<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for posting your test in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053905#M22747</link>
    <description>&lt;P&gt;Thanks for posting your test results here. Pretty much what I have seen in my deployments. This should answer the OP's query.&lt;/P&gt;</description>
    <pubDate>Fri, 26 May 2017 02:00:48 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2017-05-26T02:00:48Z</dc:date>
    <item>
      <title>ISE Profiling and Basic / Plus Licensing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053897#M22734</link>
      <description>&lt;P&gt;Can anyone help me with understanding the plus license on ISE with respect to Profiling.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been having a discussion with another engineer who says that with the basic license you can perform profiling but you would not be able to enforce any policies with that information without the plus license.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I would be able to see what is on my network with profiling using basic license but not enforce policies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone had any experience with this as I need to clear this point up before I start a POC&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053897#M22734</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2019-03-11T07:44:31Z</dc:date>
    </item>
    <item>
      <title>ISE Ordering Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053898#M22735</link>
      <description>&lt;P&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf"&gt;ISE Ordering Guide &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/table_6.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Additional information can be found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0101.html#id_24976"&gt;Cisco ISE License Model - ISE 2.2 Admin Guide &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Profiling requires the Plus License, whether you are doing enforcement or not.&lt;/P&gt;
&lt;P&gt;Each session will consume a Base License.&amp;nbsp; To begin Profiling, you must then consume a Plus license.&amp;nbsp; From there, your authentication and authorization policy will do the enforcement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The process won't even start if you do not have the license.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 18:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053898#M22735</guid>
      <dc:creator>jonathan.cuthbert</dc:creator>
      <dc:date>2017-05-24T18:36:02Z</dc:date>
    </item>
    <item>
      <title>"To begin Profiling, you must</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053899#M22738</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;"&lt;SPAN&gt;To begin Profiling, you must then consume a Plus license"&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;I believe this may be incorrect. Plus license is only consumed when a profiling condition is used in an Authz policy. This is documented in the ordering guide posted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also documented in the old &lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_30_ise_profiling.pdf"&gt;ISE Profiling design guide&lt;/A&gt; is this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;"One Advanced Endpoint license is required for each endpoint that is actively authenticated to the network and where profiling data is used to make an Authorization Policy decision. Not taking into account other services, such as posture assessment, that may require an Advanced Endpoint license, endpoints that are statically assigned to a profile do not consume an Advanced license. &lt;STRONG&gt;It is possible to profile multiple endpoints and have visibility into connected devices and their classification without requiring an Advanced Endpoint license for each if the profile information is not used to authorize the endpoint&lt;/STRONG&gt;. "&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;The Advanced Endpoint license = new Plus + Apex , so I would assume that you would not need a Plus license for ISE just to profile endpoints.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 01:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053899#M22738</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-05-25T01:15:42Z</dc:date>
    </item>
    <item>
      <title>Rahul,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053900#M22740</link>
      <description>&lt;P&gt;Rahul,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That design guide is back from 2012 which was around ISE 1.0 times.&amp;nbsp; Advanced licenses have been gone since ISE 1.2.&amp;nbsp; While you can still apply ISE licenses to current ISE, they are decomposed into Plus and Apex.&amp;nbsp; Things are completely different.&amp;nbsp; Let's not get lost in the semantics here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;First, &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0101.html#id_24976"&gt;Cisco ISE License Model:&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/plus_license.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And Cisco ISE &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0101.html#concept_F7FC0B895D284727B8E3DDDBCAD1A23A"&gt;Traditional License Consumption:&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/plus_consumption.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;While I did not get involved in the technical detail, my original statement is accurate.&amp;nbsp; To do profiling, which is a licensed feature, a Plus license is required and consumed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Plus license is only consumed when a profiling condition is used in an Authz policy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can't have a AuthZ policy without a AuthC policy.&amp;nbsp; That's mandatory.&amp;nbsp; You make your AuthZ policy based on what you find in the AuthC policy, such as type of device, ie &lt;STRONG&gt;profiling&lt;/STRONG&gt;. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 02:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053900#M22740</guid>
      <dc:creator>jonathan.cuthbert</dc:creator>
      <dc:date>2017-05-25T02:02:36Z</dc:date>
    </item>
    <item>
      <title>So I need to go and buy some</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053901#M22743</link>
      <description>&lt;P&gt;So I need to go and buy some Plus license if I want to do profiling ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 08:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053901#M22743</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2017-05-25T08:09:49Z</dc:date>
    </item>
    <item>
      <title>From ISE Plus licensing Q&amp;A:</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053902#M22744</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From ISE Plus licensing Q&amp;amp;A:&lt;/P&gt;
&lt;P&gt;Q.When is a Plus license consumed?&lt;BR /&gt;A. A Plus license is consumed when the “Registration” status or an Endpoint Profile is used within an authorization policy rule&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 08:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053902#M22744</guid>
      <dc:creator>jonathan-jackson</dc:creator>
      <dc:date>2017-05-25T08:57:14Z</dc:date>
    </item>
    <item>
      <title>Thank you for that</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053903#M22745</link>
      <description>&lt;P&gt;Thank you for that information.&amp;nbsp; That must be from a slightly older version.&amp;nbsp; From the current &lt;A href="http://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf"&gt;ordering guide&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/relationships_between_services_and_license_consumption.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;I think we are getting lost a little in the semantics here. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This is a pre-sales licensing question.&amp;nbsp; It is not a post-sales deep dive into how the back end actually works.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If profiling is desired, the Plus License is mandatory.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053903#M22745</guid>
      <dc:creator>jonathan.cuthbert</dc:creator>
      <dc:date>2017-05-25T13:46:03Z</dc:date>
    </item>
    <item>
      <title>Thanks for raising this</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053904#M22746</link>
      <description>&lt;P&gt;Thanks for raising this question - I have also wondered about this for a while.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/endpointprofile.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have tested this and found that no Plus license is consumed&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;while Profiling is enabled and&lt;/LI&gt;
&lt;LI&gt;if the Profiling data is not used in any AuthZ Policies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;TABLE class="content_table" style="table-layout: fixed;" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;LicenseTypes&lt;/TD&gt;
&lt;TD width="69%" id="eapKey" style="-ms-word-wrap: break-word;"&gt;Base license consumed&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The upside of enabling Profiling without a license is that the device type can be displayed in the Endpoint&amp;nbsp;Profile field in Live Logs - and also in the Endpoints Dashboard pie chart.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a bit of free&amp;nbsp;information about the device manufacturer courtesy of the MAC OUI.&amp;nbsp; Decoding that should not incur a Plus license count, which it doesn't - and shouldn't.&lt;/P&gt;
&lt;P&gt;I only enabled RADIUS Probe&amp;nbsp;under Profiling Service in my case.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 01:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053904#M22746</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-05-26T01:13:09Z</dc:date>
    </item>
    <item>
      <title>Thanks for posting your test</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053905#M22747</link>
      <description>&lt;P&gt;Thanks for posting your test results here. Pretty much what I have seen in my deployments. This should answer the OP's query.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 02:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3053905#M22747</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-05-26T02:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Ordering Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3208032#M22748</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help about this new feature&amp;nbsp;"Anomalous Endpoint Detection"&amp;nbsp; To configure this new feature on my environment it's necessary to buy License plus OR it no needed and i can configure with basic license? Now I'm on ISE 2.1 version and think to go on 2.3 any suggestion about this hop?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 10:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3208032#M22748</guid>
      <dc:creator>Sanath</dc:creator>
      <dc:date>2017-10-31T10:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Thanks for raising this</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3678117#M22749</link>
      <description>&lt;P&gt;Hi, One thing though that I am wondering about: Has there been a plus license installed on this test-system, even if it states the license was not consumed? I wonder if the feature is enabled/ disabled by simply having the license installed, even if is just the evaluation license..&lt;/P&gt;
&lt;P&gt;BR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 09:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-basic-plus-licensing/m-p/3678117#M22749</guid>
      <dc:creator>Patrick Meyer</dc:creator>
      <dc:date>2018-07-31T09:06:21Z</dc:date>
    </item>
  </channel>
</rss>

