Anyconnect Premium License

Answered Question
May 30th, 2012

I am looking for purchasing a license for Anyconnect Premium for the ASA5510 that run IOS 8.4. I found the following but I cannot find the description for ASA-VPNP-5510=. Is that mean unlimited users?

Premium Shared VPN Server License-500 users        ASA-VPNS-500=

Premium Shared VPN Participant License-ASA 5510                ASA-VPNP-5510=

I worked on IOS 8.2, the CSD is a separatepurchase. Is Cisco Secure Desktop included in this license? If not, what will be the part number?

I have this problem too.
0 votes
Correct Answer by Marvin Rhoads about 1 year 10 months ago

Correct - you would need L-ASA-SSL-250.

Buying that will get you an activation code which, when installed on your appliance, will change

     AnyConnect Premium Peers          : 2      perpetual

To "250" (as opposed to the default 2).

Please rate helpful posts.

  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 5 (5 ratings)
Marvin Rhoads Wed, 05/30/2012 - 13:18

The ASA-VPNS-500= and ASA-VPNP-5510= products are for a setup where you have a cluster of ASAs serving remote access browser-based (clientless) SSL VPN clients. The first item sets up your server to be able to had out licenses for 500 remote access users. The second item allows an ASA 5510 to participate in the cluster.

For more traditional remote access VPN clients (client-based SSL or IPSec VPN) you need AnyConnect (Essentials or Premium). The Premium version adds the ability to use Cisco Secure Desktop features.

Part numbers for those are:

AnyConnect Essentials:

L-ASA-AC-E-55XX= (5510 in your case)

AnyConnect Premium:

L-ASA-SSL-10, L-ASA-SSL-25, L-ASA-SSL-50, L-ASA-SSL-100, L-ASA-SSL-250, L-ASA-SSL-500, L-ASA-SSL-700, L-ASA-SSL-1000, L-ASA-SSL-2500, L-ASA-SSL-5000, or L-ASA-SSL-10K

Upgrade Part Numbers: L-ASA-SSL-10-25, L-ASA-SSL-25-50, L-ASA-SSL-50-100, L-ASA-SSL-100-250, L-ASA-SSL-100-500, L-ASA-SSL-100-750, L-ASA-SSL-100-1K, L-ASA-SSL-250-500, L-ASA-SSL-500-750, L-ASA-SSL-500-5K, L-ASA-SSL-750-1K, L-ASA-SSL-1K-2500, L-ASA-SSL-2500-5K, L-ASA-SSL-5K-10K

If you want to do Advanced Endpoint Assessment, that is an additional license - L-ASA-ADV-END-SEC - which has AnyConnect Premium as a prerequisite.

joe.ho Wed, 05/30/2012 - 13:55

Thanks for the information. I just want to double confirm. I don't want to order the wrong license. The name are too close to get confuse.

I want to get name straight because I need to get a quote for clientless and client SSL VPN.

I only have a single ASA 5510. If I want the clientless and client SSL VPN should I be listing these

AnyConnect Premium (client SSL VPN) L-ASA-SSL-250

Browser-based clientless SSL VPN     ASA-VPNS-500=

Is that all I need to get the clientless and client SSL VPN going? No additional license on top of that? Is 500 clientless SSL VPN is the minimum? Nothing less than that?

Marvin Rhoads Wed, 05/30/2012 - 14:06

AnyConnect client-based SSL VPN requires only L-ASA-AC-E-5510= for a single 5510.

Clientless (browser-based) SSL VPN requires one of the AnyConnect Premium licenses whose part numbers I listed above. They are available as the names suggest in increments of 10, 25, 50, 100 etc.

The ASA 5510 allows a maximum of 250 Anyconnect Premium clients so the 500+ licensing levels are not applicable for you.

The ASA-VPNS-500= part number is only for when you are setting up a cluster of ASAs to share licenses across multiple appliances. Typically you would only do that with larger installations thus the starting number of 500 in that scenario.

NOTE: AnyConnect Essentials and AnyConnect Premium licenses can NOT be run simultaneously on the same appliance. Once you go the Premium route you are tied to the Premium per-user licensing and the per-appliance model of Essentials is no longer an option.

joe.ho Wed, 05/30/2012 - 14:21

I understand now. I only need L-ASA-SSL-100-250 and that will give me client and clientless SSL VPN capabilites.

joe.ho Wed, 05/30/2012 - 14:25

Not to confuse people. I put the upgrade part number. I will need L-ASA-SSL-250.

Licensed features for this platform:

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 100            perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Active/Active  perpetual

VPN-DES                           : Enabled        perpetual

VPN-3DES-AES                      : Enabled        perpetual

Security Contexts                 : 2              perpetual

GTP/GPRS                          : Disabled       perpetual

AnyConnect Premium Peers          : 2              perpetual

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 250            perpetual

Total VPN Peers                   : 250            perpetual

Shared License                    : Disabled       perpetual

AnyConnect for Mobile             : Disabled       perpetual

AnyConnect for Cisco VPN Phone    : Disabled       perpetual

Advanced Endpoint Assessment      : Disabled       perpetual

UC Phone Proxy Sessions           : 2              perpetual

Total UC Proxy Sessions           : 2              perpetual

Botnet Traffic Filter             : Disabled       perpetual

Intercompany Media Engine         : Disabled       perpetual

Correct Answer
Marvin Rhoads Wed, 05/30/2012 - 14:30

Correct - you would need L-ASA-SSL-250.

Buying that will get you an activation code which, when installed on your appliance, will change

     AnyConnect Premium Peers          : 2      perpetual

To "250" (as opposed to the default 2).

Please rate helpful posts.


Login or Register to take actions

This Discussion

Posted May 30, 2012 at 8:03 AM
Replies:6 Avg. Rating:5
Views:7888 Votes:0
Categories: AnyConnect

Related Content

Discussions Leaderboard