03-03-2022 08:37 AM
Switch Ports Model SW Version SW Image Mode
------ ----- ----- ---------- ---------- ----
* 1 32 WS-C3850-24P 16.12.05b CAT3K_CAA-UNIVERSALK9 INSTALL
I have the above switch, is it possible to switch to traditional licensing? I cant seem to find how switch it back to traditional from smart licensing.
Solved! Go to Solution.
03-03-2022 08:50 AM
After 16.12 all is a smart license only
check new deployment :
03-03-2022 08:50 AM
After 16.12 all is a smart license only
check new deployment :
03-03-2022 08:53 AM - edited 03-03-2022 09:48 AM
That is terrible, smart licensing is the worst. Guess, I'll be downgrading.
03-03-2022 09:11 AM
yes, that works for you, Cisco always improves the new version better security.
03-03-2022 09:52 AM
No amount of security can trump the IT budget. It could be the best thing in the universe but with the cost, I'd never get approval. In fact, eventually when PCI-DSS compliance forces the issue, I'll have to migrate away from Cisco entirely because the company wont pay for Smart Licensing when cheaper alternatives are out there. Cisco is pricing themselves out of medium to small businesses.
03-03-2022 09:59 AM
Noted and understand clear your business point of view.
if I were you, I look for ROI with the best price, sometimes white box deployment. get value.
but some Businesses like to be compliant have a budget so they go with products like cisco.
03-03-2022 03:07 PM - edited 03-03-2022 03:23 PM
First, Cisco Smart License (CSL) is broken: FN - 72323 - Cisco IOS XE Software: QuoVadis Root CA 2 Decommission Might Affect Smart Licensing, Smart Call Home, and Other Functionality
Run the command "sh crypto pki trustpool | i cn=". If the first two lines are "QuoVadis Root CA 2" then this FN applies.
Next, Cisco dumb Smart License starts from 16.9.X until 16.12.X. Downgrade to 16.6.X and it goes back to "traditional" license.
Next, when CSL expires, do not worry about it. Nothing will happen. The License will not "roll back" and there will be no "enforcement". CSL is a "toothless tiger".
Finally, when CSL expires and spams the logs with useless error messages, use a logging discriminator to hide it. Below is an example of a logging discriminator we call "fence off CSL":
conf t logging discriminator FO_CSL facility drops SMART_LI|CALL|PKI-4-TRUSTPOOL_DOWNLOAD_FAILURE logging buffered discriminator FO_CSL 40960 logging console discriminator FO_CSL logging monitor discriminator FO_CSL end
Hope this works.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide