69-2
Cisco ASA 5500 Series Configuration Guide using the CLI
Chapter69 Configuring Remote Access IPsec VPNs
Licensing Requirements for Remote Access IPsec VPNs
A transform set protects the data flows for the access list specified in the associated crypto map entry.
You can create transform sets in the ASA configuration, and then specify a maximum of 11 of them in
a crypto map or dynamic crypto map entry. For more overview information, including a table that lists
valid encryption and authentication methods, see the “Creating an IKEv1 Transform Set” section on
page 73-5 in Chapter 73, “Configuring LAN-to-LAN IPsec VPNs” of this guide.
Licensing Requirements for Remote Access IPsec VPNs
The following table shows the licensing requirements for this feature:
Note This feature is not available on No Payload Encryption models.
Model License Requirement1
ASA 5505 IPsec remote access VPN using IKEv2 (use one of the following):
AnyConnect Premium license:
Base license and Security Plus license: 2 sessions.
Optional permanent or time-based licenses: 10 or 25 sessions.
Shared licenses are not supported.2
AnyConnect Essentials license3: 25 sessions.
IPsec remote access VPN using IKEv1 and IPsec site-to-site VPN using IKEv1 or IKEv2:
Base license: 10 sessions.
Security Plus license: 25 sessions.
ASA 5510 IPsec remote access VPN using IKEv2 (use one of the following):
AnyConnect Premium license:
Base and Security Plus license: 2 sessions.
Optional permanent or time-based licenses: 10, 25, 50, 100, or 250 sessions.
Optional Shared licenses2: Participant or Server. For the Server license, 500-50,000 in
increments of 500 and 50,000-545,000 in increments of 1000.
AnyConnect Essentials license3: 250 sessions.
IPsec remote access VPN using IKEv1 and IPsec site-to-site VPN using IKEv1 or IKEv2:
Base license and Security Plus license: 250 sessions.