cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2899
Views
35
Helpful
26
Replies

Does Cisco Smart Licensing supports Right to Use Licenses?

Hi all, I recently upgraded a C3850 to IOS-XE 16.12.5b but I realized that Cisco Smart Licensing is mandatory for that release, I was able to convert the ipbase license to Smart on the switch but I realized that it was missing the apcount adder licences. I assume that the Right-To-Use licenses are not valid in smart?  Is there a way to convert them? or how can I use them on latest IOS-XE?

 

As for now, I had to downgrade to 16.3.9 in order to recognize the licenses:

 

C3850#show lic right-to-use
Slot# License Name Type Count Period left
-------------------------------------------------------
1 ipbase permanent N/A Lifetime
1 apcount adder 5 Lifetime

License Level on Reboot: ipbase

 

Thanks in advance!

5 Accepted Solutions

Accepted Solutions

Rich R
VIP
VIP

Your problem is nothing to do with licensing - Converged Access (wireless on 3650/3850) is not supported after IOS-XE 16.3.x

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/16-5/release_notes/ol-16-5-3850.html

See under important notes: "Converged Access (CA) is not supported beyond Cisco IOS XE Denali 16.3.x."

One more reason why you shouldn't be doing wireless on 3850.  Cisco abandoned the technology because it had so many problems.

So the latest release you can use for wireless on your 3850 is 16.3.11 (so no 16.6.x @Leo Laohoo)

That IOS release train will not have any more updates now https://www.cisco.com/c/en/us/products/collateral/switches/catalyst-3850-series-switches/eos-eol-notice-c51-740255.html

 

View solution in original post

Calm down @Leo Laohoo  lol - he mentioned in one of his answers that the AP licenses disappeared when he upgraded.  He thought that was related to smart licensing.  Of course it was simply because it wasn't supported anymore.

Aldo.zavala@gmail.com always best to make the whole of your question clear right from the start - if you had made clear that your concern was about the AP licenses disappearing when you upgraded from 16.3 to something higher then the answer would have been immediately obvious.

Regarding converged access - it is gone forever - removed from all platforms everywhere, never to be supported again on anything.

The whole codebase was re-written for 9800 series (with a lot of porting from AireOS).  You might find some similarities (they're both IOS-XE) but 9800 is a completely new product.  Leo has mentioned a few of the problems with CA already.  Long story short - it was not a success.  There are not many people still using it and because the software is past end of software maintenance date most users are migrating away from it if they haven't done so already so you'd be wasting your time learning it.

Note that your 3500 APs (very old) are not supported on 9800 series WLC.

1700/2700/3700 series are only supported up to 17.3.x IOS-XE.

But all AC Wave 2 APs (eg 1800) are fully supported (so far)

Refer to https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html#ctr-ap_support

 

View solution in original post


Aldo.zavala@gmail.com wrote:

Right now I am practicing for learning purposes with a 3850 and three AP3500i


Converged Access 1.0 is dead.  Converged Access 2.0 is very, very different from CA 1.0.  
eWLC (embedded WLC on Switches or on AP) has very little commercial significance.  It is predominantly aimed at SMB/SOHO and not at an enterprise-level deployment.  

If you want something to "learn" for the future, look at virtual WLC (free to download, free to use) and then use AP2800 because they are starting to show up in used market. If you want to learn, learn that.  Do not waste any more time and money in CA 1.0 &/or APs that are not supported on vWLC.

View solution in original post


Aldo.zavala@gmail.com wrote:

Does embedded WLC on on AP's need special licensing?


It is called Mobility Express. 

No, it does not require any licenses. 

Remember, Mobility Express has very basic features and ,like eWLC, it is aimed at SOHO/SMB. 

I have never come across Mobility Express in an enterprise-level deployment.  

View solution in original post

Rich R
VIP
VIP

We've already provided all the info and suggestions you need Aldo.zavala@gmail.com - you need to go and read for yourself.

Forget about converged access - just never mention it again.

EWC is a compact form of 9800 WLC (IOS-XE) which can run on 9100 series APs or some switches.  It is designed for single sites and the WLC and APs must be on the same LAN/VLAN/broadcast domain.

Mobility Express (ME) was a very cut down version of AireOS WLC which runs on Wave 2 APs (1800/2800/3800 etc).  Personally I would not recommend this.  If you want to learn current technology then concentrate on the IOS-XE based platforms.

Like I already suggested my recommendation is EWC on 9100 AP or 9800-CL for a full featured WLC.

Don't waste your time trying to run it on a switch (which will cost more anyway).  You can keep your 3850 as a switch and upgrade to the latest IOS without wireless.

If you run a full WLC (9800 series) then you need a DNA license per AP which you purchase with the AP - all done through smart licensing.

 

View solution in original post

26 Replies 26

Leo Laohoo
Hall of Fame
Hall of Fame

Aldo.zavala@gmail.com wrote:

how can I use them on latest IOS-XE?


For the 3650/3850, Cisco Smart License starts from 16.9.X until 16.12.6.

Based on my experience, 16.12.X is not as "cracked up" as what everyone think it is.  

I find it more stable to use 16.3.X or 16.6.X for long term (several years) without any trouble.  I cannot get four months out of 16.12.X without proactively rebooting the stack or the stack crashing.  

Stick with 3.6.X, 16.3.X or even 16.6.X.

I think I tried 16.6.x and it defaulted to smart, it didn't let me see my RTU access point license, is it something that I need to disable? For instance when I downgraded to 12.3.x I had to do nothing, the right to use licenses just appeared there. 


Aldo.zavala@gmail.com wrote:

I think I tried 16.6.x and it defaulted to smart


Try again. 
CSL is only supported from 16.9.X until 16.12.X.

I think I tried 16.6.x

This still works as the traditional way of License, it only started smart License as per my experience 16.9.X

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I just loaded the 16.06.08 on the switch and it have enabled right to use but it didn't load my five AP licenses:

C3850#show license right-to-use
Slot# License Name Type Period left
----------------------------------------------------
1 ipbase Permanent Lifetime
----------------------------------------------------
License Level on Reboot: ipbase

 

Here is the console output on the first reload after software installed:

Bootable image at @ ram:0x537783bc
Bootable image segment 0 address range [0x81100000, 0x81bffab0] is in range [0x80180000, 0x90000000].
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@boot_system: 623
Loading Linux kernel with entry point 0x816e1140 ...
Bootloader: Done loading app on core_mask: 0xf

### Launching Linux Kernel (flags = 0x5)

%IOSXEBOOT-5c8e9d6656e9d89a8dedeae457871084-new_cksum: (rp/0): 4
%IOSXEBOOT-5c8e9d6656e9d89a8dedeae457871084-saved_cksum: (rp/0): 4

Both links down, not waiting for other switches
Switch number is 1

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706



Cisco IOS Software [Everest], Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version 16.6.8, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2020 by Cisco Systems, Inc.
Compiled Thu 23-Apr-20 17:22 by mcpre



Cisco IOS-XE software, Copyright (c) 2005-2020 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.




FIPS: Flash Key Check : Begin
FIPS: Flash Key Check : End, Not Found, FIPS Mode Not Enabled

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco WS-C3850-48P (MIPS) processor (revision S0) with 852817K/6147K bytes of memory.
Processor board ID FCW1910D0V3
2048K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
250456K bytes of Crash Files at crashinfo:.
1609272K bytes of Flash at flash:.
0K bytes of WebUI ODM Files at webui:.

Base Ethernet MAC Address          : 40:a6:e8:92:27:80
Motherboard Assembly Number        : 73-14442-10
Motherboard Serial Number          : FOC19095D00
Model Revision Number              : S0
Motherboard Revision Number        : A0
Model Number                       : WS-C3850-48P
System Serial Number               : FCW1910D0V3


%INIT: waited 0 seconds for NVRAM to be available

central-management-version 13882355751269171203
  ^
% Invalid input detected at '^' marker.
% Please use license right-to-use exec CLI to activate/deactivate license
wireless mobility controller
 ^
% Invalid input detected at '^' marker.

wireless mobility controller peer-group CUBA-01
 ^
% Invalid input detected at '^' marker.

wireless mobility controller peer-group CUBA-01 bridge-domain-id 1
 ^
% Invalid input detected at '^' marker.

wireless mobility controller peer-group CUBA-01 multicast ip 0.0.0.0
 ^
% Invalid input detected at '^' marker.

wireless management interface Vlan9
 ^
% Invalid input detected at '^' marker.

wireless mgmt-via-wireless
 ^
% Invalid input detected at '^' marker.

wlan default_2.4 1 NEW_INFINITUM849A_2.4
 ^
% Invalid input detected at '^' marker.

 call-snoop
 ^
% Invalid input detected at '^' marker.

 client association limit 200
 ^
% Invalid input detected at '^' marker.

 client vlan 7
 ^
% Invalid input detected at '^' marker.

 ip dhcp opt82 format add-ssid
  ^
% Invalid input detected at '^' marker.

 ip dhcp server 192.168.7.1
  ^
% Invalid input detected at '^' marker.

 ip multicast vlan 7
  ^
% Invalid input detected at '^' marker.

 media-stream multicast-direct
  ^
% Invalid input detected at '^' marker.

 radio dot11bg
 ^
% Invalid input detected at '^' marker.

 no security wpa akm dot1x
     ^
% Invalid input detected at '^' marker.

 security wpa akm psk set-key ascii 0 E2YEvusrGD
  ^
% Invalid input detected at '^' marker.

 no shutdown
     ^
% Invalid input detected at '^' marker.

wlan default_5 2 INFINITUM849A_5
 ^
% Invalid input detected at '^' marker.

 call-snoop
 ^
% Invalid input detected at '^' marker.

 client association limit 200
 ^
% Invalid input detected at '^' marker.

 client vlan 7
 ^
% Invalid input detected at '^' marker.

 ip dhcp opt82 format add-ssid
  ^
% Invalid input detected at '^' marker.

 ip dhcp server 192.168.7.1
  ^
% Invalid input detected at '^' marker.

 ip multicast vlan 7
  ^
% Invalid input detected at '^' marker.

 media-stream multicast-direct
  ^
% Invalid input detected at '^' marker.

 radio dot11ag
 ^
% Invalid input detected at '^' marker.

 no security wpa akm dot1x
     ^
% Invalid input detected at '^' marker.

 security wpa akm psk set-key ascii 0 E2YEvusrGD
  ^
% Invalid input detected at '^' marker.

 shutdown
  ^
% Invalid input detected at '^' marker.

wlan default_2.4_NEW 3 INFINITUM849A_2.4
 ^
% Invalid input detected at '^' marker.

 call-snoop
 ^
% Invalid input detected at '^' marker.

 client association limit 200
 ^
% Invalid input detected at '^' marker.

 client vlan 7
 ^
% Invalid input detected at '^' marker.

 ip dhcp opt82 format add-ssid
  ^
% Invalid input detected at '^' marker.

 ip dhcp server 192.168.7.1
  ^
% Invalid input detected at '^' marker.

 ip multicast vlan 7
  ^
% Invalid input detected at '^' marker.

 media-stream multicast-direct
  ^
% Invalid input detected at '^' marker.

 radio dot11bg
 ^
% Invalid input detected at '^' marker.

 no security wpa akm dot1x
     ^
% Invalid input detected at '^' marker.

 security wpa akm psk set-key ascii 0 E2YEvusrGD
  ^
% Invalid input detected at '^' marker.

 shutdown
  ^
% Invalid input detected at '^' marker.

ap led
 ^
% Invalid input detected at '^' marker.

ap link-encryption
 ^
% Invalid input detected at '^' marker.

ap dot11 airtime-fairness policy-name Default 0
 ^
% Invalid input detected at '^' marker.

ap group default-group
 ^
% Invalid input detected at '^' marker.

ap hyperlocation ble-beacon 0
 ^
% Invalid input detected at '^' marker.

ap hyperlocation ble-beacon 1
 ^
% Invalid input detected at '^' marker.

ap hyperlocation ble-beacon 2
 ^
% Invalid input detected at '^' marker.

ap hyperlocation ble-beacon 3
 ^
% Invalid input detected at '^' marker.

ap hyperlocation ble-beacon 4
 ^
% Invalid input detected at '^' marker.



Press RETURN to get started!


*Jan 16 21:03:42.214: %SMART_LIC-6-AGENT_READY: Smart Agent for Licensing is initialized
*Jan 16 21:03:54.322: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan
*Jan 16 21:03:55.003: %LINK-3-UPDOWN: Interface Lsmpi18/3, changed state to up
*Jan 16 21:03:55.005: %LINK-3-UPDOWN: Interface EOBC18/1, changed state to up
*Jan 16 21:03:55.006: %LINK-3-UPDOWN: Interface GigabitEthernet0/0, changed state to down
*Jan 16 21:03:55.006: %LINK-3-UPDOWN: Interface LIIN18/2, changed state to up
*Jan 16 21:03:55.108: WCM-PKI-SHIM: buffer allocation failed for SUDI support check
*Jan 16 21:03:55.108: PKI/SSL unable to send Sudi support to WCM
*Jan 16 21:02:54.579: %STACKMGR-6-STACK_LINK_CHANGE: Switch 1 R0/0: stack_mgr:  Stack port 1 on Switch 1 is nocable 
*Jan 16 21:02:54.579: %STACKMGR-6-STACK_LINK_CHANGE: Switch 1 R0/0: stack_mgr:  Stack port 2 on Switch 1 is down 
*Jan 16 21:02:54.579: %STACKMGR-6-STACK_LINK_CHANGE: Switch 1 R0/0: stack_mgr:  Stack port 2 on Switch 1 is nocable 
*Jan 16 21:02:54.579: %STACKMGR-6-SWITCH_ADDED: Switch 1 R0/0: stack_mgr:  Switch 1 has been added to the stack. 
*Jan 16 21:02:54.579: %STACKMGR-6-SWITCH_ADDED: Switch 1 R0/0: stack_mgr:  Switch 1 has been added to the stack. 
*Jan 16 21:02:54.579: %STACKMGR-6-SWITCH_ADDED: Switch 1 R0/0: stack_mgr:  Switch 1 has been added to the stack. 
*Jan 16 21:02:54.579: %STACKMGR-6-ACTIVE_ELECTED: Switch 1 R0/0: stack_mgr:  Switch 1 has been elected ACTIVE. 
*Jan 16 21:03:56.036: %LINEPROTO-5-UPDOWN: Line protocol on Interface Lsmpi18/3, changed state to up
*Jan 16 21:03:56.036: %LINEPROTO-5-UPDOWN: Line protocol on Interface EOBC18/1, changed state to up
*Jan 16 21:03:56.037: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to down
*Jan 16 21:03:56.037: %LINEPROTO-5-UPDOWN: Line protocol on Interface LIIN18/2, changed state to up
*Jan 16 21:03:57.038: %HMANRP-6-HMAN_IOS_CHANNEL_INFO: HMAN-IOS channel event for switch 1: EMP_RELAY: Channel UP!
*Jan 16 21:03:57.041: %HMANRP-6-EMP_NO_ELECTION_INFO: Could not elect active EMP switch, setting emp active switch to 0: EMP_RELAY: Could not elect switch with mgmt port UP
*Jan 16 21:03:58.092: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to down



is not recognizing the AP licenses on that version 16.06.08 or something needs to be done in the config?

 

Thanks!!!

Rich R
VIP
VIP

Your problem is nothing to do with licensing - Converged Access (wireless on 3650/3850) is not supported after IOS-XE 16.3.x

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/16-5/release_notes/ol-16-5-3850.html

See under important notes: "Converged Access (CA) is not supported beyond Cisco IOS XE Denali 16.3.x."

One more reason why you shouldn't be doing wireless on 3850.  Cisco abandoned the technology because it had so many problems.

So the latest release you can use for wireless on your 3850 is 16.3.11 (so no 16.6.x @Leo Laohoo)

That IOS release train will not have any more updates now https://www.cisco.com/c/en/us/products/collateral/switches/catalyst-3850-series-switches/eos-eol-notice-c51-740255.html

 

I will downgrade again to 16.3.x, so what were the many problems with Converged Access (CA)? did cisco abandoned that only for the 3650/3580 or in general for all lines?


Is Converged Access (CA) working good in the 9000 series or cisco removed it for them as well?

 

Thanks


@Rich R wrote:

So the latest release you can use for wireless on your 3850 is 16.3.11 (so no 16.6.x @Leo Laohoo)


I really have no idea WTF he is trying to do.  First, he insists on doing Converged Access -- And I know CA is not supported after 16.3.X.  And now he wants to do CSL.  

I only answered the portion regarding CSL and he never mentioned anything about CA.  

Calm down @Leo Laohoo  lol - he mentioned in one of his answers that the AP licenses disappeared when he upgraded.  He thought that was related to smart licensing.  Of course it was simply because it wasn't supported anymore.

Aldo.zavala@gmail.com always best to make the whole of your question clear right from the start - if you had made clear that your concern was about the AP licenses disappearing when you upgraded from 16.3 to something higher then the answer would have been immediately obvious.

Regarding converged access - it is gone forever - removed from all platforms everywhere, never to be supported again on anything.

The whole codebase was re-written for 9800 series (with a lot of porting from AireOS).  You might find some similarities (they're both IOS-XE) but 9800 is a completely new product.  Leo has mentioned a few of the problems with CA already.  Long story short - it was not a success.  There are not many people still using it and because the software is past end of software maintenance date most users are migrating away from it if they haven't done so already so you'd be wasting your time learning it.

Note that your 3500 APs (very old) are not supported on 9800 series WLC.

1700/2700/3700 series are only supported up to 17.3.x IOS-XE.

But all AC Wave 2 APs (eg 1800) are fully supported (so far)

Refer to https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html#ctr-ap_support

 

converged access means the fact that AP's can be managed from the catalyst correct?

 

so how does the new technology in the catalyst 9000 manages the AP's? 

or is it only managed by WLC and totally not by Catalyst switches anymore at all


Aldo.zavala@gmail.com wrote:

converged access means the fact that AP's can be managed from the catalyst correct?


Up to a certain degree of the wireless design, yes.  

At this point I am reading the product line of Catalyst 9200 and Catalyst 9300 and both seems to support wireless management as well.


I have no money to purchase brand new and I will have to shop for used gear again. In the old 3650/3580 models I was able to find what I needed by asking vendors to how me the output of "sh lic rig" such as:

C3850#sh lic rig
Slot# License Name Type Count Period left
-------------------------------------------------------
1 ipbase permanent N/A Lifetime
1 apcount adder 5 Lifetime

In the new catalyst 9200 and 9300 series I assume they have smart licensing by default and now way to disable, how can I check if they have licenses for wireless access points? Or do all of them come with some bundled licenses for AP?

 

 

 


Aldo.zavala@gmail.com wrote:

At this point I am reading the product line of Catalyst 9200 and Catalyst 9300 and both seems to support wireless management as well.


Same response as before:  Up to a certain degree of the wireless design, yes.

Maybe it would be a lot better if you can provide us with a clear picture of what you are trying to do & what you are trying to achieve. 

No one knows what APs you have.  So even if you go down the 9200/9300 path, there is still no guarantee the APs will be supported with the switches.  

Not everything can work with Converged Access. 

Right now I am practicing for learning purposes with a 3850 and three AP3500i

 

But I am also interested in learning the basics of 

  1. Cisco Embedded Wireless Controller on Catalyst:
    1. I found interesting that technology. I mean I have a WLC2504 but I also want to learn to use the Catalyst as a wireless controller as well. Right now I am facing the limitations of my current gear and I am considering to explore newer gen gear.
  2. Cisco Embedded Wireless Controller on AP
    1. Somebody mentioned me that there is an option of doing EWC on AP, and I found it interesting as well for small deployments or for deployments in were a WLC or a catalyst can't be used as wireless controller. At this moment only my desire of learning. 
    2. Does the EWC on AP needs special licensing to manage the other AP's ? 
Review Cisco Networking products for a $25 gift card