Cisco ASA Anyconnect licensing for dummies, updated!

The picture below should be self-explaining. Click it for a larger version.

Edit 2014: There was some errors in the logics around AEA-licenses. The picture below is now corrected. Please do not use the old version (v1.1).

ASA-licensing

 

Let me explain this.

 

First of all, Advanced Endpoint Assessment (AEA) is a feature where you can do advanced posture checks and remediations with AnyConnect. AEA can check if your antivirus is enabled, and if not enable it, verify if the clients software firewall is installed and enabled and other advanced remediation thingies. I have never used it and if you are not certanly sure you don´t need this license. But if you do you need to continue on the Anyconnect Premium track. No Essentials license for you, my friend.

 

So. The big question is: Premium licenses or Essentials? The big (simplified) answer is: do you want to use the “clientless” portal? This requires premium licenses and cannot be used if you have “anyconnect essentials” configured (which in turn require the essentials license, see below).

So, let´s say that you need premium licenses. These comes in chunks of concurrent users from 2 to 10, 25, 50 and so on. These are not additative. If you have 2 you can go to the fixed steps of 10, 25, 50 and so on. If you have 25 you can go to 50, 100, 250 et cetera. Each combination of number of license you HAVE and the number of license you WANT have a specific product number. One from 10 to 25, one from 10 to 50, one from 25 to 50 and so on. Messy? Indeed.

 

The cheaper track is the essentials-licens. You unlock your firewall to unlimited(*) number of concurrent vpn client with one single license. It is cheaper and easier but comes with a few downsides: If you use essentials you cannot do the portal-thingie. And you can not use AEA (which is probably not an issue, see above).

If you wanna use essentials you add the license, AND you do not forget to add the command “webvpn -> anyconnect-essentials” to enable essentials. This command cannot be entered without the license and when essentials is enabled the firewall doesnt care if there are premium licenses installed or not.

 

On the other hand, if you use premium licenses, you must (except for adding the licenses of course) disable essentials (webvpn -> no anyconnect-essentials). The essentials license (if it exists) will stay there but for no use and good.

 

So, can it be even more complicated? You bet! No matter what selections you have done above you cannot use anyconnect in your mobile device (iOS, Android). Why? Because Cisco wants to sell “Anyconnect Mobile” licenses. Don´t worry, they are cheap. But you need to add this if you want mobile clients. It is a binary one-timer. You add one mobile-license and you can also use mobile vpn clients.

 

So, let´s have a look at a few examples:

 

Example 1: We have an ASA5510 on which we want to connect numerous of anyconnect clients. We don´t care about the portal, but we want to use mobile clients.  We add these licenses:

  • one L-ASA-AC-E-5510=
  • one L-ASA-AC-M-5510=

The 5510 platform can handle 250 concurrent vpn sessions. This means that the licenses above allows us to use 250 concurrent connected vpn-clients, and among them there can be any number of mobile clients. (Dont forget to enable essentials in the config!)

 

Example 2: An ASA5520 on which we want to use the clientless portal as well as anyconnect clients up to a number of 45 concurrent sessions. We add this license:

 

  • One L-ASA5500-SSL50

 

Now we had raised the number of concurrent vpn-sessions from the built-in 2 to 50. Since it is premium licenses any of these 50 sessions can be clientless portal users.

 

Example 2b: We want to raise the number of concurrent users from 50 to 100. We also want to allow iPhone-devices to connect with AnyConnect. We add these licenses:

 

  • One L-ASA-SSL-50-100=
  • One L-ASA-AC-M-5520=

 

Sounds complicated? Only the first 20 times you need to understand the licensing model. And everytime Cisco changes it. Which happens. 🙂

Tagged with: , ,
Posted in Cisco Security
15 comments on “Cisco ASA Anyconnect licensing for dummies, updated!
  1. jabbson says:

    Are you saying that AEA is supported in Essential license? Since when? 😉
    It is not, as far as i know…

  2. productions de rue roseau courses à embaucher des talentsCollins III (Susan) de Norfolk,woolrich uomo, en Virginie, Kevin Collins de Port Jefferson et Mary Lynn (Allen) Chavez de Virginia Beach, VA; et ses petits-enfants Kristin, John, Aidan,botanical slimming, Caitlin arrières petits-Madison et Genesis. Memorial et la dispersion des cendres, le dimanche 19 Janvier 2014, au Waikiki Yacht Club Dispersion des cendres en mer 15h30. Célébration de la vie et Memorial à 17 heu

  3. Son premier avertissement est venu le 13 Janvier quand il a attaqué Abyss coulisses. Sa deuxième avertissement est venu une semaine plus tard le 20 Janvier,burberry scarf sale, cette fois Crimson attaqué AJ Styles. Cette même nuit, il est venu à l’aide de Kurt Angle en attaquant Abyss. Notre diversité bureau a déterminé que nous pourrions faire un hébergement simple,woolrich, raisonnable sur un terrain religieux en ne lui [le conducteur] affectation &

  4. Devin says:

    I read a lot of interesting posts here. Probably you spend a lot of time writing,
    i know how to save you a lot of work, there is an online tool that creates
    unique, SEO friendly posts in minutes, just search in google
    – k2seotips unlimited content

  5. jaraju says:

    Hi, I got a question. Let’s say my ASA supports 250 SSL VPN. I want to have AEA for 50 users and not required for 200 users. Is it possible if I want to enable 50 Premium and 200 Essentials?

    Thanks in advanced!

  6. خرید vpn says:

    ethosacademy.biz خرید vpn

  7. I have recently started a blog, the info you offer on this website has helped me tremendously. Thanks for all of your time & work.
    Boston College iPhone 5s Cases Polka Dots http://kinduz.com/wp-content/school/Boston-College-iPhone-5s-Cases-Polka-Dots.html

  8. missouri mls says:

    For thee seller they can help them to decide on a fair price to
    ask for the property that they are selling. Two real estate myths influenc the way people perceive the roles of basnks
    and realtors. Let’s have news of boloming Real Estate in Ahmedabad as people are now crazy to Buy Property in Ahmedabad India.
    Yoou CAN find free information on real estate investing.

    Also vsit my web site – missouri mls

  9. Bon info . Lucky Me Je ai découvert votre site par accident ( stumbleupon ) .
    Je ai livre marqué it pour plus tard !

  10. supplémentaires messages comme celui-ci.

  11. I’m really enjoying the theme/design of your blog.
    Do you ever run into any web browser compatibility issues?
    A number of my blog visitors have complained about my blog not
    operating correctly in Explorer but looks great in Opera.
    Do you have any solutions to help fix this problem?

    my blog VPN secures (http://top10vpnservices.blogspot.com/)

  12. Shalin says:

    What is the diagram software you created this diagram with? Is it ms office or creately online?

  13. خرید vpn says:

    Thanks for every other excellent post. The place else may just anybody get that type of info in such an ideal approach of writing?
    I have a presentation next week, and I’m at the search for such info.

1 Pings/Trackbacks for "Cisco ASA Anyconnect licensing for dummies, updated!"
  1. […] Cisco ASA Anyconnect licensing for dummies, updated! – For thee seller they can help them to decide on a fair price to ask for the property that they are selling. Two real estate myths influenc the way people perceive the … […]

Leave a Reply

Your email address will not be published. Required fields are marked *

*

Signuppp

[mc4wp_form id="2457"]
Website Security Test