11-26-2020
03:04 AM
- last edited on
03-09-2022
11:25 PM
by
smallbusiness
01-25-2021 10:32 PM
For Catalyst switches, MACsec does not require any specific licensing.
For ASRs and other high end WAN devices, special licensing is required to use MACsec.
02-09-2021 10:08 AM - edited 02-10-2021 06:46 AM
Well hold up, there are some MACSEC licensing requirements, traditionally pre cat9k both TrustSec and MACSEC were IP base/IP services only feature sets.
LAN Base on older platforms does not have any MACSEC/CTS support
With the Cat9k, Essentials has partial support for MACSEC, but not CTS. If you want AES 256 support with MACSEC, then you require Network Advantage.
01-21-2021 08:15 AM
In regard to ISE licensing, the base session licenses are what you need to support link encryption (MACsec). Not sure what version you are running, but please note that as of late 2020 and ISE 3.0 there is a new licensing scheme introduced. See below for further detail:
Products - ISE 3.0 License Migration Guide - Cisco
HTH!
01-22-2021 12:30 AM
Hi Mike, thanks for your reply, there is no ISE in the deployment
we are using macsec with mka.
thanks again
01-25-2021 03:53 PM
MACsec is really a feature of the switch and endpoint that ISE has the option to require as part of the endpoint authorizations. It is a basic RADIUS feature in the Base (2.x) and Essentials (3.x) licenses.
02-09-2021 04:15 AM
thanks Thomas
01-25-2021 10:32 PM
For Catalyst switches, MACsec does not require any specific licensing.
For ASRs and other high end WAN devices, special licensing is required to use MACsec.
02-09-2021 04:14 AM
thanks Marvin, that means we don't need to renew our DNA advantage license every three years.
thanks
02-09-2021 10:08 AM - edited 02-10-2021 06:46 AM
Well hold up, there are some MACSEC licensing requirements, traditionally pre cat9k both TrustSec and MACSEC were IP base/IP services only feature sets.
LAN Base on older platforms does not have any MACSEC/CTS support
With the Cat9k, Essentials has partial support for MACSEC, but not CTS. If you want AES 256 support with MACSEC, then you require Network Advantage.
02-10-2021 01:07 AM
thanks for your reply Damien, yes we are using cisco CAT9K and looks like we will need to renew the dna advantage license after all then,
02-10-2021 09:40 AM
Note that MACsec-128 is included with the perpetual Network Essentials license though. That does not require any term license or recurring license cost.
03-23-2024 03:35 AM
Hi Marvin, what about C8500? does it require the special license or Hsec license ?
03-24-2024 07:57 PM
On the Catalyst 8500 platform, a MACsec license is required according to this document:
I can't find the SKU for ordering it but your reseller should be able to help you with that. If you are the reseller, you might reach out to the Partner Helpdesk for assistance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide