cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
459
Views
2
Helpful
4
Replies

ISE Tacacs licenses

manvik
Level 3
Level 3

What all license are required in Cisco ISE 3.x.x for Tacacs AAA alone to work for Network switches/Devices.
Currently I have 2500 Network devices, am planning to increase it to 4500. 
Should I buy any additional license for this or Change VM capacity.

1 Accepted Solution

Accepted Solutions

@manvik you would need a Device Administration license on each PSN. https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/ise-licensing-guide-og.html If you already have these licenses and are just increasing the number of NADs you don't need to purchase additional licenses.

What VM spec do you have configured? Check the performance and scale guide to determine if you need to increase spec - https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html

 

View solution in original post

4 Replies 4

@manvik you would need a Device Administration license on each PSN. https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/ise-licensing-guide-og.html If you already have these licenses and are just increasing the number of NADs you don't need to purchase additional licenses.

What VM spec do you have configured? Check the performance and scale guide to determine if you need to increase spec - https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html

 

from this downloads which ova file shd i download (Medium, Small or large) for 5000 endpoints.

https://software.cisco.com/download/home/283801620/type/283802505/release/3.3.0

@manvik the small (for PSN) image should be fine for 5000 devices, but check the TACACS authentication rates in regard to Transactions per second as per link.

 

TACACS has many advantages over RADIUS for NADs management, but if for any reason you would want to use RADIUS to manage your NADs without buying TACACS licenses then please check this post of mine to see how you can do it:

Privilege Level 15 with Cisco ISE | Blue Network Security (bluenetsec.com)