11-09-2015 08:00 AM - edited 03-10-2019 11:13 PM
Hello,
Trying to locate the SKU to enable cisco Tacacs+ (Device Administration) license. Should be ~$4500 - but not finding it. Anyone had any luck?
Thank you!
j
Solved! Go to Solution.
11-09-2015 08:38 AM
07-12-2016 08:33 PM
[@glenn.costantino]
No - the Device Administration feature is licensed for the deployment regardless of the number of devices using the feature.
11-09-2015 08:38 AM
07-12-2016 12:08 PM
The ordering guide states you need a minimum 100 ISE base licenses to use the TACACS feature - Device Administration but there is no Large deployment license like in the past - is it safe to say you need a base license for every switch that you are trying to manage administrative access to? for example 425 network switches would require the L-ISE-BSE-500 license?
07-12-2016 08:33 PM
[@glenn.costantino]
No - the Device Administration feature is licensed for the deployment regardless of the number of devices using the feature.
01-17-2017 09:52 PM
@marvin rhoads
Do you mean if I have 3 network administrators, I require 3 Device Administration license only?
How does Device Administration license work? Does it release license when administrator finish the authentication?
Thank you.
01-17-2017 10:50 PM
01-18-2017 12:28 AM
Thank you [@mrhoads-cco]
09-21-2017 05:05 AM
Means If I have 10 devices authenticated via TACACS, it will counted as 10 base license required?
Assumed I have L-ISE-TACACS= install already.
In another scenario, if I have 10devices authenticated via Radius, it wouldn't be any base license required. Right?
09-21-2017 07:48 AM
TACACS+ user authentications for device administration do not consume base licenses. As long as you have the TACACS license installed you can authenticate users for device adminstration as the deployment type will scale to.
If you are using RADIUS for device administration then the user sessions are RADIUS sessions and consume base licenses just as if they were a wired, wireless or VPN endpoint using RADIUS authentication for network access..
01-11-2019 10:59 AM
Glenn,
we have ACS and ISE 1.4 in our deployment and we are going through ISE 2.3 deployment,
Since we already purchased permanent base and license for 5K endpoints and is currently applied to ISE 1.4 deployment
we are not buying new base and plus license for new ISE 2.3 deployment
our plan is to migrate the licenses from ISE 1.4 to ISE 2.3 and all the network devices on our network at the same time to new ISE 2.3 deployment.
But while we are testing and validating 802.1x part of the new ISE 2.3 deployment we want to continue migrating device from ACS to ISE 2.3 for device administration.
I know that you need to have base license to apply device admin license and you can't even apply permanent device admin license with base evaluation license.
So we convinced our cisco rep to give us temporary base and plus license for 100 endpoints for 90 days, so we can apply our permanent device admin license and work with device migration for device administration.
Now our base and plus license is going to expire in 25 days.
what will happen to my device admin license if my base license expires?
will tacacs continue to work and will I be able to add new network devices for TACACS?
07-13-2016 09:41 AM
To add to what Marvin already said: Compared to ACS where the license was based on the number of NADs, in ISE the Base/Plus/Apex licenses are based on the number of endpoints (PCs, Mobile Devices, etc)
Thank you for rating helpful posts!
07-13-2016 03:48 PM
Thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide