cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2614
Views
4
Helpful
7
Replies

Smart Licensing Authorization Expired: Details=AuthorizedPeriodExpired

I am running ISE 3.1 patch-5 on SNS-3655 and for the past two weeks, I am getting these messages via email every hours from the ISE:

- Smart Licensing Authorization Expired: Details=AuthorizedPeriodExpired.

- Smart Licensing Id Certificate renewal failure: Details=Invalid response from licensing cloud.

- Smart Licensing Authorization Expired: Details=Smart Licensing authorization expired

I searched the bug ID and it looks similar to this CSCwa13877; however, the issue was related to Cisco DataCenter and it was resolved more than a year ago.  Furthermore, it is fixed in 3.1 patch 2 or patch 3 and I am currently on patch-5.

Any ideas?

2 Accepted Solutions

Accepted Solutions

Hi @Arne Bier:  I got the problem resolved and here is what I did, even though ISE is allowed to communicate with smartreceiver.cisco.com:

1- Upgraded to patch-5,

2- reboot, 

3- after reboot, the ISE still communicated with tools, tools1, tools2, and tools3.cisco.com,

4- De-register & Register the ISE node with a new token from the licensing portal,

5- after step 4, the ISE no longer communicates with tools.cisco.com, only with smartreceiver.cisco.com,

I think the documentation from Cisco needs to be updated when patch-5 is applied to the system, IMHO.

 

View solution in original post

Thank you! Re-registering with a new token resolved the problem for me.

View solution in original post

7 Replies 7

Arne Bier
VIP
VIP

Hi @adamscottmaster2013 

This situation varies over time and if you've done everything right on your end (i.e. have all the correct trusted certs in ISE, and ISE can talk out to the internet) then the issue could be the intermittent nature of the Cisco service.

Having said that - as you know, since patch 5, ISE talks to a new URL - it used to be tools.cisco.com - now it's smartreceiver.cisco.com

Has this been looked into?

I am actively avoiding patch 5 because of the issue with Cisco phone certs (CAPF-signed) not working due to some TLS issue.

Hi @Arne Bier:  I got the problem resolved and here is what I did, even though ISE is allowed to communicate with smartreceiver.cisco.com:

1- Upgraded to patch-5,

2- reboot, 

3- after reboot, the ISE still communicated with tools, tools1, tools2, and tools3.cisco.com,

4- De-register & Register the ISE node with a new token from the licensing portal,

5- after step 4, the ISE no longer communicates with tools.cisco.com, only with smartreceiver.cisco.com,

I think the documentation from Cisco needs to be updated when patch-5 is applied to the system, IMHO.

 

Thank you! Re-registering with a new token resolved the problem for me.

Does re-registration interupt services?

Adamscottmaster2013,

Did the re-register require a maintenance window? Does it interupt services?

@DannyDulin:  I couldn't tell because the ISE that I have only uses for Device Administration and not 802.1x, wired, wireless.  Therefore, I didn't notice any interruption during the re-registration of the licensing.  YMMV.

I am experiencing this issue and plan to use a maintenance window. As I understand it, there is no interruption if the evaluation period still has some time on it. However, I experienced a bug a while back that TAC had to fix that depleted the our evaluation period. So, I suspect there may be an interruption when I do the fix. I was planning to upgrade to 3.2.0, patch 8, but think I'll fix this first.

Does anyone know if upgrade to 3.2.0 resolves the issue without having to deregister/re-register? Or do you still have to fix the registration?