cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9232
Views
18
Helpful
7
Replies

DTLS license for Catalyst 9800

aypopoff
Level 1
Level 1

Hello,

Could you advise how to order DTLS license(LIC-C9800-DTLS-K9) for existing  Cat 9800 controller ?

 

For example, I have installed C9800-L-C-K9. It was ordered without LIC-C9800-DTLS-K9 license.

Now I need to enable DTLS encryption. So how to order LIC-C9800-DTLS-K9 (without controller) ?

 

 

1 Accepted Solution

Accepted Solutions

No, this has nothing to do with DTLS, you can enable and use DTLS without it.

View solution in original post

7 Replies 7

marce1000
VIP
VIP

 

 https://www.cisco.com/c/dam/global/de_de/training-events/Roadshow2012/pdfs/Licensing_Cisco_FAQ.pdf 

                       (check first question)

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Talk to the supplier you purchased the 9800 from. They would be able to tell you. In AireOS, dtls was based on the image you download, LDPE image didn’t have dtls, but non LDPE you can enable dtls.
-Scott
*** Please rate helpful posts ***

Grendizer
Cisco Employee
Cisco Employee

LIC-9800-DTLS-K9 is not smart license or PAK based license, it is perpetual license that cost $0 and at this time can't be purchase as spare (separately from the original order). Even if you are able to purchase it separately (which you can’t) there is no installation needed for it. You can enable and use the dtls from the AP Join profile without it. This is just for entitlement.

May I ask if you need it to secure the Mobility tunnels or to secure CAPWAP data tunnel?

9800 Mobility tunnel is always secure and encrypted, there is no way to disable it and is used to communicate the mobility messaging securely between mobility peers, this is not tied with DTLS License.

By default, the CAPWAP control plane is encrypted and can’t be disabled but CAPWAP data plane is not encrypted by default and you can enable the encryption for it if you are in a country allow that.

So the short answer is, you can’t purchase LIC-9800-DTLS-K9 which has no dollar value (cost is $0). Maybe Cisco will change that in the future.

Great thanks for response.

>> You can enable and use the dtls from the AP Join profile without it.
To enable DTLS in the AP Join profile, the controller should be registered  in CSSM (Smart Account) with Export-Controlled Functionality enabled.  Right?

If customer's smart account doesn't have  Export-Controlled Functionality allowed, then, while registering controller, while generating new token, checkbox to enable export-controlled functionality will not be available.
And DTLS in the AP Join profile will not be available too. Right?

No, this has nothing to do with DTLS, you can enable and use DTLS without it.
Review Cisco Networking products for a $25 gift card