Cisco Systems Questions about max. Users ASA

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Questions about max. Users ASA Andy Doe 07-02-09
Posted by Andy Doe on July 2, 2009, 12:26 pm
Please log in for more thread options
Hi,

I have a ASA 5005 here which supports up to 10 Users. What does this exactly
mean? Is this a count of internal IP addresses?
If so, can I extend the possible internal clients through PAT? Lets say I
put an internal router behind the FW which does PAT for the
internal clients behind the router (the FW should only see one IP then,
right?)

Just a thought...what do you think?

BR...Andy



Posted by Chino on July 2, 2009, 12:40 pm
Please log in for more thread options
> I have a ASA 5005 here which supports up to 10 Users. What does this
> exactly mean? Is this a count of internal IP addresses?
> If so, can I extend the possible internal clients through PAT? Lets say I
> put an internal router behind the FW which does PAT for the
> internal clients behind the router (the FW should only see one IP then,
> right?)
>
> Just a thought...what do you think?

If ASA works just like the old 501 PIX, then limit is applied to the nat
translations.
So you only can get 10 user nat translated at a time.
If you setup a router behind, it should work fine.



Posted by alexd on July 3, 2009, 3:26 pm
Please log in for more thread options
Chino wrote:

> If ASA works just like the old 501 PIX, then limit is applied to the nat
> translations.
> So you only can get 10 user nat translated at a time.

If you had, say, a network printer that had no need to access the internet,
presumably removing its default gateway setting would ensure it didn't count
toward the total?

--
<http://ale.cx/> (AIM:troffasky) (UnSoEsNpEaTm@ale.cx)
20:25:03 up 58 days, 4:58, 1 user, load average: 0.28, 0.19, 0.17
A few flakes working together can unleash an avalanche of destruction



Posted by Chino on July 4, 2009, 6:33 am
Please log in for more thread options
> If you had, say, a network printer that had no need to access the
> internet,
> presumably removing its default gateway setting would ensure it didn't
> count
> toward the total?

Never tried but it should work.



Similar ThreadsPosted
Questions about max. Users ASA July 2, 2009, 12:26 pm
Monitoring VPN users on PIX 515 September 23, 2005, 2:16 pm
ASA na local users February 24, 2008, 5:21 pm
VPN Client - some users can't connect February 2, 2006, 10:57 am
RME baseline templates, any users? April 29, 2006, 6:52 pm
End-Users vpn client question April 30, 2006, 10:04 pm
Configuring a VPN for users to connect thru May 11, 2006, 12:24 am
Need a VPN solution for 25 users..already own PIX 515UR September 26, 2006, 10:14 am
Internet only users - PIX settings October 1, 2009, 11:38 am
Baltimore Cisco users' group February 11, 2005, 1:11 pm
PIX or Router blocks wireless users? November 7, 2005, 5:59 am
How to write on syslog which users access via RAS. January 5, 2006, 11:12 am
How to write on syslog which users access via RAS. January 5, 2006, 11:46 am
Michigan LWAP WLAN Users January 20, 2006, 9:16 am
Active Directory users on Cisco PIX February 23, 2006, 5:26 am
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More