cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2585
Views
5
Helpful
6
Replies

ASR1001 IPSEC Licensing

peter.wolodzko
Level 1
Level 1

Hello,

 

Can't enable/use IPSEC on ASR1001:

 

Router(config)#int tu1
Router(config-if)# tunnel protection ipsec profile INET
IPSEC license request failed
Router(config-if)#IPSEC license request failed (18)

Router(config-if)#
*Jan 1 00:17:29.180: %LICENSE-1-REQUEST_FAILED: License request for feature ipsec 1.0 failed. UDI=ASR1001:JAE15300JKH

 

Using:

System image file is "bootflash:/asr1001-universalk9.03.16.06b.S.155-3.S6b-ext.bin"

License Level: adventerprise
License Type: Permanent
Next reload license Level: adventerprise

 

Accepted the EULA:

StoreIndex: 4 Feature: ipsec Version: 1.0
License Type: EvalRightToUse
License State: Active, Not in Use, EULA accepted
Evaluation total period: 8 weeks 4 days
Evaluation period left: 8 weeks 4 days
Period used: 0 minute 0 second
License Count: Non-Counted
License Priority: Low

 

Also, thought IPSEC was part of ADVENTERPRISE.  Is it not?  But in any case, would at least like to use it as EVAL.

 

Help!

Thanks.

6 Replies 6

Hello,

 

post the output of:

 

show license feature

 

Also make sure that you do not inadvertently have the 'npe' version (no payload encryption), that should be visible in 'sh ver'...

Hello,

 

No "npe" verion:

Router# show version
Cisco IOS XE Software, Version 03.16.06b.S - Extended Support Release
Cisco IOS Software, ASR1000 Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.5(3)S6b, RELEASE SOFTWARE (fc4)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2017 by Cisco Systems, Inc.
Compiled Thu 02-Nov-17 10:59 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2017 by cisco Systems, Inc.
All rights reserved. Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0. The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0. For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON

RDMNPLYMOU-VPN-A uptime is 27 minutes
Uptime for this control processor is 28 minutes
System returned to ROM by reload at 00:43:02 UTC Mon Jan 1 2001
System image file is "bootflash:/asr1001-universalk9.03.16.06b.S.155-3.S6b-ext.bin"
Last reload reason: Watchdog

 

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

License Level: adventerprise
License Type: Permanent
Next reload license Level: adventerprise

cisco ASR1001 (1RU) processor (revision 1RU) with 3728356K/6147K bytes of memory.
Processor board ID SSI15270G7L
4 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
8388608K bytes of physical memory.
7782399K bytes of eUSB flash at bootflash:.

Configuration register is 0x2102

 

License Feature:

Router# show licence feature

Feature name Enforcement Evaluation Subscription Enabled RightToUse
adventerprise yes yes no yes yes
advipservices yes yes no no yes
ipbase no no no no no
avc yes yes no no yes
broadband no no no no no
broadband_4k no no no no no
cube_250 no no no no no
cube_250_red no no no no no
cube_ent_100 no no no no no
cube_ent_100_red no no no no no
cube_lab no no no no no
cube_video_b2btp no no no no no
cube_video_b2btp_red no no no no no
firewall no no no no no
fpi no no no no no
fwnat_red yes yes no no yes
gtp_addon_aic no no no no no
internal_service yes no no no no
ipsec yes yes no no yes
lawful_intr yes yes no no yes
lisp yes yes no no yes
nat64_stateful_2m no no no no no
otv yes yes no no yes
sgt_fw no no no no no
sw_redundancy yes yes no no yes
throughput yes yes no no yes
vpls yes yes no no yes
FoundationSuiteK9 yes yes no no yes
AdvUCSuiteK9 yes yes no no yes

 

Thank you!

polezhaev.oleg
Level 1
Level 1

Good day!

I had the same problem on ASR1001, solved by changing the clock from 2001 to 2021. After that, when you enter the "tunnel protection ipsec profile INET" command, the license is turned on:

%CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
Index 19 Feature: ipsec 
Period left: Life time
License Type: RightToUse
License State: Active, In Use
License Count: Non-Counted
License Priority: Low


It is also necessary to replace the batterie on the mainboard so that the clock is not reset when the power is turned off.

Hello!

 

Oleg, you are right. It's working!

Thanks!

Hello,

 

just for clarity, this procedure does not work without opening the chassis and replacing the battery ?

Hello, George.

 

It's not necessary. I got working license just after changing time and rebooting. But I can guess, in case of power loss you can loss some features again.

Review Cisco Networking for a $25 gift card