03-27-2014 08:09 AM - edited 03-10-2019 09:34 PM
Hi,
Just a question on ISE license consumption.
If a user logs in and gets authenticated (user authentication) via ISE on a device that is already authenticated (device authentication), does it consume 2 licenses, one for the device and one for the user?
This is nowhere clearly told in any cisco documentation.
Can anybody help me clarify this?
Thank you,
Mohan
03-27-2014 01:11 PM
No, it will not. The license consumption is not based on user but on the device. More specificially the MAC address of the device. So in your example, only a single license will be consumed. However, a single device can consume more than one license if for instance it authenticates on both wired and wireless or goes behind a docking station since a different MAC address will be presented to the system.
Hope this helps!
Thank you for rating!
12-10-2014 12:41 AM
and what happens if we use ISE just for basic AAA over radius as a replacement for ACS..for example, 500 routers&switches which need AAA for admin&management access..do we need 500 basic licenses or not?..
thanx..
regards..
12-10-2014 06:29 AM
Yes, you would need 500 Base Licenses. Note the table from the ISE 1.3 Admin Guide detailing the Base License needed for AAA:
Here is the link for reference:
Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question. Otherwise, feel free to post follow-up questions.
Charles Moreton
12-10-2014 10:39 PM
hi charles..
thanx on your answer..
regards..
06-05-2014 11:45 AM
Hi,
ISE always count the licenses on the base of endpoints connected.
Endpoints can be personal computers, laptops, IP phones, smart phones, gaming consoles, printers, and fax machines.
06-05-2014 08:18 PM
The base package includes all of the base services required to enable 802.1X, Guest, and Monitoring and Troubleshooting. The advanced package includes Posture, Profiler, and Security Group Access services.
Cisco ISE is bundled with a licensing mechanism that has the following important features:
•Built-in License—Cisco ISE comes with a built-in evaluation license, which is valid for 90 days. The evaluation license includes both base and advanced packages and limits the number of endpoints to 100 for both the base and advanced packages. Therefore, it is not required to install a regular license immediately upon installation.
•Central Management—Licenses are centrally managed by the ISE administration node. In a distributed deployment, where two ISE nodes assume the Administration persona (primary and secondary), upon successful installation of the license file, the licensing information from the primary Administration node is propagated to the secondary Administration node. So there is no need to install the same license on each Administration node within the deployment.
•Concurrent Endpoint Count—The Cisco ISE license includes a count value for base and advanced packages, which restricts the number of endpoints that use those services. The count value is the number of endpoints across the entire deployment that are concurrently connected to the network and accessing the service.
Concurrent endpoints represent the total number of supported users and devices. An endpoint can be any combination of users, personal computers, laptops, IP phones, smart phones, gaming consoles, printers, fax machines, or other types of network devices.
IMPORTANT : - Alarm is generated when the soft limit of endpoints is crossed and there is no functional impact on the users. To avoid service disruption, Cisco ISE continues to provide services to endpoints that exceed license entitlement. However there are plans to implement a hard limit on this soon.
Regards,
Jatin Katyal
** Do rate helpful posts **
06-05-2014 11:27 PM
06-06-2014 02:03 AM
A Cisco ISE user consumes a license during an active session. Once the sessions has ended, ISE releases the license for reuse by another user.
The Cisco ISE license is counted as follows:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide