cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3995
Views
0
Helpful
3
Replies

Cisco 4321/k9 License

Amjad khan
Level 1
Level 1

Hi,

I just bought cisco 4321/k9 router. My purpose is to create ipsec vpn to Headoffice and run POS and Single Cisco Phone over ipsec. When i started configuring router, it was not accepting ipsec commands. I checked license and it was showing only ipbasek9 license. When i enabled securityk9 license, ipsec started working. i checked license information which was as follows:

 

Router#show license all
Smart Licensing Status
======================

Smart Licensing is ENABLED

License Conversion:
Automatic Conversion Enabled: False
Status: Not started

Export Authorization Key:
Features Authorized:
<none>

Utility:
Status: DISABLED

Smart Licensing Using Policy:
Status: ENABLED

Data Privacy:
Sending Hostname: yes
Callhome hostname privacy: DISABLED
Smart Licensing hostname privacy: DISABLED
Version privacy: DISABLED

Transport:
Type: cslu
Cslu address: <empty>
Proxy:
Not Configured

Miscellaneous:
Custom Id: <empty>

Policy:
Policy in use: Merged from multiple sources.
Reporting ACK required: yes (CISCO default)
Unenforced/Non-Export Perpetual Attributes:
First report requirement (days): 365 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 90 (CISCO default)
Unenforced/Non-Export Subscription Attributes:
First report requirement (days): 90 (CISCO default)
Reporting frequency (days): 90 (CISCO default)
Report on change (days): 90 (CISCO default)
Enforced (Perpetual/Subscription) License Attributes:
First report requirement (days): 0 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 0 (CISCO default)
Export (Perpetual/Subscription) License Attributes:
First report requirement (days): 0 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 0 (CISCO default)

Usage Reporting:
Last ACK received: <none>
Next ACK deadline: Mar 16 07:28:29 2022 UTC
Reporting push interval: 30 days
Next ACK push check: <none>
Next report push: Mar 16 07:30:29 2021 UTC
Last report push: <none>
Last report file write: <none>

Trust Code Installed: <none>

License Usage
=============

securityk9 (ISR_4321_Security):
Description: securityk9
Count: 1
Version: 1.0
Status: IN USE
Export status: NOT RESTRICTED
Feature Name: securityk9
Feature Description: securityk9
Enforcement type: NOT ENFORCED
License type: Perpetual

Product Information
===================
UDI: PID:ISR4321/K9,SN:FDO2241277E

Agent Version
=============
Smart Agent for Licensing: 5.0.6_rel/47

License Authorizations
======================
Overall status:
Active: PID:ISR4321/K9,SN:FDO2241277E
Status: NOT INSTALLED

Purchased Licenses:
No Purchase Information Available

Router#show license summary
License Usage:
License Entitlement Tag Count Status
-----------------------------------------------------------------------------
securityk9 (ISR_4321_Security) 1 IN USE

Router#show license tech reservation
Overall status:
Active: PID:ISR4321/K9,SN:FDO2241277E
Status: NOT INSTALLED


--------------------------------------------------

Technology Package License Information:

-----------------------------------------------------------------
Technology Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------
appxk9 None Smart License None
uck9 None Smart License None
securityk9 securityk9 Smart License securityk9
ipbase ipbasek9 Smart License ipbasek9

The current throughput level is 50000 kbps


Smart Licensing Status: Registration Not Applicable/Not Applicable

cisco ISR4321/K9 (1RU) processor with 1707020K/3071K bytes of memory.
Processor board ID FDO2243A0XJ
Router operating mode: Autonomous
2 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3125247K bytes of flash memory at bootflash:.

Configuration register is 0x2102

 

Now, My question is do i need any kind of additional licensing? as i just need to run ipsec and securityk9 is showing perpetual already. I need to buy 15 more routers like this so need assistance for licensing. Thanks and Cheers.

 

3 Replies 3

@Amjad khan 

What bandwidth do you have? Depending on how much throughput you are expecting, you might need the HSEC license in addition to the security license.

 

https://www.cisco.com/c/en/us/td/docs/routers/access/4400/software/configuration/guide/isr4400swcfg.pdf

 

The HSECK9 license is required for a feature to have full crypto functionality. Without the HSECK9 license, only 225 secure tunnels and 85 Mbps of crypto bandwidth would be available.The HSECK9 license allows features in the security k9 technology package to use the maximum number of secure tunnels and crypto bandwidth.

 

HTH

I have 25 Mbps Connection so assuming bandwidth 25mbps. I need to create just single ipsec tunnel to head office. 

@Amjad khan If IPSec throughput won't exceed 25Mbps and 15 sites/tunnels in total, you shouldn't need to purchase the HSEC license.

 

HTH