cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2992
Views
2
Helpful
8
Replies

FTD Smart Licensing Offline Activation

taro75
Level 1
Level 1

If I have to deploy FTD in an offline (no active internet) how can I activate the smart licenses? Is there any specific part number I can order during the procurement for offline license activation?

1 Accepted Solution

Accepted Solutions

Internet connectivity is not mandatory during the 90-day evaluation period.

If you require a licensed device past the 90-day period you have two options:

1. The Smart Software Manager (SSM) satellite server as mentioned already in this thread by @Rob Ingram 

2. Permanent License Reservation (PLR) - a scheme that requires Cisco account manager to sponsor you for approval and is typically only granted for government and military systems that are kept totally apart from the Internet for security purposes. Details on that can be found here:

https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-license.html#id_123878

View solution in original post

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

Additionally, it will work with the included evaluation license for up to 90 days. No Internet is required for that.

Keep in mind also that the FMC will need intermittent access to internet or the smart license satellite server to be able to check and update license status.

--
Please remember to select a correct answer and rate helpful posts

taro75
Level 1
Level 1

My query is that I do not have any Internet connectivity from firewall to the Internet, is it not possible to get the licenses from Cisco which does not require any Internet connectivity. I can update the IPS signatures offline. Is the Internet connection and verification mandatory with new devices? 

Internet connectivity is not mandatory during the 90-day evaluation period.

If you require a licensed device past the 90-day period you have two options:

1. The Smart Software Manager (SSM) satellite server as mentioned already in this thread by @Rob Ingram 

2. Permanent License Reservation (PLR) - a scheme that requires Cisco account manager to sponsor you for approval and is typically only granted for government and military systems that are kept totally apart from the Internet for security purposes. Details on that can be found here:

https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-license.html#id_123878

taro75
Level 1
Level 1

I need PLR, I believe it's a zero cost item. I need this because firewalls are in plant (OT) setup. Is there any restrictions in getting this license?

 

Also with smartnet, I am entitled to download FTD OS, SRU VDB, GEODB, LSP etc.

So if I purchase PLR SKU with smartnet contract, what are the other benefits do I get buy purchasing subscription for Threat Defense/URL/Malware etc.

The PLR SKU only entitles your Smart Account for downloading that special license type.

Smartnet on a given appliance entitles you to appliance hardware and software (OS, patches, VDB and GeoDB) support, both online and via Cisco TAC.

SRU and LSP are entitlements requiring a Threat (IPS) license. URL License allows you to create policies based on URL categories. Malware license allows you to create File policies that investigate observable files for malware.

My requirement, our firewalls are in offline (no Internet connectivity) environment. In this case I will get smartnet contract support and PLR SKU. I will download the IPS signatures manually, put it in a USB disk and upload to firewall using FDM. Is this achievable?

Review Cisco Networking for a $25 gift card