Cisco Asa 5505 Activation Key Ge: The Best Practices for Firewall and VPN Configuration
- conwaypettiford872
- Aug 19, 2023
- 2 min read
I have a ASA 5505 that I test with which originally came with the Security Plus license. I recently erased flash and loaded the latest asa841-k8.bin version of IOS along with asdm-642.bin. Everything booted fine and came up as it does when freshly wiped however I noticed that i was now only running a base license. If I issue the sh activiation-key command, I noticed the following messages (full output is at the bottom):
Cisco Asa 5505 Activation Key Ge
Enter the serial number of the Cisco ASA. You can get this by looking on the chassis, or doing a show version or a show activation-key. The license key will be emailed to you, and then all you have to do is enter it into the ASA with the activation-key command.
Every Cisco ASA platform comes with a certain number of implicitly activated features and capacities as a part of the Base License. In other words, these capabilities are fixed in the given software image for the particular hardware; you cannot selectively disable them. One example of such a feature is Active/Active failover, which is always available on all Cisco ASA 5585-X appliances. Some platforms offer the optional Security Plus license, which may unlock additional features or capacities on top of the Base License. For example, you can increase the maximum concurrent firewall connection count on the Cisco ASA 5505 from 10,000 to 25,000 by installing a Security Plus license.
Use the show version or show activation-key command to display the complete list of licensed features and capacities of a particular Cisco ASA device along with the activation information. Example 3-1 shows sample output of the show activation-key command issued on a Cisco ASA 5525-X appliance. Notice that the count of Firewall Connections does not show up as a licensed feature; check the output of the show resource usage command for some of these platform capacities. However, this sample output contains several pieces of additional information: the serial number of the appliance and the remaining active time for each feature. It also lists multiple activation keys that enable the given set of features on this particular device for the specified amount of time. These activation keys enable a straightforward mechanism for adding or removing licensed features on Cisco ASA devices.
Users can always make an informed choice as to whether they should proceed with certain services offered by Cisco Press. If you choose to remove yourself from our mailing list(s) simply visit the following page and uncheck any communication you no longer want to receive: www.ciscopress.com/u.aspx.
CiscoASA# show activation-key Serial Number: ************ Running Activation Key: 0x7905c844 0x2c16a53f 0xe430dd6c 0xa6e428a8 0x05260b8b Licensed features for this platform: Maximum Physical Interfaces : Unlimited Maximum VLANs : 50 Inside Hosts : UnlimitedFailover : DisabledVPN-DES : Enabled VPN-3DES-AES : Disabled Security Contexts : 0 GTP/GPRS : Disabled SSL VPN Peers : 2 Total VPN Peers : 250 Shared License : Disabled AnyConnect for Mobile : Disabled AnyConnect for Linksys phone : Disabled AnyConnect Essentials : Disabled Advanced Endpoint Assessment : Disabled UC Phone Proxy Sessions : 2 Total UC Proxy Sessions : 2 Botnet Traffic Filter : Disabled This platform has a Base license. The flash activation key is the SAME as the running key. CiscoASA# 2ff7e9595c
Comments