cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
422
Views
0
Helpful
1
Replies

Questions on device licensing

rihennig
Level 1
Level 1

Wasn't sure where the best place for this question is, so this is a cross post from the IDS/IPS forum:

I have a PIX 501 and I have a bunch general licensing questions about this device, and I don't have any prior experience with licensing on Cisco devices, so please be patient:

It comes with a basic license, but for any encryption related things, the product sheet says this:

The Cisco PIX 501 Security Appliance has two optional encryption licenses-one license (PIX-501-VPN-3DES) enables 168-bit 3DES and up to 256-bit AES encryption, the other license (PIX-VPN-DES) enables 56-bit DES encryption.

This device is end of sale, so I don't think you can buy a license for these things anymore, or can you? If a device is end of sale, can you either buy a license for the extra features, or does that functionality just open up for you? Or since it is end of sale, does that mean I can't buy the licenses, and if not, does that mean I can never use these extra features?

Since the item was used, it may be possible someone already installed a license (I need a power adapter for it still so I haven't been able to check). If this is the case, does the license ever expire? Can I use the license that is already there, if one exists? Also, how are licenses stored? If I do like a write erase, will the license be wiped out? How do I check for the existence of a license?

Let's say that the device does not have a license, will the software on the device just not recognize or show available the commands specific to the extra features that require a license? Or if I try a command for an extra feature, will it spit back an error telling me I need a license?

Thanks for your help!!

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

Richard

You have some interesting questions here - and since I do not work for Cisco my answers reflect my experience but are certainly not authoritative.

If the device is at end of sales I would guess that additional licenses are no longer available for purchase.

When devices get to end of sales it is certainly not the situation that features requiring special licensing just open up for you. If a feature required a special license and you do not have that license then the feature is just not available to you.

If you attempt to perform something that would require a license that you do not have there will be some error message. I am not sure what it would be - and may very well depend on what you are trying to do. I would suspect that many of the errors would be more like "invalid input" than a message that specifies licensing issues.

Officially the license was issued to the original purchaser and officially the purchaser can not transfer the license. But the practicality is that once installed the license is available to who ever is running the device. I am pretty sure that for PIX 501 there were not any licenses that were time based. On more recent products some licenses are permanent and some may be time based.

I can not speak to the technical details of how/where the license information is stored. But I can say that I have removed configs and/or write erase and the license was not affected.

When you get the power cord I believe that you will find the license information in the output of show version.

HTH

Rick

HTH

Rick
Review Cisco Networking for a $25 gift card