed to have the exact same license and features on the two ASA's, which is not the case in your issue. Licensing can be a bit difficult to understand but you can get all the information regarding your setup in this doc:


http://packetpushers.net/cisco-asa-licensing-explained/


http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.html#wp460665



Hope that helps.


Thanks,

Varun

Actions

This Discussion