cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9711
Views
10
Helpful
5
Replies

ISE and Anyconnect License

ramikamel911
Level 1
Level 1

Hello Guys,

As you know, Anyconnect is used now instead of NAC Agent, do we require to purchase a license for that?

Regards

1 Accepted Solution

Accepted Solutions

Whether you need AnyConnect licenses with ISE depends on how you are using ISE.

If you want to use AnyConnect NAM as the 802.1x supplicant, that requires AnyConnect Plus. In that case, AnyConnect can be deployed from ISE as part of client provisioning. If can also be pre-deployed outside of ISE either manually or via your enterprise software deployment tools (like Windows GPO or Microsoft SCCM).

If you also or instead want to use AnyConnect for Posture Assessment then you require AnyConnect Apex licenses. (The Apex license also includes right to use the NAM feature.) Here, we can also deploy AnyConnect from ISE during the Posture Assessment process.

In both use cases where we deploy from ISE, the AnyConnect software (pkg file you may be familiar with from ASA use) can be uploaded onto the ISE server along with the associated profile.xml file that governs its behavior.

There is no license file or technical check that you have the license for AnyConnect. It is the administrator's responsibility to be compliant.

View solution in original post

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes. If you are deploying AnyConnect as an access agent (NAM) or ISE Posture module you require either AnyConnect Plus or Apex licenses. (Apex includes all AnyConnect features.)

ISE does not enforce the license use but it is required to be compliant with AnyConnect licensing terms.

Hi Marvin,

Thanks for your reply.

In my setup, I will order ISE-PLS and ISE-APX, do still I need Anyconnect Plus/Apex?

And as I know, Anyconnect can't be installed on ISE, it should be installed on ASA.... where the Anyconnect license will be installed? and how many users I will be going to require? for example, I've 500 users ISE-PLS & ISE-APX. 

Regards.

Whether you need AnyConnect licenses with ISE depends on how you are using ISE.

If you want to use AnyConnect NAM as the 802.1x supplicant, that requires AnyConnect Plus. In that case, AnyConnect can be deployed from ISE as part of client provisioning. If can also be pre-deployed outside of ISE either manually or via your enterprise software deployment tools (like Windows GPO or Microsoft SCCM).

If you also or instead want to use AnyConnect for Posture Assessment then you require AnyConnect Apex licenses. (The Apex license also includes right to use the NAM feature.) Here, we can also deploy AnyConnect from ISE during the Posture Assessment process.

In both use cases where we deploy from ISE, the AnyConnect software (pkg file you may be familiar with from ASA use) can be uploaded onto the ISE server along with the associated profile.xml file that governs its behavior.

There is no license file or technical check that you have the license for AnyConnect. It is the administrator's responsibility to be compliant.

Quick Question Marvin, before licensing activation of ASA , does it come with APEX License as Default. ?

Cisco ASA hardware appliances come with two AnyConnect "Premium" licenses by default. That's roughly equivalent to the current Apex tier (but without AnyConnect for Mobile or Advanced Endpoint Assessment).