05-23-2019 03:37 AM
Hi dear friends
i am starting to upgrade my WAN to SD-WAN, but i encountered to some problem with licensing
1- what is perpetual license and 3/5 years license in SD-WAN, how can i buy and which one is better for us?
2- detail information about difference between license type, for example details about essential vs advantage? for example, what security feature support by which one??
and many other question
regards
Reza
Solved! Go to Solution.
05-28-2019 01:03 PM
1- what is different between SDWAN (or security) on Essential and advanced SDWAN (or advanced security) on Advantage?
Ans 1:- Basic SD-WAN security services includes:-
-L3/L4/App-Aware Firewall
-Snort IPS/IDS with Talos® signature updates
-DNS monitoring and connector for Cisco Umbrella
Advanced SD-WAN security Advantage Offers:-
-Unlimited segmentation
-URL-filtering
-Cisco Advanced Malware Protection (AMP)
-Cisco Umbrella cloud-app discovery (Umbrella Insights)
2- what mean "you get the flexibility to consume the latest technology" ?? could you give an example?
Ans 2: Flexibility to consume latest technology means, flexibility in choosing whatever you want, you can upgrade from enterprise to advantage or premier licensing whenever you grow as business right. You can choose the term 3/5 years, and you have a bandwidth choice of 10Mb/10gig. You get to use latest features, like LAB automation, SWIM, mVPN, VRF, MPLS, this is just by choosing your licenses Advantage/Essentials in Cisco ONE, with this you do not have to buy specific hardware to get these features, all these features are software centric. I guess above explanation is very crystal clear. I am not sure if you still not able to get the concept. :)
3- "some features are available with 3/5 term license while perpetual license carry other features not available with term", could you give an example for this feature?
Ans 3:- Let me make it simpler for you, perpetual means never ending or doesn't come with a end date, (Ex; Network Essentials and Advantage, please understand DNA Essentials and Advantage is not same it is term license), Now the hardware you purchase like Cat9k,Cat4500 etc will carry some features right if they are switches it will have switch features and all similar for router, So by default you will have Perpetual license when you purchase your H/W. Along with that you have to attach your software which is either DNA Essentials or Advantage which has 3,5,7 term, So you will get term license feature along with perpetual license. For example: In CCD, if you order a cold coffee i.e Devils own, it will come with coffee, Choco sauce (which is perpetual), Add-on is Whipped cream which is chargeable (Add-on is good to add as it will make the coffee much tastier). Hope that made sense :)
4- i got, i can buy Cisco one licenses (essential or advantage) that is perpetual and include all features in DNA (essential or advantage), is it correct?
Ans 4: Cisco ONE Advantage is one you should go for not essentials as support will be limited to 50 routing licenses with essentials, So, Cisco 1 Advantage is a way to go which is renamed to DNA Premier as of now. So you have to purchase that along with your hardware and you don't have to include anything, Everything will be covered with DNA Premier licensing , all routing, advanced security features which can be maximum included, Hence Premier pricing is high!
5- "Network Essentials and Advantage are perpetual and not required for vEdge" this happen if i use C1? if yes, i should buy ISR 4431 with IOS-XE SDWAN and buy C1, and everything will be ok??
Ans:- This depends how you are going to manage your SDWAN, Cloud Management with vManage is the preferred option for customers who wish to simplify WAN deployments, accelerate digital transformation, and move toward intent-based WAN. On Prem Manages WAN using Cisco DNA Center. The subscription for the Cisco vEdge platform includes entitlement for vManage On-prem. To make it simple you should or its recommended to purchase DNA Premier and choose how you want to manage ONprem/Cloud, Cloud mgmt will work with vManage. If you have old device ISR4k then add DNA advantage to it or purchase DNA Premier with ISR 4431 then you are all set, Read this whitepaper below and you will be able to set up SDWAN for your branches, Good Luck.
https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/sd-wan/white-paper-c11-741071.pdf
05-23-2019 04:39 AM - edited 05-23-2019 04:40 AM
Hi Reza,
1. Cisco SD-WAN follows Cisco DNA subscription offers. Each WAN Edge needs to be equipped with a 3/5 year license. The easiest way to buy and get the right license recommendation would be to contact your Cisco Account Team.
2. Detailed information on license tier to feature mapping can be found on page 16 of DNA Software Routing Subscription Guide.
You can use the following link to check additional info on licensing: https://community.cisco.com/t5/networking-documents/sd-wan-community-resources/ta-p/3745752#Licensing
05-23-2019 07:14 AM
05-23-2019 08:18 AM
SD-WAN licences are subscription based. The perpetual license cannot be used for SD-WAN. If you want to use ISR4431 as SD-WAN WAN edge you need to buy a subscription license. You choose a valid license based on features, required bandwidth and license term (3/5 years).
Cisco SD-WAN provides wide range of Security features. The link I provided before lists detailed security features to license tier mapping on page 16.
05-24-2019 02:54 AM
05-24-2019 01:17 PM
Sorry Reza, now I got your question :)
So page 16 is listing Cisco SD-WAN build-in security features.
If you want to use Cisco SD-WAN service chaining feature to direct traffic to 3rd patry security appliances you will need a DNA Advantage license.
05-24-2019 10:48 PM
12-02-2019 12:34 PM
Dear
what does it mean: Unlimited segmentation to DNA Advantage, please help me with a example. And with Essential what is the limit of this segmentation?
12-02-2019 11:42 PM
Hi Manuel,
This means in Cisco DNA Essentials you can use only single service VPN (single VRF). In Cisco DNA Advantage you can use up to platform scale.
05-24-2019 01:28 PM
Cisco DNA Advantage enables flexible connectivity, advanced SDWAN, advanced security, assurance and application-driven policy, In short Cisco DNAC advantage offers more visibility in network with its advanced capabilities
Cisco DNA Essentials enables connectivity, SDWAN, security and application visibility. This is just the lower version of Advanced licensing so it will provide basic visibility not complete visbility.
With the new routing subscription tiers, you get the flexibility to consume the latest technology either in the cloud or on your premises, across the entire routing stack.All of these are available as 3 or 5 year subscriptions. All the tiers include Software Support.
To make your life easier so you can understand this well, You are confused on differences of 3/5 term licenses and perpetual licenses.
Perpetual license is something which does not expire, while 3/5 yrs licenses comes with time limit for 3 yrs and 5 yrs term post that you have to renew it to use the services.
There is a difference because cisco has placed them differently some features are available with 3/5 term license while perpetual license carry other features not available with term. I have shared a screen shot for Cat9k for example so you can understand it better.
Now you dont, have to purchase perpetual license mostly it comes included to your device catalyst or your ISRs, named as Network Essentials or Advantage, This differs from DNA/SDWAN Essentials and Advanatage. If you purchase C1 or Cisco ONE you get perpetual license benefits. For ex- BGP, OSPF, TACACS
Network Essentials and Advantage are perpetual and not required for vEdge. ISR 4431 can be cloud managed through vManage. Similarly for ENCS5000, ISE1k, ISR 4k and ASR4k, Perpetual licenses are not required.
On the Security part, with Essentials you will get All types of connectivity, Secure VPN overlay, IPS, basic app visibility, with advantage you will get SDWAN and Adv. WAN topologies, Limited segmentation, cloud connectivity, ETA etc
With Advanatage you get ISE base and ISE plus and Stealthwatch license included and with Essentials you get only ISE base.
So highly preffered product which you should buy is Cisco ONE Advanatage, and that will include everything in this single SKU, to avoid any confusion along with perpetual licenses. Cisco ONE DNA Licenses is combination of Cisco ONE to unleash the power of both forms of licensing.
05-24-2019 11:14 PM
05-28-2019 12:57 PM
05-28-2019 01:03 PM
1- what is different between SDWAN (or security) on Essential and advanced SDWAN (or advanced security) on Advantage?
Ans 1:- Basic SD-WAN security services includes:-
-L3/L4/App-Aware Firewall
-Snort IPS/IDS with Talos® signature updates
-DNS monitoring and connector for Cisco Umbrella
Advanced SD-WAN security Advantage Offers:-
-Unlimited segmentation
-URL-filtering
-Cisco Advanced Malware Protection (AMP)
-Cisco Umbrella cloud-app discovery (Umbrella Insights)
2- what mean "you get the flexibility to consume the latest technology" ?? could you give an example?
Ans 2: Flexibility to consume latest technology means, flexibility in choosing whatever you want, you can upgrade from enterprise to advantage or premier licensing whenever you grow as business right. You can choose the term 3/5 years, and you have a bandwidth choice of 10Mb/10gig. You get to use latest features, like LAB automation, SWIM, mVPN, VRF, MPLS, this is just by choosing your licenses Advantage/Essentials in Cisco ONE, with this you do not have to buy specific hardware to get these features, all these features are software centric. I guess above explanation is very crystal clear. I am not sure if you still not able to get the concept. :)
3- "some features are available with 3/5 term license while perpetual license carry other features not available with term", could you give an example for this feature?
Ans 3:- Let me make it simpler for you, perpetual means never ending or doesn't come with a end date, (Ex; Network Essentials and Advantage, please understand DNA Essentials and Advantage is not same it is term license), Now the hardware you purchase like Cat9k,Cat4500 etc will carry some features right if they are switches it will have switch features and all similar for router, So by default you will have Perpetual license when you purchase your H/W. Along with that you have to attach your software which is either DNA Essentials or Advantage which has 3,5,7 term, So you will get term license feature along with perpetual license. For example: In CCD, if you order a cold coffee i.e Devils own, it will come with coffee, Choco sauce (which is perpetual), Add-on is Whipped cream which is chargeable (Add-on is good to add as it will make the coffee much tastier). Hope that made sense :)
4- i got, i can buy Cisco one licenses (essential or advantage) that is perpetual and include all features in DNA (essential or advantage), is it correct?
Ans 4: Cisco ONE Advantage is one you should go for not essentials as support will be limited to 50 routing licenses with essentials, So, Cisco 1 Advantage is a way to go which is renamed to DNA Premier as of now. So you have to purchase that along with your hardware and you don't have to include anything, Everything will be covered with DNA Premier licensing , all routing, advanced security features which can be maximum included, Hence Premier pricing is high!
5- "Network Essentials and Advantage are perpetual and not required for vEdge" this happen if i use C1? if yes, i should buy ISR 4431 with IOS-XE SDWAN and buy C1, and everything will be ok??
Ans:- This depends how you are going to manage your SDWAN, Cloud Management with vManage is the preferred option for customers who wish to simplify WAN deployments, accelerate digital transformation, and move toward intent-based WAN. On Prem Manages WAN using Cisco DNA Center. The subscription for the Cisco vEdge platform includes entitlement for vManage On-prem. To make it simple you should or its recommended to purchase DNA Premier and choose how you want to manage ONprem/Cloud, Cloud mgmt will work with vManage. If you have old device ISR4k then add DNA advantage to it or purchase DNA Premier with ISR 4431 then you are all set, Read this whitepaper below and you will be able to set up SDWAN for your branches, Good Luck.
https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/sd-wan/white-paper-c11-741071.pdf
05-28-2019 01:34 PM
01-30-2025 01:54 AM
Could you please clarify following. If İ would like to use SD-WAN hub and spoke IPSEC VPN Will esential license support it ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide