FortiCare Versions Essentials, Premium, or Elite?

KB ID 0001782

FortiCare Versions

With the release of the Q2 2022 FortiNet price list, they have decided to split FortiCare up into three different versions

  • FortiCare Essentials: Is the base-level service, and it is targeted toward devices that require a limited amount of support. This service is only offered to FortiGate models 8x and below and to low-end FortiWifi devices. Support includes web only tickets & chat, with next day business response.
  • FortiCare Premium: The previous 24×7 FortiCare offering, including ‘follow the sun support’, one-hour response for critical issues and the next business-day response for non-critical issues.
  • FortiCare Elite: The previous ASE (Advanced Support and Engineering) FortiCare offering now enabling coverage of a broader product range. This level provides 24×7 follow the sun support and optimum response times of 15 minutes. FortiCare Elite services offers enhanced service-level agreements (SLAs) and accelerated issue resolution. This advanced support offering provides access to a dedicated support team. Single-touch ticket handling by the expert technical team streamlines resolution. This option also provides Extended End-of-Engineering-Support (EoE’s) of 18 months for added flexibility and access to the new FortiCare Elite Portal. This intuitive portal provides a single unified view of device and security health.

Related Articles, References, Credits, or External Links

NA

AnyConnect 4 – Plus and Apex Licensing Explained

KB ID 0001013 

Problem

(Updated 11/05/21)

Before version 4 we simply had AnyConnect Essentials and Premium licensing, now we have Plus and Apex licensing.

AnyConnect Plus and Apex

There are in fact three licensing options;

  • Cisco AnyConnect Plus Subscription Licenses
  • Cisco AnyConnect Plus Perpetual Licenses
  • Cisco AnyConnect Apex Subscription Licenses
  • NEW VPN Only perpetual Licences

Plus and Apex Contain;

AnyConnect PLUS (Cisco pitch “Equivalent to the old Essentials License”).

  • VPN functionality for PC and mobile platforms, including per-app VPN on mobile platforms.
  • Basic endpoint context collection (Note: NOT full ISE context support).
  • IEEE 802.1X Windows supplicant.
  • Cisco Cloud Web Security agent for Windows & Mac OS X platforms.
  • Cisco Web Security Appliance support.
  • FIPS compliance.

AnyConnect APEX (Cisco pitch “Equivalent to the old Premium License”).

  • Everything that’s included in AnyConnect Plus.
  • Clientless (browser-based) VPN termination on the Cisco ASA.
  • VPN Compliance/Posture agent in conjunction with the Cisco ASA.
  • Unified Compliance/Posture agent in conjunction with the Cisco ISE 1.3 or later.
  • Next Generation Encryption/Suite B.

Both licenses are available as 1, 2 and 5 (not 3 as listed on the Cisco website) year subscription, or you can buy Plus licenses with a perpetual license option.

Note: For PLUS Licences looks at SKUs starting  L-AC-PLS, for APEX Licences look SKUs starting at L-AC-APX

(Note: if you have a Plus Perpetual license you still need to purchase a software applications support plus upgrades (SASU) contract.

Regardless of which you buy, the SASU for AnyConnect is NOT included in the support contract for the parent device e.g. the SmartNet on your Cisco ASA Firewall.

To purchase support you order the parent license (SKU: L-AC-PLS-P-G) which has no cost, then you add in the relevant license for the amount of clients you have e.g. AC-PLS-P-500-S for 500 users, AC-PLS-P-2000-S for 2000 users etc.

BE AWARE: AnyConnect 4 Licenses will display as AnyConnect Premium licenses when you issue a ‘show version’ command. When adding an AnyConnect 4 License (regardless of the quantity of licenses added), will license to the maximum permitted AnyConnect Premium license count for the ASA hardware platform, those being;

New AnyConnect VPN Only Licences (Perpetual)

You can now purchase VPN Only perpetual licences, they are sold by ‘Concurrent VPN Connection‘. You order them like so;

L-AC-VPNO-25 (for 25 concurrent VPN connections) you can also buy in 50, 100, 250, 500, 1K, 2500, 5K ,and 10K versions. Depending on what you device will physically support (see below)

Cisco ASA Maximum VPN Peers / Sessions

Cisco Firepower Firewalls

FPR-1010 = 75
FPR-1120 = 150
FPR-1130 = 400
FPR-1140 = 800
FPR-2110 = 1500
FPR-2120 = 3500
FPR-2130 = 7500
FPR-2140 = 10,000
FPR-4110 = 10,000
FPR-4112 = 10,000
FPR-4115 = 15,000
FPR-4120 = 20,000
FPR-4125 = 20,000
FPR-4140 = 20,000
FPR-4145 = 20,000
FPR-4150 = 20,000
FPR-9300-SM24 = 20,000 
FPR-9300-SM36 = 20,000
FPR-9300-SM40 = 20,000
FPR-9300-SM44 = 20,000
FPR-9300-3xSM44 = 60,000
FPR-9300-SM48 = 20,000
FPR-9300-SM56 = 20,000
FPR-9300-SM3x56 = 60,000

Cisco ASA 5500-X Firewalls
5506-X = 50
5508-X = 100
5512-X = 250
5515-X = 250
5516-X = 300
5525-X = 750
5545-X = 2500
5555-X = 5000
5585-X = 10,000
Cisco ASA 5500 Firewalls

5505 = 25 
5510 = 250 
5520 = 750 
5540 = 5,000 
5550 = 5,000 
5580 = 10,000

Cisco ASAv Firewalls

ASAv5  = 50
ASAv10 = 100
ASAv30 = 750
ASAv50 = 10,000
 

Related Articles, References, Credits, or External Links

Cisco AnyConnect – Essentials / Premium Licenses Explained

Cisco ASA 5500 – Adding Licenses

Cisco AnyConnect Ordering Guide

Windows – Create ‘Multiple Version’ Install Media(x32 and x64 bit)

KB ID 0000164 

Problem

When Microsoft released Windows Vista and Server 2008 they had the brilliant Idea of putting all the versions you would require in the same install media. With Windows 7 they have changed their approach, and the install media is specific to the version that is going to be installed. Well actually that’s not true the version is decided by a file in the installation media called ei.cfg and all versions are STILL in there.

What they still do, is have their x32 bit and their x64 bit Operating Systems on different media. If you do a lot of installs you might want them all on one DVD. Below are two walkthroughs, the first shows you how to make an x32 and x64 bit install DVD with all the versions* on it, the second shows you how to unlock your exiting install media so that all the versions on it are accessible.

Create an x32 and x64 bit Windows 7 Multi Install Media DVD

Create an x32 or x64 bit Windows 7 Multi Install DVD.

*When I say “all versions” I’m NOT including Windows 7 Enterprise, that comes on separate media, and is just for open value subscription customers, or customers with software assurance.

Solution

Create an x32 AND x64 bit Windows 7 Multi Install Media DVD

1. Download your Windows 7 ISO Images (x32 and x64), from VLSC, Technet, or MSDN etc.

2. Make two Directories on your Machine’s C: Drive called Master and Images.

3. Using 7Zip open the x32 bit ISO file you have downloaded, and extract the sourcesinstall.wim file to the C:Images folder.

4. Then rename the file you just extracted to x32.wim.

4. Using 7Zip open the x64 bit ISO file you have downloaded, and extract the sourcesinstall.wim file to the C:Images folder.

5. Then rename the file you just extracted to x64.wim.

5. Install the WAIK on your machine (instructions here).

6. Check the x32 image for the “Image Index” (these are the numbers of all the Windows versions in this image), Yours will probably be identical, but you may have different media so check! Launch the “Deployment Tools Command Prompt”

To check the image index, execute the following command;

[box]
imagex /info C:Imagesx32.wim
[/box]

You can see (above) this image has five images within it, scroll down and you can see them.

Mine is structured as follows;

Image 1 – Starter Edition
Image 2 – Home Basic
Image 3 – Home Premium
Image 4 – Professional
Image 5 – Ultimate

7. Create a new image from all these Windows 7 x32 images, by executing the following commands;

[box]

IMAGEX /Export C:Imagesx32.wim 1 C:ImagesInstall.wim “Windows 7 Starter x32”
IMAGEX /Export C:Imagesx32.wim 2 C:ImagesInstall.wim “Windows 7 Home Basic x32”

IMAGEX /Export C:Imagesx32.wim 3 C:ImagesInstall.wim “Windows 7 Home Premium x32”

IMAGEX /Export C:Imagesx32.wim 4 C:ImagesInstall.wim “Windows 7 Professional x32”

IMAGEX /Export C:Imagesx32.wim 5 C:ImagesInstall.wim “Windows 7 Ultimate x32”

[/box]

8. Now check the x64 image (Note: There is NO x64 bit Starter Edition).

To check the image index, execute the following command;

[box]
imagex /info C:Imagesx64.wim
[/box]

You can see (above) this image has four images within it, scroll down and you can see them.

Mine is structured as follows;

Image 1 – Home Basic
Image 2 – Home Premium
Image 3 – Professional
Image 4 – Ultimate

9. Create a new image from all these Windows 7 x64 images, by executing the following commands;

[box]
IMAGEX /Export C:Imagesx64.wim 1 C:ImagesInstall.wim “Windows 7 Home Basic x64”

IMAGEX /Export C:Imagesx64.wim 2 C:ImagesInstall.wim “Windows 7 Home Premium x64”

IMAGEX /Export C:Imagesx64.wim 3 C:ImagesInstall.wim “Windows 7 Professional x64”

IMAGEX /Export C:Imagesx64.wim 4 C:ImagesInstall.wim “Windows 7 Ultimate x64”
[/box]

10. Extract the contents of one (I used the x32 bit one) of your ISO files to the C:Master Directory.

11. Delete the C:MasterSourcesei.cfg file.

12. Copy the C:ImagesInstall.wim to c:MasterSources (Select Yes to Overwrite).

13. Create a new ISO file, by executing the following command;

[box]
oscdimg.exe -lMulti-Windows-7 -m -u2 -b”C:MasterBootetfsboot.com” C:Master C:Multi-Windows-7.ISO
[/box]

14. Test your new install media (Note: if you want to Burn a DVD from this ISO use ImgBurn (it’s free).

Create an x32 OR x64 bit Windows 7 Multi Install DVD.

So if you have the installation media in .iso format you can change it so you can see the other install versions. On THIS site there are some utilities to help you – the “eicfg removal utility” removes the pointer to the file (which means you can install any version by picking it from the install menu (like you did with Windows Vista). Or you can swap your version with the second tool “Windows 7 iso image edition switcher”. I deploy a lot of machines so the former is a much better option for me.

1. Drop the windows 7 .iso file somewhere you can get at it (i.e. on your desktop).

2. Download eicfg removal utility, Extract it and run the eicfg_remover.exe

3. Browse to your .iso file > Open.

4. Now if you boot with this media you will get a choice of which version you want to install.

 

Related Articles, References, Credits, or External Links

Original article written 02/01/10

Cisco AnyConnect – Essentials / Premium Licenses. Explained

KB ID 0000628 

Problem

Note: With Anyconnect 4 Cisco now use Plus and Apex AnyConnect licensing.

When Cisco released the 8.2 version of the ASA code, they changed their licensing model for AnyConnect Licenses. There are two licensing models, Premium and Essentials.

Solution

Cisco ASA AnyConnect Premium Licenses.

You get two of these free with your firewall*, with a ‘Premium License’ you can use the AnyConnect client software for remote VPN Access, and you can access Clientless SSL facilities via the web portal.

*As pointed out by @nhomsany “The two default premium licenses available are NOT cross-platform, (i.e. only Mac or Windows).

Additionally you can use this license’ model with the Advanced Endpoint Assessment License’, this is the license’ you require for Cisco Secure Desktop. You can also use this license’ with the AnyConnect Mobile license’ for access from mobile devices like phones or tablets, (both these licenses are an additional purchase).

For most people wishing to buy extra AnyConnect licensing, this will be the one you want. Their type and size differ depending on the ASA platform in question, e.g. the 5505 premium licenses. are available as 10 session and 25 session licenses. the 5510 are in 10, 25, 50, 100 and 250 Sessions. (Note: These are correct for version 8.4 and are subject to change, check with your re seller).

Failover: If you are using failover firewalls you can (but don’t have to) use a shared license’ model, this lets you purchase a bundle of Premium licenses. and share them across multiple pieces of hardware, This requires an ASA to be setup as the license’ server’. Before version 8.3 you needed to purchase licenses for both firewalls. After version 8.3, Cisco allowed the licenses. to be replicated between firewalls in a failover pair. The exception is Active/Active where the amount of licenses. is aggregated together from both firewalls and ALL are available providing the figure does not exceed the maximum for the hardware being used.

Cisco ASA AnyConnect Essential Licenses

When you enable ‘Essential Licensing’, your firewall changes it’s licensing model and the two Premium licenses. you get with it are disabled*. The Firewall will then ONLY accept AnyConnect connections from the AnyConnect VPN client software.

Note: The portal still exists, but can only be used to download the AnyConnect Client Software.

With Essentials licensing enabled, the firewall will then accept the maximum VPN sessions it can support for that hardware version (see here), without the need to keep adding licenses.

Note: Remember these are “Peer VPN Sessions”. If you have a bunch of other VPN’s (including IPSEC ones), then these are taken from the ‘pot’.

Additionally, you can also use this license’ with the AnyConnect Mobile license’ for access from mobile devices like phones or tablets, this license’ is an additional purchase.

Failover: Prior to version 8.3, if you have failover firewalls and are using Essentials licenses you need to purchase an Essentials license’ for BOTH firewalls. After version 8.3 Cisco allowed the licenses. to be replicated between firewalls in a failover pair.

Cisco ASA Maximum VPN Peers / Sessions

5505 = 25
5510 = 250
5520 = 750
5540 = 5,000
5550 = 5,000
5580 = 10,000

Next Generation Platform (X)

5512-X = 250
5515-X = 250
5525-X = 750
5545-X = 2500
5555-X = 5000
5585-X = 10,000

*To re-enable the built in Premium Licenses. you need to disable Essentials licensing by using the ‘no anyconnect-essentials” command or in the ASDM> Configuration > Remote Access VPN > Network (Client) Access > Advanced > AnyConnect Essentials.

Related Articles, References, Credits, or External Links

Cisco ASA5500 AnyConnect SSL VPN 

Cisco AnyConnect Mobility License’

Cisco ASA 5500 – Adding Licenses