05-09-2017 02:43 PM - last edited on 03-05-2019 08:30 AM by NikolaIvanov
So I have a brand new 4331 ISR and literally just putting in basic config. Yes, n00b, but have some basics. I am trying to configure zone based firewall... I get my "conf t" and type in;
NEW4331ISR(config)#zone security PUBLIC
^
% Invalid input detected at '^' marker.
NEW4331ISR(config)#
I am obviously missing something really easy, like "licensing" or "you can't do that without _____ you n00b"
So.. short of RTFM what does the community have for me.
Sean
Running Config attached
05-09-2017 03:01 PM
Hello,
that is indeed usually a licensing issue. Can you post the output of 'show version' and 'show license' ?
05-09-2017 03:05 PM
NEW4331ISR#sh ver
Cisco IOS XE Software, Version 03.16.04b.S - Extended Support Release
Cisco IOS Software, ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.5(3)S4b, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Mon 17-Oct-16 20:23 by mcpre
Cisco IOS-XE software, Copyright (c) 2005-2016 by cisco Systems, Inc.
All rights reserved. Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0. The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0. For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.
ROM: IOS-XE ROMMON
NEW4331ISR uptime is 1 day, 6 hours, 36 minutes
Uptime for this control processor is 1 day, 6 hours, 37 minutes
System returned to ROM by reload at 04:18:13 UTC Wed Mar 22 2017
System image file is "bootflash:/isr4300-universalk9.03.16.04b.S.155-3.S4b-ext.SPA.bi"
Last reload reason: PowerOn
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
export@cisco.com.
Suite License Information for Module:'esg'
--------------------------------------------------------------------------------
Suite Suite Current Type Suite Next reboot
--------------------------------------------------------------------------------
FoundationSuiteK9 None Smart License None
securityk9
appxk9
AdvUCSuiteK9 None Smart License None
uck9
cme-srst
cube
Technology Package License Information:
-----------------------------------------------------------------
Technology Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------
appxk9 None Smart License None
uck9 None Smart License None
securityk9 None Smart License None
ipbase ipbasek9 Smart License ipbasek9
cisco ISR4331/K9 (1RU) processor with 1648789K/6147K bytes of memory.
Processor board ID FDOX0X0X0X0X
5 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3223551K bytes of flash memory at bootflash:.
Configuration register is 0x2102
05-09-2017 03:10 PM
***EDIT***
05-10-2017 01:34 PM
Hello,
possibly you have smart licensing enabled. Try and disable it with the command:
NEW4331ISR#no license smart enable
and then reboot the device.
05-09-2017 03:10 PM
OK, then here's what I want to do. I want to block all EXTERNAL->INTERNAL traffic, and create 3 VPN connections to small offices around town. What Lic do I need?
Sean
05-09-2017 03:21 PM
Hello,
the 'Security' license is what you need.
05-10-2017 12:41 PM
Ok, so when I try to install the Lic;
NEW4331ISR#license install flash:isr4300-universalk9.lic
^
% Invalid input detected at '^' marker.
No matter what I try and put there it always gives me invalid at the first letter of the switch after "license".
What gives?
05-10-2017 01:10 PM
Hello,
what options do you have:
NEW4331ISR#license ?
05-10-2017 01:28 PM
smart Smart licensing
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide