cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1275
Views
5
Helpful
2
Replies

IPS license

NAVIN PARWAL
Level 2
Level 2

Folks,

We have a IDSM blade and recently upgraded to IPS (5.x), we found out that it would not work without a license, then TAC told us that IPS license is on subscrition basis??? does anyone know what the procedure is to get a license for 5.x if they already have 4.x software running on IDS.

Thanks

2 Replies 2

marcabal
Cisco Employee
Cisco Employee

Even with version 4.x the signature updates were not free; users you needed to purchase the service contracts before upgrading the sensors.

In version 4.1 the documentation stated this, but it was not enforced in the software.

With version 5.0 the software is now starting to enforce the purchase of a service contract in order to get updates by using a license.

The license is tied to the serial number of the sensor, and licenses are only created for sensor serial numbers that are under a service contract.

If you originally purchased the IDSM-2 with version 4.x then you may have also purchased a service contract at that time. These 4.x contracts, that have not yet expired, have all been converted to the new 5.x contracts ("Cisco Services for IPS")

If your contract was converted then all you need to do is verify that your IDSM-2's serial number is covered by that contract, and then just request a license for that serial number (the cost for the license would have already been paid with the original purchase of the 4.x contract)

If your 4.x contract has expired, then you will need to purchase a new service contract.

All of the service contracts provide the license. The only difference between the contracts is the required response times when you report a problem.

The Cisco service contract that provides Hardware, Software, IPS License

and SIG Updates coverage for IDSM-2 is Cisco Services for IPS.

For WS-SVC-IDS2BUNK9= , Cisco Services for IPS SKUs are:

CON-SU1-IDSBNK9 $5,399 Advance Hardware Replacement Next Business Day (8x5xNBD)

CON-SU2-IDSBNK9 $6,479 Adv HW Repl (8x5x4)

CON-SU3-IDSBNK9 $6,839 Adv HW Repl (24x7x4)

CON-SUO1-IDSBNK9 $5,999 Adv HW Repl and Field Engineer on site Next Business Day (8x5xNBD)

CON-SUO2-IDSBNK9 $7,349 Adv HW Repl and FE onsite (8x5x4)

CON-SUO3-IDSBNK9 $7,799 Adv HW Repl and FE onsite (24x7x4)

So you will need to purchase one of the above part numbers for the service contract, and then add your IDSM-2's serial number to be managed by that contract. Once your IDSM-2 is covered by the contract, then you can request the license.

I would suggest contacting your Cisco Sales Representative (or the Partner representative if purchased from a reseller) and ask for assistance in getting your IDSM-2 covered under one of the contracts above.

Once your IDSM-2 serial number is covered by the contract, then the easiest way to request the license is to go through IDM to the Licensing configuration window. In that window is a button for connecting directly to Cisco Connection OnLine (CCO). It will connect to Cisco and pull down your license.

Getting the service contract purchased and setup may take a few days. In the meantime Cisco is allowing 60 day trial licenses (the licenses are fully featured but will expire after 60 days). So you can get your sensor fully functional now, and you have 60 days to get your service contract taken care of.

To get the 60 day trial license you will use the same License window in IDM. Push the Cisco Connection OnLine button. When it determines that your IDSM-2 is not under a service contract it will provide you the option to request and install a 60 day trial license.

Some things to be aware of:

1) The License does NOT prevent the sensor from functioning. An unlicensed sensor will be able to monitor traffic and respond to the attacks just fine.

Licensing is only used when installing signature updates. An unlicensed sensor (or expired license)will not allow the installation of signature updates that enforce licensing.

2) Each time a signature update is built Cisco decides whether or not that signature update will enforce licensing. If Cisco decides not to enforce licensing on that update, then that update can be installed with a license.

Up until now Cisco has decided NOT to enforce licensing on all signature updates up till S181.

This was to give time for users to get their service contracts and licenses in proper order.

So you can update your unlicensed sensor to S181.

When S182 gets ready for release Cisco will make a decision whether or not to begin enforcing licensing.

(Very high possibility that S182 may be the first update to begin enforcing licenses)

So if you haven't licensed your sensor yet you are still OK and can load the latest S181 update, but may not be able to load the next S182 update.

Review Cisco Networking for a $25 gift card