cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5451
Views
0
Helpful
11
Replies

Cisco Macsec and licenses

LionKin1984
Level 1
Level 1

Hello,

what is the license requirement for Cisco Macsec?

 

thanks

2 Accepted Solutions

Accepted Solutions

Well hold up, there are some MACSEC licensing requirements, traditionally pre cat9k both TrustSec and MACSEC were IP base/IP services only feature sets. 

LAN Base on older platforms does not have any MACSEC/CTS support
With the Cat9k, Essentials has partial support for MACSEC, but not CTS. If you want AES 256 support with MACSEC, then you require Network Advantage. 

View solution in original post

11 Replies 11

Mike.Cifelli
VIP Alumni
VIP Alumni

In regard to ISE licensing, the base session licenses are what you need to support link encryption (MACsec).  Not sure what version you are running, but please note that as of late 2020 and ISE 3.0 there is a new licensing scheme introduced.  See below for further detail:

Products - ISE 3.0 License Migration Guide - Cisco

HTH!

Hi Mike, thanks for your reply, there is no ISE in the deployment

we are using macsec with mka.

 

thanks again

thomas
Cisco Employee
Cisco Employee

MACsec is really a feature of the switch and endpoint that ISE has the option to require as part of the endpoint authorizations. It is a basic RADIUS feature in the Base (2.x) and Essentials (3.x) licenses.

image.png

thanks Thomas

thanks Marvin, that means we don't need to renew our DNA advantage license every three years.

thanks

Well hold up, there are some MACSEC licensing requirements, traditionally pre cat9k both TrustSec and MACSEC were IP base/IP services only feature sets. 

LAN Base on older platforms does not have any MACSEC/CTS support
With the Cat9k, Essentials has partial support for MACSEC, but not CTS. If you want AES 256 support with MACSEC, then you require Network Advantage. 

thanks for your reply Damien, yes we are using cisco CAT9K and looks like we will need to renew the dna advantage license after all then,

Note that MACsec-128 is included with the perpetual Network Essentials license though. That does not require any term license or recurring license cost.

https://www.cisco.com/c/en/us/products/collateral/switches/catalyst-9300-series-switches/nb-06-cat9300-ser-data-sheet-cte-en.html#Licensing

Hi Marvin, what about C8500? does it require the special license or Hsec license ?

On the Catalyst 8500 platform, a MACsec license is required according to this document:

https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-macsec-in-cisco-sd-wan.html#supported-devices-for-macsec-support-in-cisco-vmanage

I can't find the SKU for ordering it but your reseller should be able to help you with that. If you are the reseller, you might reach out to the Partner Helpdesk for assistance.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: