cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
906
Views
0
Helpful
4
Replies

ise 2.6 license required for anyconnect/asa radius authentication with ISE

nareh84
Level 3
Level 3

hi

 

 

I have currently deployed ISE2.6 (demo license). on ASA, anyconnect authentication points to ISE2.6. once user successfully authenticates, DACL is applied to user. at ISE end, its integrated with AD (for group information) and ASA is configured as radius device.

 

when i login via anyconnect, i am not seeing any license consumed, i am not sure whether any type of ISE license (base) is required for this setup. if yes then whether 1 base license is required for ASA or it depends on number of users using anyconnect at any given point of time?

 

 

4 Replies 4

pavagupt
Cisco Employee
Cisco Employee

ISE License consumption is based on services and sessions. A base license is consumed for every active session and utilizing posture service on top of it consumes apex license.   That's the expectation.

 

 

thomas
Cisco Employee
Cisco Employee

Specifically ISE active endpoint counts are determined by RADIUS Accounting Start/Stop messages.

Ensure you have configured RADIUS Accounting on your ASA.

 

hi

 

 

I only need authentication and authorization (DACL). it means if i dont enable accounting, it will not consume any ise license?

 

 

Regards

 

Naray

Every active session (including authentication/authorization ) will consume a base license. Accounting in ISE will ensure session handling/management better.