-40%
Failover Pair of Cisco ASA5505-SEC-BUN-K9 for Active/Standby High Availability
$ 210.67
- Description
- Size Guide
Description
Pair of Cisco ASA5505-SEC-BUN-K9 for Active/Standby Failover High AvailabilityOnly a pair of ASA5505-SEC-BUN-K9 licensed units can act as a Active/Standby pair for failover protection also called HA High Availability. No other ASA5505 licences activate this feature on the units.
These units have IOS 9.23 with the maximum 512MB/128MB Dram & Flash
ASA5505-BUN Bundles
Bundle Differences
ASA5505-K8
DES
ASA5505-BUN-K9
3DES/AES
ASA5505-50-BUN-K9
3DES/AES 50-user
ASA5505-UL-BUN-K9
3DES/AES Unlimited User
ASA5505-SEC-BUN-K9
3DES/AES Unlimited +
25 IPsec VPN peers, Failover, dual ISP and DMZ support
Licensed features for this platform:
Maximum Physical Interfaces
8
perpetual
VLANs
20
DMZ Unrestricted
Dual ISPs
Enabled
perpetual
VLAN Trunk Ports
8
perpetual
Inside Hosts
Unlimited
perpetual
Failover
Active/Standby
perpetual
Encryption-DES
Enabled
perpetual
Encryption-3DES-AES
Enabled
perpetual
AnyConnect Premium Peers
25
perpetual
AnyConnect Essentials
Disabled
perpetual
Other VPN Peers
25
perpetual
Total VPN Peers
25
perpetual
Shared License
Enabled
perpetual
AnyConnect for Mobile
Enabled
perpetual
AnyConnect for Cisco VPN Phone
Enabled
perpetual
Advanced Endpoint Assessment
Enabled
perpetual
UC Phone Proxy Sessions
24
perpetual
Total UC Proxy Sessions
24
perpetual
Botnet Traffic Filter
Enabled
perpetual
Intercompany Media Engine
Disabled
perpetual
Cluster
Disabled
perpetual
This platform has an
ASA 5505 Security Plus license
.
Security Plus licensing exists only on 5505 and 5510. On the 5505 it has the following effects:
Upgrades the maximum VPN sessions from 10 to 25.
Upgrades the maximum connections from 10,000 to 25,000.
Increases the number of VLANs from 3 to 20 and enables trunking.
Enables optional stateless active/standby failover.
A user is considered an internal device which communicates with the external VLAN.
SSL licenses break into two general types: Essentials and Premium.
Essentials provides AnyConnect client based connections from personal computers including Windows and Mac systems.
Installing an Essentials license allows for up to the maximum number of VPN sessions on the platform to be concurrently used for SSL.
AnyConnect Essentials licenses debuted with ASA release v8.2.
Premium licenses allow for both AnyConnect client based and clientless SSL VPN. Clientless VPN is established through a web browser. While it is typically less functional than AnyConnect client based VPN, it is adequate access for many users. Additionally, Cisco Secure Desktop (Host Scan and Vault functionality) is included. Premium licenses do not max out the unit they’re on of SSL VPN sessions as does the Essentials license. Instead, this is a per seat license that can be purchased in bulk quantities. These quantities are 10, 25, 50, 100, 250, 500, 750, 1000, 2500, 5000, 10000 with each platform being able to support only the maximum number of licenses which it supports total VPN connections (ex. 5510 supports up to 250). Premium licenses are significantly more expensive than Essentials.
Configuring Active/Standby is the failover features that enable you to achieve HA high availability.
On a 5505 or 5510 both ASAs require Security Plus licenses since Security Plus enables the HA functionality.
Units with ASA software v8.3 or earlier must have identical licensing to be a HA pair.
Advanced Endpoint Assessment will scan a SSL VPN client using Cisco Secure Desktop for security policy compliance and attempt to remediate if the system is out of compliance. This is similar but a little less feature-rich than NAC. Licenses are simple for Advanced Endpoint Assessment. One license per ASA is required in addition to SSL Premium. If the ASA is in a HA pair, one license per pair is required if using ASA software v. 8.3(1) or later.
Cisco UC Proxy allows for Cisco IP phones to create a TLS tunnel between a remote phone and the ASA located at a corporate office. Typically if a secure connection between a phone and office were required, a firewall would have to sit at the user’s location. In many cases this would be a 800 series router. This deployment architecture doesn’t scale well due to management costs and cost of routers with their corresponding SMARTnet. UC Proxy bypasses the router and uses the IP phone as the VPN endpoint.
UC Proxy licenses are sold in numerous tiers ranging from 24 to 10,000 concurrent connections. The licenses cannot be stacked, but incremental licenses can be purchased.
AnyConnect Mobile Licenses
Out of the box, ASAs do not accept connections from mobile devices such as iOS or Android systems. The AnyConnect Mobile client must be installed on the client’s device. In addition to the client, the ASA must have AnyConnect Essentials or Premium enabled and a Mobile license used in conjunction. Only one Mobile license is required per ASA. The Mobile license inherits the number of SSL users allowed by Essentials or Premium.
L-ASA5505-SEC-PL