12-02-2019 03:43 AM - edited 02-21-2020 09:44 AM
All,
Have 2 5525 ASA's with Source Fire with URL/IPS and AV license for both SF modules
planning to bring in a firepower management center virtual appliance to mange SF modules for HA
could advise me on the license that I need to purchase
Solved! Go to Solution.
12-02-2019 09:46 PM
The FMC license is only for FMC to manage the devices. 2 of them in this case.
You need to add the licenses of the managed Firepower service modules themselves into FMC.
If you've already redeemed them for ASDM-based management, then you must rehost them to FMC (using software.cisco.com portal). FMC will then have them available and is used assign them to the Firepower service modules.
FTD devices work similarly except they use Smart licenses instead of PAK-based ones.
12-17-2019 06:39 AM
Correct you do not need to INSTALL a classic (PAK-based) license for FMC itself since version 6.0.
If you are managing FTD products with your FMC, then you must have it licensed via via the Cisco portal with a Smart software license.
Either way, you are still required to HAVE a license for right-to-use the product since it is not free.
12-02-2019 11:02 AM
Cisco offers 4 license options for the FMCv. The entry level one covers two devices such as you have.
The SKU (part number) is SF-FMC-VMW-2-K9.
We would typically combine it with a support contract. The part number for that is SF-FMC-VMW-2-K9. The support contract needs an associated term (usually 1, 3 or 5 years).
12-02-2019 09:09 PM
thank you, does SKU SF-FMC-VMW-2-K9 include license for URL/AV an IPS
what about my existing licenses
12-02-2019 09:46 PM
The FMC license is only for FMC to manage the devices. 2 of them in this case.
You need to add the licenses of the managed Firepower service modules themselves into FMC.
If you've already redeemed them for ASDM-based management, then you must rehost them to FMC (using software.cisco.com portal). FMC will then have them available and is used assign them to the Firepower service modules.
FTD devices work similarly except they use Smart licenses instead of PAK-based ones.
12-08-2019 02:17 AM
just another thing, do I need a separate license for FTD
12-08-2019 03:41 AM
Yes, FTD devices require licensing.
Technically you can run them with the free Base software license but almost nobody does so because you would not be availing yourself of many of the available features.
The available Firepower Threat Defense–related licenses and subscriptions include functionality like Security Intelligence and Next-Generation IPS (“T”), Advanced Malware Protection (“M”), and URL Filtering (“C”). They are available singly or in combination and for terms or 1-, 3- or 5-years.
There is also AnyConnect licensing (Plus or Apex) if you want to use remote access VPN.
12-17-2019 06:06 AM
Hi Marvin,
thanks a lot and sorry to trouble
I purchased the license and added the key using classic licensing, but it shows firesight license no longer required for FMC version 6 or higher
please advise
12-17-2019 06:39 AM
Correct you do not need to INSTALL a classic (PAK-based) license for FMC itself since version 6.0.
If you are managing FTD products with your FMC, then you must have it licensed via via the Cisco portal with a Smart software license.
Either way, you are still required to HAVE a license for right-to-use the product since it is not free.
12-17-2019 06:51 AM
thank you very much
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide