

With the Base License, you can configure the physical switch ports only in access mode with the Security Plus license, you gain the ability to carry multiple VLANs on any of the Cisco ASA 5505 physical interfaces by configuring them as trunks.

Keep in mind that you can create a larger number of subinterfaces on some ASA appliances, but this particular limit only kicks in when you actually assign the given number of subinterfaces to VLANs with the vlan interface command. This limit can be expanded on Cisco ASA 5505, ASA 5510, and ASA 5512-X models by applying a Security Plus license. The system will deny only new attempted connections above the licensed limit there are no adverse effects for existing connections in this case. This limit can only be increased with the Security Plus license on Cisco ASA 5505, ASA 5510, and ASA 5512-X appliances. The following licensed features and capacities are not available on any No Payload Encryption hardware models. On the Cisco ASA 5580 platform, the Base License allows creating up to two application contexts, while several premium licenses of different tiered counts allow extending this limit up to 250 contexts in total.ĭepending on specific markets and international export regulations, some Cisco ASA models may also ship with the permanent No Payload Encryption license this license ties to the particular hardware without the option of change or removal. Some platforms offer the optional Security Plus license, which may unlock additional features or capacities on top of the Base License.įor example, you can increase the maximum concurrent firewall connection count on the Cisco ASA 5505 from 10,000 to 25,000 by installing a Security Plus license.įor instance, the Botnet Traffic Filter license will allow you to protect all connections through a Cisco ASA up to the maximum limit for the platform.Īn example of such a feature is the ability to configure security contexts on some Cisco ASA appliances. One example of such a feature is ActiveActive failover, which is always available on all Cisco ASA 5585-X appliances. In other words, these capabilities are fixed in the given software image for the particular hardware you cannot selectively disable them. You can also activate additional licenses permanently or for a certain duration of time.
