Cisco ASA DHCP Reservation (Solved)

KB ID 0001751

Problem

We have been asking for this for years! Even on my home network I’ve not been able to allocate an ASA DHCP reservation for my laptop and my MyCloud drive. I’ve been in discussions in forums with people who are convinced that putting a static ARP entry into the ASA would solve the problem (it doesn’t – I tested it extensively!)

But finally in version 9.13(1) we can now add a static DHCP reservation (MAC address to IP address).

Create an ASA DHCP Reservation

Assuming you have DHCP already setup e.g.

[box]

!
dhcpd address 10.254.254.10-10.254.254.75 inside
dhcpd enable inside
!

[/box]

Then simply add the reservation, you need to specify the MAC address as xxxx.xxxx.xxxx (that’s with full stops not colons), if in doubt, ping the existing IP address then execute a ‘show arp’ command to show you all the MAC addresses the firewall can see, so you can copy/paste it into the following command;

[box]

dhcpd reserve-address 10.254.254.50 38f9.d326.66cc inside

[/box]

Quite why it took so long for Cisco to give us this basic function, I have no idea.

Related Articles, References, Credits, or External Links

NA

AnyConnect 4 – Plus and Apex Licensing Explained

KB ID 0001013 

Problem

(Updated 11/05/21)

Before version 4 we simply had AnyConnect Essentials and Premium licensing, now we have Plus and Apex licensing.

AnyConnect Plus and Apex

There are in fact three licensing options;

  • Cisco AnyConnect Plus Subscription Licenses
  • Cisco AnyConnect Plus Perpetual Licenses
  • Cisco AnyConnect Apex Subscription Licenses
  • NEW VPN Only perpetual Licences

Plus and Apex Contain;

AnyConnect PLUS (Cisco pitch “Equivalent to the old Essentials License”).

  • VPN functionality for PC and mobile platforms, including per-app VPN on mobile platforms.
  • Basic endpoint context collection (Note: NOT full ISE context support).
  • IEEE 802.1X Windows supplicant.
  • Cisco Cloud Web Security agent for Windows & Mac OS X platforms.
  • Cisco Web Security Appliance support.
  • FIPS compliance.

AnyConnect APEX (Cisco pitch “Equivalent to the old Premium License”).

  • Everything that’s included in AnyConnect Plus.
  • Clientless (browser-based) VPN termination on the Cisco ASA.
  • VPN Compliance/Posture agent in conjunction with the Cisco ASA.
  • Unified Compliance/Posture agent in conjunction with the Cisco ISE 1.3 or later.
  • Next Generation Encryption/Suite B.

Both licenses are available as 1, 2 and 5 (not 3 as listed on the Cisco website) year subscription, or you can buy Plus licenses with a perpetual license option.

Note: For PLUS Licences looks at SKUs starting  L-AC-PLS, for APEX Licences look SKUs starting at L-AC-APX

(Note: if you have a Plus Perpetual license you still need to purchase a software applications support plus upgrades (SASU) contract.

Regardless of which you buy, the SASU for AnyConnect is NOT included in the support contract for the parent device e.g. the SmartNet on your Cisco ASA Firewall.

To purchase support you order the parent license (SKU: L-AC-PLS-P-G) which has no cost, then you add in the relevant license for the amount of clients you have e.g. AC-PLS-P-500-S for 500 users, AC-PLS-P-2000-S for 2000 users etc.

BE AWARE: AnyConnect 4 Licenses will display as AnyConnect Premium licenses when you issue a ‘show version’ command. When adding an AnyConnect 4 License (regardless of the quantity of licenses added), will license to the maximum permitted AnyConnect Premium license count for the ASA hardware platform, those being;

New AnyConnect VPN Only Licences (Perpetual)

You can now purchase VPN Only perpetual licences, they are sold by ‘Concurrent VPN Connection‘. You order them like so;

L-AC-VPNO-25 (for 25 concurrent VPN connections) you can also buy in 50, 100, 250, 500, 1K, 2500, 5K ,and 10K versions. Depending on what you device will physically support (see below)

Cisco ASA Maximum VPN Peers / Sessions

Cisco Firepower Firewalls

FPR-1010 = 75
FPR-1120 = 150
FPR-1130 = 400
FPR-1140 = 800
FPR-2110 = 1500
FPR-2120 = 3500
FPR-2130 = 7500
FPR-2140 = 10,000
FPR-4110 = 10,000
FPR-4112 = 10,000
FPR-4115 = 15,000
FPR-4120 = 20,000
FPR-4125 = 20,000
FPR-4140 = 20,000
FPR-4145 = 20,000
FPR-4150 = 20,000
FPR-9300-SM24 = 20,000 
FPR-9300-SM36 = 20,000
FPR-9300-SM40 = 20,000
FPR-9300-SM44 = 20,000
FPR-9300-3xSM44 = 60,000
FPR-9300-SM48 = 20,000
FPR-9300-SM56 = 20,000
FPR-9300-SM3x56 = 60,000

Cisco ASA 5500-X Firewalls
5506-X = 50
5508-X = 100
5512-X = 250
5515-X = 250
5516-X = 300
5525-X = 750
5545-X = 2500
5555-X = 5000
5585-X = 10,000
Cisco ASA 5500 Firewalls

5505 = 25 
5510 = 250 
5520 = 750 
5540 = 5,000 
5550 = 5,000 
5580 = 10,000

Cisco ASAv Firewalls

ASAv5  = 50
ASAv10 = 100
ASAv30 = 750
ASAv50 = 10,000
 

Related Articles, References, Credits, or External Links

Cisco AnyConnect – Essentials / Premium Licenses Explained

Cisco ASA 5500 – Adding Licenses

Cisco AnyConnect Ordering Guide

Cisco Catalyst 9200 / 9300 DNA Licensing

KB ID 0001750

Problem

I get asked this at least once a month, “What’s the score with this DNA Licensing?” It took long enough for everyone to get used to Lan Base, IP Base, and IP Services!

The cynic in me would say, Cisco have learned from Meraki that selling subscription licences is much better than selling products that you don’t get any recurring revenue from. But I’ll try an give you the short answer so you can get the correct license. 

Solution: Buying Cisco Catalyst 9K Switches

Firstly: Not sure who decided that Cisco would release 9000 series Catalyst switches, when they had 9000 series Nexus switches? (Thanks for that!)

Catalyst 9200 or 9300?

As a rule of thumb 9200 series are typically used as access switches i.e. replacements for things like the Catalyst 2960, 2960-X, and 2960-XR). And the 9300 series are a replacement for things like Cisco Catalyst 3750G, 3750-X, and 3850.

Note: There’s also a Catalyst 9400 switch, which is a modular (line card) based chassis switch to replace the Catalyst 4500 and 6000 series.
Note2: There’s also a Catalyst 9500 switch that replaced the 10Gbps catalyst 3850 models (traditional 1U size).
Note3: There’s also a Catalyst 9600 switch which is modular (line card) based chassis switch to replace the Catalyst 6000 Series.
Note4: There’s also a Catalyst 9800 series which, just to confuse everyone further, is a range of wireless controllers?

So which switch to buy? Cisco keep adding models to both ranges so the first thing to do is decide 9200 or 9300, then look at the current Cisco Data Sheet for that range.

9200 Series Data Sheet

9300 Series Data Sheet

Then decide

  1. How many ports (access/downlink) do you need, and what speed/type do they need to be?
  2. Do you need PoE?
  3. What uplink ports do you need? (Some models have fixed (built in) uplinks, others need a network module (modular) uplink. Remember modular uplinks have their own part number (SKU), and will need to be ordered separately. (Note: 9200L and 9300L have fixed uplinks)
  4. Do you need additional (redundant) power supplies? 
  5. Do you need to ‘Stack’ your switches, if so don’t forget to get a stack cable (theres no separate stacking modules).

They were cheaper than you expected right?

That’s because now we need to add on a DNA licence as well.

DNA Licensing

Cisco DNA (Digital Network Architecture) is the name given collectively to a suite of products that are aimed towards being software driven, automated, with built in security.

There’s three types;

  • DNA Essentials: (Lan Base in old money) Basically Layer 2 functionality and static routing.
  • DNA Advantage:  (Combines IP Base and IP Services in old money) Basically full Layer 3 functionality, (and all the functionality of DNA Essentials).
  • DNA Premier: Combines all the functionality of DNA Essentials and DNA Advantage, and adds on ISE integration and Cisco Secure Network Analytics (formerly Stealthwatch) support.

Each licence comes in either a 3 Year, 5 Year, or 7 Year subscription model.

Example DNA Licensing SKU: C9200- DNA-E-24-3Y

C9200  – for a Cisco Catalyst 9200 series switch.

DNA – Digital Network Architecture licence.

E – Essentials (A would be advantage, and P would be premier).

24 – For a 24 port switch

3Y – 3 Year Subscription

Related Articles, References, Credits, or External Links

NA