01-12-2017 04:40 AM - edited 03-10-2019 06:45 AM
Hello everyone
I've had a 5506-X with full licenses (malware, URL, ..) for quite a while now. Recently I additionally installed the Management Center and registred my 5506-X to it.
Well, and that's how far I am right now. I thought, before going further, I should get my licenses activated. I feel kind of stupid for not even getting this done to be honest... :-) So, what am I doing wrong? My licenses on the 5506 kinda just disappeared. At the device management in the FMC I see my device as unlicensed but can't license it, since it is grayed out.
I tried "System - Licenses - Classic Licenses" but my licenses won't work since the license key is different.
Thanks for anything, have a good day!
Solved! Go to Solution.
01-16-2017 04:06 AM
You're welcome.
The next FTD release (6.2 - due out very soon) will NOT have remote access VPN. We hope to see it in the subsequent one but Cisco doesn't commit until the code is in final QA and looking good.
You can migrate existing ASA FirePOWER services license to FTD type. If you have the IPS only (TA) "license" (technicaly a subscription) then you need to open a case the Cisco TAC - Global Licensing Organization (GLO) team.
Smart licenses need to be tied to an organization - or technically the holder of a support contract. (That's 99% of the time an organization.) I suppose if you had your own Samrtnet contract or license and it was associated with your personal email that you could register "yourself@whatever.com" and get it that way. Smart licensing by itself has no fee but the licenses you buy do have a cost. If you work for a Cisco partner, there are lab licenses avaialable but those are not offered to customers or other end users.
01-12-2017 04:43 AM
Quick follow-up question; do I have to "Tranfser/Rehost" my licenses to my Management Center "device"? Speaking about the Cisco license administration portal of course...
01-13-2017 07:41 AM
If you were origianlly licensed and using ASDM, moving to FMC does indeed require you to rehost the licenses. When you are doing centralized management from an FMC, the licenses are actually issued to its license key. You then assign them to any managed ASAs. You will only have that option (i.e non-grayed out check boxes) once you host the licenses on the FMC.
01-13-2017 09:10 AM
Hello Marvin
Thanks for your reply. I did that and it worked as you described.
Can you tell me something about the lcensing of the FMC itself?
01-15-2017 10:10 PM
As of version 6.0, classic licenses (i.e. a PAK with a license key) are no longer required for FMC. It's a bit confusing since Cisco still issues PAKs for it. However when you try to redeem them, you will get the error you saw. The managed sensors with FirePOWER software (but not those with FirePOWER Threat Defense - FTD) do continue to use classic licenses managed in your FMC (or ASDM if you are using that method).
If you are managing FTD image devices with FMC, then you do need to register it in the Cisco "smart" licensing portal so you can associate the devices' smart licenses with it.
I agree it is a very confusing process at this time. I have already given feedback to Cisco sales to that efect.
01-16-2017 12:58 AM
Thanks, that's helpful :-)
Regarding the smart licensing; let's say I want to re-image my ASA with the FTD image. Do I need new licenses?
I currently have my 5506-X fully licensed and the (rather useless?) FMC license for two devices.
Edit: I've read, there should be something like "convert to smart license" in the licensing portal? I'm quite sure I do not have an option like this...
01-16-2017 02:26 AM
You're welcome.
You can rehost your licenses from the ASDM you were originally using to FMC. That would be useful to you.
Migrating to FTD is a big step and there are several features (most notably remote access VPN - i.e., AnyConnect-based) that are not available yet on FTD. Yes - all FTD requireds Smart Licensing once the original buil-in trial license expires. If your organization and/or your account have never used Smart Licensing before you will have to register for that first prior to performing and Smart Licensing actions.
01-16-2017 03:46 AM
Oh I think I misguided you a little bit. I indeed have rehosted my device licenses to the FMC. That's for the most part at working well. The only thing I don't really get is the supossed 50000 FMC licenses I apparently have... but.. as long as it's working.. :-)
I've read about the lack of VPN functionality with FTD, which is - sadly - a show-stopper for me. But since we're both here, I still gonna have some questions, the future implementation in my mind.
- Is there any news, when the next release (hopefully with VPN) will come out?
- As far as my understanding goes right now, I don't have to purchase new licenses for FTD, I just have to "migrate" my existing ones?
- Since I do all the FirePOWER etc. related stuff in my stare time (and I don't really see my organization implementing these features soon), is there a possibility to register for Smart Licensing without it being linked to my/any organization?
- I do have kind of a feeling that I have to pay for the Smart Licensing, right? :-)
Thanks again for the help, I really appreciate your "services" :-)
01-16-2017 04:06 AM
You're welcome.
The next FTD release (6.2 - due out very soon) will NOT have remote access VPN. We hope to see it in the subsequent one but Cisco doesn't commit until the code is in final QA and looking good.
You can migrate existing ASA FirePOWER services license to FTD type. If you have the IPS only (TA) "license" (technicaly a subscription) then you need to open a case the Cisco TAC - Global Licensing Organization (GLO) team.
Smart licenses need to be tied to an organization - or technically the holder of a support contract. (That's 99% of the time an organization.) I suppose if you had your own Samrtnet contract or license and it was associated with your personal email that you could register "yourself@whatever.com" and get it that way. Smart licensing by itself has no fee but the licenses you buy do have a cost. If you work for a Cisco partner, there are lab licenses avaialable but those are not offered to customers or other end users.
01-16-2017 05:43 AM
Well that's unfortunate... I guess I'll start looking into it when AnyConnect becomes available. Thanks for the detailed explanation anyway!
07-28-2017 08:16 AM
I suspect i might be doing something wrong, but i have hosted the license on FMC version 6.2.1 is what i am using. However, i still cannot enable the license on the device tab.
07-29-2017 06:42 AM
[@david.funmi@eu.didata.com] ,
Are you using classic licenses (i.e. anything other than FTD)? What sensor type? If it's an ASA FirePOWER service module you need the free Control license first before you can apply IPS, URL or Malware licenses.
07-31-2017 04:11 AM
07-31-2017 04:34 AM
The Control license is provided in the box with the ASA as a printed form with the PAK on it.
If you don't have it anymore, there are a couple of routes you can take:
1. If you purchased through a Tier 1 reseller or partner they can call it up in the Cisco order fulfillment system (the PAK shows up as part of the delivered hardware).
2. You can open a case with TAC (ask for Global Licensing Operations or GLO team) and provide the serial number and they can do the same.
3. You can email licensing@cisco.com for it.
In any case it is definitely required. You cannot apply any other licenses or deploy access control policies without it.
01-12-2017 05:38 AM
Activate your FMC first. The license key uniquely identifies the Firepower Management Center in the Cisco License Registration Portal. It is composed of a product code (66) and the MAC address of the Firepower Management Center; for example, 66:00:00:77:FF:CC:88.
You must use the license key in the Cisco License Registration Portal to obtain the license text required to add licenses to the Firepower Management Center.
Make sure you have the product activation key (PAK) from the Software Claim Certificate that Cisco provided when you purchased the license. If you have a legacy, pre-Cisco license, contact Support.
For more info see the below link
Hope this help you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide