cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1318
Views
0
Helpful
3
Replies

Cisco ISE endpoint posturing with anyconnect apex license

pmlam3274
Level 1
Level 1

not long ago, I was told in order to use the anyconnect posture module, I will need to purchase the anyconnect apex license, which is fine. However what is odd to me is that the part number (L-AC-APX-3RY-G) is the same part number for the Cisco ASA SSL VPN license. So my question, will I able to use this anyconnect apex license that I purchase for Cisco ISE, on the Cisco ASA as well?  I am a little confused since I was also told the Anyconnect APEX license for Cisco ISE is honor based only.  Hopefully someone here can answer my question. 

1 Accepted Solution

Accepted Solutions

Rahul Govindan
VIP Alumni
VIP Alumni

Short answer is yes as it is the same license. The Anyconnect Apex (similar to the old Anyconnect Premium) adds the following functionality to the Anyconnect plus (old Anyconnect essentials) license:

Clientless (browser-based) VPN termination on the Cisco Adaptive Security Appliance
VPN compliance and posture agent in conjunction with the Cisco Adaptive Security Appliance
Unified compliance and posture agent in conjunction with the Cisco Identity Services Engine 1.3 or later
Next-generation encryption (Suite B) with AnyConnect and third-party (non-AnyConnect) IKEv2 VPN clients
Network Visibility Module (new in 4.2)

So both the Posture and the VPN is covered under the same license. You would just have to purchase the right count for the number of concurrent VPN users in your environment.

More information about the licenses are here:

http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200191-AnyConnect-Licensing-Frequently-Asked-Qu.html#anc16

View solution in original post

3 Replies 3

Rahul Govindan
VIP Alumni
VIP Alumni

Short answer is yes as it is the same license. The Anyconnect Apex (similar to the old Anyconnect Premium) adds the following functionality to the Anyconnect plus (old Anyconnect essentials) license:

Clientless (browser-based) VPN termination on the Cisco Adaptive Security Appliance
VPN compliance and posture agent in conjunction with the Cisco Adaptive Security Appliance
Unified compliance and posture agent in conjunction with the Cisco Identity Services Engine 1.3 or later
Next-generation encryption (Suite B) with AnyConnect and third-party (non-AnyConnect) IKEv2 VPN clients
Network Visibility Module (new in 4.2)

So both the Posture and the VPN is covered under the same license. You would just have to purchase the right count for the number of concurrent VPN users in your environment.

More information about the licenses are here:

http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200191-AnyConnect-Licensing-Frequently-Asked-Qu.html#anc16

Thank you for the info.  Since the apex license can be use both on Cisco ISE and Cisco ASA, does it mean I can register the same license to both systems?

pmlam3274
Level 1
Level 1

Rahul,

If I purchase the L-AC-APX-3Y-S5 for 1000 users, do you know if I can split it 500 each and apply it to 2 different ASA?