03-21-2021 02:27 AM
Hi,
I just bought cisco 4321/k9 router. My purpose is to create ipsec vpn to Headoffice and run POS and Single Cisco Phone over ipsec. When i started configuring router, it was not accepting ipsec commands. I checked license and it was showing only ipbasek9 license. When i enabled securityk9 license, ipsec started working. i checked license information which was as follows:
Router#show license all
Smart Licensing Status
======================
Smart Licensing is ENABLED
License Conversion:
Automatic Conversion Enabled: False
Status: Not started
Export Authorization Key:
Features Authorized:
<none>
Utility:
Status: DISABLED
Smart Licensing Using Policy:
Status: ENABLED
Data Privacy:
Sending Hostname: yes
Callhome hostname privacy: DISABLED
Smart Licensing hostname privacy: DISABLED
Version privacy: DISABLED
Transport:
Type: cslu
Cslu address: <empty>
Proxy:
Not Configured
Miscellaneous:
Custom Id: <empty>
Policy:
Policy in use: Merged from multiple sources.
Reporting ACK required: yes (CISCO default)
Unenforced/Non-Export Perpetual Attributes:
First report requirement (days): 365 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 90 (CISCO default)
Unenforced/Non-Export Subscription Attributes:
First report requirement (days): 90 (CISCO default)
Reporting frequency (days): 90 (CISCO default)
Report on change (days): 90 (CISCO default)
Enforced (Perpetual/Subscription) License Attributes:
First report requirement (days): 0 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 0 (CISCO default)
Export (Perpetual/Subscription) License Attributes:
First report requirement (days): 0 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 0 (CISCO default)
Usage Reporting:
Last ACK received: <none>
Next ACK deadline: Mar 16 07:28:29 2022 UTC
Reporting push interval: 30 days
Next ACK push check: <none>
Next report push: Mar 16 07:30:29 2021 UTC
Last report push: <none>
Last report file write: <none>
Trust Code Installed: <none>
License Usage
=============
securityk9 (ISR_4321_Security):
Description: securityk9
Count: 1
Version: 1.0
Status: IN USE
Export status: NOT RESTRICTED
Feature Name: securityk9
Feature Description: securityk9
Enforcement type: NOT ENFORCED
License type: Perpetual
Product Information
===================
UDI: PID:ISR4321/K9,SN:FDO2241277E
Agent Version
=============
Smart Agent for Licensing: 5.0.6_rel/47
License Authorizations
======================
Overall status:
Active: PID:ISR4321/K9,SN:FDO2241277E
Status: NOT INSTALLED
Purchased Licenses:
No Purchase Information Available
Router#show license summary
License Usage:
License Entitlement Tag Count Status
-----------------------------------------------------------------------------
securityk9 (ISR_4321_Security) 1 IN USE
Router#show license tech reservation
Overall status:
Active: PID:ISR4321/K9,SN:FDO2241277E
Status: NOT INSTALLED
--------------------------------------------------
Technology Package License Information:
-----------------------------------------------------------------
Technology Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------
appxk9 None Smart License None
uck9 None Smart License None
securityk9 securityk9 Smart License securityk9
ipbase ipbasek9 Smart License ipbasek9
The current throughput level is 50000 kbps
Smart Licensing Status: Registration Not Applicable/Not Applicable
cisco ISR4321/K9 (1RU) processor with 1707020K/3071K bytes of memory.
Processor board ID FDO2243A0XJ
Router operating mode: Autonomous
2 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3125247K bytes of flash memory at bootflash:.
Configuration register is 0x2102
Now, My question is do i need any kind of additional licensing? as i just need to run ipsec and securityk9 is showing perpetual already. I need to buy 15 more routers like this so need assistance for licensing. Thanks and Cheers.
03-21-2021 04:51 AM - edited 03-21-2021 04:54 AM
What bandwidth do you have? Depending on how much throughput you are expecting, you might need the HSEC license in addition to the security license.
The HSECK9 license is required for a feature to have full crypto functionality. Without the HSECK9 license, only 225 secure tunnels and 85 Mbps of crypto bandwidth would be available.The HSECK9 license allows features in the security k9 technology package to use the maximum number of secure tunnels and crypto bandwidth.
HTH
03-21-2021 04:58 AM
I have 25 Mbps Connection so assuming bandwidth 25mbps. I need to create just single ipsec tunnel to head office.
03-21-2021 05:40 AM - edited 03-21-2021 05:41 AM
@Amjad khan If IPSec throughput won't exceed 25Mbps and 15 sites/tunnels in total, you shouldn't need to purchase the HSEC license.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide