13
Release Notes for the Cisco ASA 5500 Series, Version 8.2(x)
OL-18971-02
New Features
Shared license for SSL
VPN sessions
You can purchase a shared license with a large number of SSL VPN sessions and share the sessions
as needed among a group of adaptive security appliances by configuring one of the adaptive
security appliances as a shared license server, and the rest as clients. The following commands were
introduced: license-server commands (various), show shared license.
Note This license cannot be used at the same time as the AnyConnect Essentials license.
Firewall Features
TCP state bypass If you have asymmetric routing configured on upstream routers, and traffic alternates between two
adaptive security appliances, then you can configure TCP state bypass for specific traffic. The
following command was introduced: set connection advanced tcp-state-bypass.
Per-Interface IP
Addresses for the
Media-Termination
Instance Used by the
Phone Proxy
In Version 8.0(4), you configured a global media-termination address (MTA) on the adaptive
security appliance. In Version 8.2, you can now configure MTAs for individual interfaces (with a
minimum of two MTAs). As a result of this enhancement, the old CLI has been deprecated. You
can continue to use the old configuration if desired. However, if you need to change the
configuration at all, only the new configuration method is accepted; you cannot later restore the old
configuration.
Displaying the CTL File
for the Phone Proxy
The Cisco Phone Proxy feature includes the show ctl-file command, which shows the contents of
the CTL file used by the phone proxy. Using the show ctl-file command is useful for debugging
when configuring the phone proxy instance.
This command is not supported in ASDM.
Clearing Secure-phone
Entries from the Phone
Proxy Database
The Cisco Phone Proxy feature includes the clear phone-proxy secure-phones command, which
clears the secure-phone entries in the phone proxy database. Because secure IP phones always
request a CTL file upon bootup, the phone proxy creates a database that marks the IP phones as
secure. The entries in the secure phone database are removed after a specified configured timeout
(via the timeout secure-phones command). Alternatively, you can use the clear phone-proxy
secure-phones command to clear the phone proxy database without waiting for the configured
timeout.
This command is not supported in ASDM.
H.239 Message Support
in H.323 Application
Inspection
In this release, the adaptive security appliance supports the H.239 standard as part of H.323
application inspection. H.239 is a standard that provides the ability for H.300 series endpoints to
open an additional video channel in a single call. In a call, an endpoint (such as a video phone),
sends a channel for video and a channel for data presentation. The H.239 negotiation occurs on the
H.245 channel. The adaptive security appliance opens a pinhole for the additional media channel.
The endpoints use open logical channel message (OLC) to signal a new channel creation. The
message extension is part of H.245 version 13. The decoding and encoding of the telepresentation
session is enabled by default. H.239 encoding and decoding is preformed by ASN.1 coder.
Table 4 New Features for ASA Version 8.2(1) (continued)
Feature Description
Comments to this Manuals