Information about vpn and the asa cx module, Compatibility with asa features, Licensing requirements for the asa cx module – Cisco ASA 5505 User Manual

Page 1250: Guidelines and limitations

Advertising
background image

59-4

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 59 Configuring the ASA CX Module

Licensing Requirements for the ASA CX Module

Information About VPN and the ASA CX Module

The ASA includes VPN client and user authentication metadata when forwarding traffic to the ASA CX
module, which allows the ASA CX module to include this information as part of its policy lookup
criteria. The VPN metadata is sent only at VPN tunnel establishment time along with a type-length-value
(TLV) containing the session ID. The ASA CX module caches the VPN metadata for each session. Each
tunneled connection sends the session ID so the ASA CX module can look up that session’s metadata.

Compatibility with ASA Features

The ASA includes many advanced application inspection features, including HTTP inspection.
However, the ASA CX module provides more advanced HTTP inspection than the ASA provides, as well
as additional features for other applications, including monitoring and controlling application usage.

To take full advantage of the ASA CX module features, see the following guidelines for traffic that you
send to the ASA CX module:

Do not configure ASA inspection on HTTP traffic.

Other application inspections on the ASA are compatible with the ASA CX module, including the
default inspections.

Do not enable the Mobile User Security (MUS) server; it is not compatible with the ASA CX
module.

If you enable failover, when the ASA fails over, any existing ASA CX flows are transferred to the
new ASA, but the traffic is allowed through the ASA without being acted upon by the ASA CX
module. Only new flows recieved by the new ASA are acted upon by the ASA CX module.

Licensing Requirements for the ASA CX Module

The following table shows the licensing requirements for this feature:

The ASA CX module and PRSM require additional licenses. See the ASA CX documentation for more
information.

Guidelines and Limitations

This section includes the guidelines and limitations for this feature.

Context Mode Guidelines

Supported in single context mode only. Does not support multiple context mode.

Firewall Mode Guidelines

Supported in routed and transparent firewall mode.

Model

License Requirement

All models

Base License.

Advertising