300-730 · Question #167
A clientless SSLVPN solution is built for 10 employees on a newly installed Cisco ASA. After a couple of days in production, it has been observed that only the first two users to log in each day are a
The correct answer is A. Allocate additional Cisco AnyConnect Premium licenses to the ASA.. Only 2 users can connect simultaneously because the ASA's SSL VPN license limits concurrent sessions, requiring additional AnyConnect Premium licenses to support all 10 employees.
Question
Options
- AAllocate additional Cisco AnyConnect Premium licenses to the ASA.
- BIncrease the vpn-simultaneous-logins parameter to a value of more than 2.
- CIncrease the number or IP addresses available in the VPN pool.
- DVerify that the users that cannot log in are in the correct AD group with VPN permissions.
How the community answered
(28 responses)- A71% (20)
- B18% (5)
- C7% (2)
- D4% (1)
Why each option
Only 2 users can connect simultaneously because the ASA's SSL VPN license limits concurrent sessions, requiring additional AnyConnect Premium licenses to support all 10 employees.
The Cisco ASA base license includes only 2 simultaneous SSL VPN (AnyConnect Premium) sessions by default. Once that licensed session count is exhausted, any additional users receive a login failure. Allocating additional AnyConnect Premium licenses raises the concurrent session ceiling to accommodate the full user base.
The vpn-simultaneous-logins group policy attribute controls per-user login limits but cannot exceed the platform's licensed SSL VPN session count, so increasing it alone would not resolve the issue.
An IP address pool applies to full-tunnel AnyConnect connections that require an assigned IP address, not to clientless SSL VPN sessions which do not consume pool addresses.
AD group membership issues would cause authentication failures for specific users regardless of login order, not a pattern where only the first two logins each day succeed.
Concept tested: Cisco ASA SSL VPN concurrent session licensing limits
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/intro-license-smart.html
Topics
Community Discussion
No community discussion yet for this question.