cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1096
Views
0
Helpful
2
Replies

ISE Plus License usage

GRANT3779
Spotlight
Spotlight

When exactly does a Plus License get used?

 

 

I have profiled Cisco Phones that Authenticate via MAB and then pass the following authorisation policy -

"If Device is in Endpoint Identity Group / Profiled / Cisco IP Phones then allow access to voice domain"

 

The phone authorises fine but I do not see a Plus license being used.

 

I would have thought because the auth policy is checking a group which contains profiled devices a plus license would be used upon access to the network.

 

2 Replies 2

Arne Bier
VIP
VIP

Good question - the exact mechanics of how licenses are consumed is not well explained by Cisco.  The closest answer I have read is exacly what you mentioned.  However - your AuthZ policy is not referring to a profiling attribute.  You are simply checking whether a device is in an Endpoint Group.  That comes for "free" with the base license, because Endpoint Identity Groups are used for multiple purposes.

I don't have a concrete example, because I don't have PLUS (or EVAL) licenses, but if you were to start doing fancy AuthZ policies that involve conditions about the stuff you found as a result of profiling, then I would assume you'd consume a PLUS license. 

Hi Arne,

 

Yes I guess that makes sense. I may test a few different auth profiles to see if I can find some consistency as to when a plus license is used.

Thanks