Monday, March 30, 2015

Cisco ASA: Activating 3DES On An K8 Image

Its a little odd to me that, at one time, you had to have a license for 3DES.  I have not seen this in a while, but the other day, I did come across an ASA that did not have 3DES enabled.  In short, they had the K8 image and it was not licensed for it.  Bummer.
But, the good news is that you can get a free license for it.  I simply went to the Cisco licensing page and requested my copy of a license for 3DES and immediately was emailed the activation key.  See the "show verion":
...
Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 50             perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Disabled       perpetual
Encryption-DES                    : Enabled        perpetual
Encryption-3DES-AES               : Disabled       perpetual
Security Contexts                 : 0              perpetual
GTP/GPRS                          : Disabled       perpetual
AnyConnect Premium Peers          : 2              perpetual
AnyConnect Essentials             : Disabled       perpetual
Other VPN Peers                   : 250            perpetual
Total VPN Peers                   : 250            perpetual
Shared License                    : Disabled       perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
UC Phone Proxy Sessions           : 2              perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
Intercompany Media Engine         : Disabled       perpetual
Cluster                           : Disabled       perpetual

Here is how I put it on the ASA:
ASA# activation-key e60dc86d 08d1aa2f 30135118 9be89470 400e16af
Validating activation key. This may take a few minutes...
Both Running and Flash permanent activation key was updated with the requested key,
and will become active after the next reload.
ASA#

No comments:

Post a Comment

Your comment will be reviewed for approval. Thank you for submitting your comments.