06-18-2021 12:35 AM
Good Day,
We have an environment that has multiple users who attach to network with Cisco Anyconnect VPN and ASA Firewalls. We are using Cisco ACS server at the moment ; but are looking to migrate to the ISE product in the coming weeks.
The anyconnect clients are licensed on the firewall to connect.
The users are authenticated with ACS and AD.
I am trying to find out if I need the Apex license on the ISE server to allow these same users to login to the network via VPN or if I can get by with only the Base and Plus license.
The ISE server is running version 2.7 and has Base and Plus permanent licenses.
The old ACS server has a "large deployment' permanent license.
Thanks in advance.
Regards
Amanda
Solved! Go to Solution.
06-18-2021 01:39 AM - edited 06-18-2021 01:40 AM
For your use case, you only need the AnyConnect license as defined by your VPN gateway. You probably have PLUS enabled on the ASA and the ISE does not need anything more. You directly can authenticate and authorize your users on the ISE.
If you want to add a compliance check of the VPN-devices at a later point, you need the APEX (or PREMIER after upgrading to ISE 3) licenses on the ISE *and* APEX licenses for AnyConnect.
06-18-2021 01:39 AM - edited 06-18-2021 01:40 AM
For your use case, you only need the AnyConnect license as defined by your VPN gateway. You probably have PLUS enabled on the ASA and the ISE does not need anything more. You directly can authenticate and authorize your users on the ISE.
If you want to add a compliance check of the VPN-devices at a later point, you need the APEX (or PREMIER after upgrading to ISE 3) licenses on the ISE *and* APEX licenses for AnyConnect.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide