Cisco ASA 5505 Configuration Manual page 138

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Guidelines and Limitations
Note
For the ASA 5505 and 5510 adaptive security appliances, both units require the Security Plus
license; the Base license does not support failover, so you cannot enable failover on a standby unit
that only has the Base license.
Upgrade and Downgrade Guidelines
Your activation key remains compatible if you upgrade to the latest version from any previous version.
However, you might have issues if you want to maintain downgrade capability:
Downgrading to Version 8.1 or earlier—After you upgrade, if you activate additional feature
licenses that were introduced before 8.2, then the activation key continues to be compatible with
earlier versions if you downgrade. However if you activate feature licenses that were introduced in
8.2 or later, then the activation key is not backwards compatible. If you have an incompatible license
key, then see the following guidelines:
Downgrading to Version 8.2 or earlier—Version 8.3 introduced more robust time-based key usage
as well as failover license changes:
Additional Guidelines and Limitations
The activation key is not stored in your configuration file; it is stored as a hidden file in flash
memory.
The activation key is tied to the serial number of the device. Feature licenses cannot be transferred
between devices (except in the case of a hardware failure). If you have to replace your device due
to a hardware failure, contact the Cisco Licensing Team to have your existing license transferred to
the new serial number. The Cisco Licensing Team will ask for the Product Authorization Key
reference number and existing serial number.
Once purchased, you cannot return a license for a refund or for an upgraded license.
Although you can activate all license types, some features are incompatible with each other; for
example, multiple context mode and VPN. In the case of the AnyConnect Essentials license, the
license is incompatible with the following licenses: full SSL VPN license, shared SSL VPN license,
and Advanced Endpoint Assessment license. By default, the AnyConnect Essentials license is used
instead of the above licenses, but you can disable the AnyConnect Essentials license in the
configuration to restore use of the other licenses using the Configuration > Remote Access VPN >
Network (Client) Access > Advanced > AnyConnect Essentials pane.
Cisco ASA 5500 Series Configuration Guide using ASDM
4-22
Failover units do require the same RAM on both units.
If you previously entered an activation key in an earlier version, then the adaptive security
appliance uses that key (without any of the new licenses you activated in Version 8.2 or later).
If you have a new system and do not have an earlier activation key, then you need to request a
new activation key compatible with the earlier version.
If you have more than one time-based activation key active, when you downgrade, only the most
recently activated time-based key can be active. Any other keys are made inactive. If the last
time-based license is for a feature introduced in 8.3, then that license still remains the active
license even though it cannot be used in earlier versions. Reenter the permanent key or a valid
time-based key.
If you have mismatched licenses on a failover pair, then downgrading will disable failover. Even
if the keys are matching, the license used will no longer be a combined license.
If you have one time-based license installed, but it is for a feature introduced in 8.3, then after
you downgrade, that time-based license remains active. You need to reenter the permanent key
to disable the time-based license.
Chapter 4
Managing Feature Licenses
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents