02-12-2003 08:49 AM - edited 02-20-2020 10:33 PM
For PIX 501, Cisco offers a Connection-based license: 10 or 100 users. What does this mean (e. g. for a 10 user license):
- a maximum of 10 xlates in the nat table?
- a maximum of 10 connections in the conn table?
If last one is true, one user might estabish 10 outbound connections (from one ip address). At this time, other users cannot establish any outboung connection?
Thanks
Edgar
Solved! Go to Solution.
02-12-2003 09:34 PM
A "user" is defined as follows:
- has sent or received traffic through the PIX in the last xlate timeout seconds (five minutes with the 501 default config).
- has a UDP or TCP connection
- has a NAT session
- has a user authentication session
It is certainly not the number of connections, but basically the number of unique internal IP addresses that have any number of connections through the PIX. The 501 will support up to around 26000 connections, but only 10 internal IP addresses could be using those.
You can do a "sho local-host" on the PIX to see all the current "users".
02-12-2003 09:34 PM
A "user" is defined as follows:
- has sent or received traffic through the PIX in the last xlate timeout seconds (five minutes with the 501 default config).
- has a UDP or TCP connection
- has a NAT session
- has a user authentication session
It is certainly not the number of connections, but basically the number of unique internal IP addresses that have any number of connections through the PIX. The 501 will support up to around 26000 connections, but only 10 internal IP addresses could be using those.
You can do a "sho local-host" on the PIX to see all the current "users".
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: