This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
One of my customer has WLC and AP which doesn't support TACACS so they want to to the device administration using RADIUS. We have completed the POC for the customer but need to understand the License consumption. Do we need to include device admin license along with the 100 base license or only base license is enough.
Solved! Go to Solution.
Every successful Radius Authentication&Authorization for an Endpoint will consume 1 base license. If the same Endpoint has 1000 repeat authentications then it's still only 1 base license consumed. The NAS should ideally send Radius Accounting to ISE, because ISE uses that to track the session for that endpoint - and when WLC sends accounting Stop for that endpoint, then ISE should free up the license for that endpoint.
If you don't send Radius accounting then ISE has some internal logic when it decides to free up the license. I forget what the time interval is - it's like 1 hour or something. it's very crude.