12-16-2020 02:47 AM
am i correct? for ordering the TACACS+ component for HA and VMware deployment
1. 2 units of R-ISE-VMS-K9. Cisco ISE Virtual Machine Small
2. 2 units of L-ISE-TACACS-ND Cisco ISE Device Admin Node License
i have 500 network devices. So how many Device Admin Node License do i need ?
and do i still need to order 100 ISE BASE License ?
Solved! Go to Solution.
12-16-2020 04:04 PM
2 units of R-ISE-VMS-K9. Cisco ISE Virtual Machine Small
2 units of L-ISE-TACACS-ND Cisco ISE Device Admin Node License
You are correct.
From http://cs.co/ise-licensing:
1.9.3 How do I license Device Administration
● License that enables Device Administration: Device Admin License
● License consumption: Device Administration licenses are consumed per policy service node. You must have Device Administration license for each of the policy service nodes that you enable TACACS+ service on. Device Administration using TACACS+ does not consume endpoints, and there is no limit on network devices for Device Administration. The user does not require a legacy base license.
12-16-2020 03:25 AM
here is the License information :
If your device are 500 and not going to more in the future, but i suggest to look 500-999 License
12-16-2020 04:56 AM - edited 12-16-2020 05:00 AM
Hi @passakorn.m
If you have 2 ISE PSN, then you will need 2 x Device Administration licenses
Reference:-
"License consumption: Device Administration licenses are consumed per policy service node. You must have Device Administration license for each of the policy service nodes that you enable TACACS+ service on. Device Administration using TACACS+ does not consume endpoints, and there is no limit on network devices for Device Administration. The user does not require a legacy base license."
HTH
12-16-2020 04:04 PM
2 units of R-ISE-VMS-K9. Cisco ISE Virtual Machine Small
2 units of L-ISE-TACACS-ND Cisco ISE Device Admin Node License
You are correct.
From http://cs.co/ise-licensing:
1.9.3 How do I license Device Administration
● License that enables Device Administration: Device Admin License
● License consumption: Device Administration licenses are consumed per policy service node. You must have Device Administration license for each of the policy service nodes that you enable TACACS+ service on. Device Administration using TACACS+ does not consume endpoints, and there is no limit on network devices for Device Administration. The user does not require a legacy base license.
12-16-2020 07:20 PM
To answer your question about the 100 Base licenses, it depends on what version of ISE you are deploying.
With ISE 2.7 and earlier, Base licenses are required with the Device Admin licenses as stated in the Admin Guide:
"A Base or Mobility license is required to install the Device Administration license."
The smallest bundle of Base licenses you can purchase is 100, so that will be plenty for Device Admin functions.
With ISE 3.0, the new 'nested doll' licensing model does not require Essentials licenses to enable the Device Admin feature, so you only need Device Admin licenses.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide