Cisco ISE license count

Hello,
I noticed a weird issue on my ISE deployment. The Active Endpoints and Active Guests Counters on the ISE home page adds to a total of 105 users but when i check my license counter. I see 234 base licenses used and 221 advanced licenses used. Please what could be the problem or what am i missing?

base license counts and dashboard active endpoints not matching
CSCui07434
Description
Symptom:
ISE base license counts and the active endpoints displayed at ISE dashboard are not matching
Conditions:
ISE 1.2.0.x

Similar Messages

  • Cisco ISE licensing...

    Hi,
    seeking help to reduce our ISE licensing cost, actually we are out budget and we planning to order ISE licenses less than what we required, and looking for efficiently using the same, is there any way, i mean if we reduce "user idle timeout" is it reduce our license consumption?
    any kind help appreciated...
    thank you,

    License Count
    A Cisco ISE user consumes a license during an active session. Once the sessions has ended, ISE releases the license for reuse by another user.
    The Cisco ISE license is counted as follows:
    A Base, Plus, or Advanced license is consumed based on the feature that is used.
    An endpoint with multiple network connections can consume more than one license per MAC address. For example, a laptop connected to wired and also to wireless at the same time. Licenses for VPN connections are based on the IP address.
    Licenses are counted against concurrent, active sessions. An active session is one for which a RADIUS Accounting Start is received but RADIUS Accounting Stop has not yet been received.

  • Exceeding ISE license counts - performance consequences?

    Hello,
    I have a customer that is running a 2-node ISE deployment and is licensed for 250 Base and 250 Adv. users.
    We have moved the wired users over in one of their offices into Monitor Mode only, and the Base/Adv. Active license counts have exceeded both these values.
    Long-term, what is the operational impact?
    I understand from Chapter 7 of the ISE User Guide that "To avoid service disruption, Cisco ISE continues to provide services to endpoints that exceed license entitlement. Cisco ISE instead relies on RADIUS accounting functions to track concurrent endpoints on the network and generate alarms when endpoint counts exceed the licensed amounts"
    My question is, that aside from a scenario where TAC is engaged and they see the license count exceeded, what is the operational and functional impact of exceeding the license count.  I know that ISE continues to process autthentications, because the 251st client is not refused access.
    I've read the Order Guide and the User Guide and the Hardware Guide, and no actual impact is mentioned.
    thanks in advance,
    Andrew

    I had a similar question. I asked how does ISE calculate users. In the wlc I would see 10k radius clients but ISE would show half that number. This is what I was told:
    Unfortunately there is no documentation on it. The active endpoints are calculated from the active sessions seen on the primary monitoring node session database, meaning active client sessions seen by PSNs and reported to the primary monitoring node. As to the rules that qualify an endpoint as active, there isn?t really even any internal documentation on that. The effective behavior seen indicates that this is calculated by endpoints who authenticate and continue to re-authenticate/periodically trigger accounting updates from NADs. Hopefully this helps!
    Tac case # 627456397
    Sent from Cisco Technical Support iPad App

  • Cisco ISE license file

    I would like to backup the license file to apply for a fresh installation on the same hardware (3355). Is that possible? I tried resetting the configuration from the CLI and the license was excluded, it was necessary to do a restore.

    By re-hosting you can do:
    please check the link https://supportforums.cisco.com/discussion/11728041/ise-license

  • Cisco ise licensing question

    Hi there,
    I got a ISE 3315 with an IP-Plus license on it. Now I need to install a Wireless advanced license, but I got an error when trying. I've read that the wireless license doesn't need the ip-base one but I can't remove it?
    Any ideas?
    Thanks, Norbert
    Sent from Cisco Technical Support iPhone App

    you can't edit the license file.  If you think it's wrong open a TAC case with the licensing team and they will work with you to cut the correct license.
    HTH,
    Steve
    Please remember to rate useful posts, and mark questions as answered

  • Basic ISE Licensing question

    Hi,
    Just a question on ISE license consumption.
    If a user logs in and gets authenticated (user authentication) via ISE on a device that is already authenticated (device authentication), does it consume 2 licenses, one for the device and one for the user?
    This is nowhere clearly told in any cisco documentation.
    Can anybody help me clarify this?
    Thank you,
    Mohan

    The base package includes all of the base services required to enable 802.1X, Guest, and Monitoring and Troubleshooting. The advanced package includes Posture, Profiler, and Security Group Access services.
    Cisco ISE is bundled with a licensing mechanism that has the following important features:
    •Built-in License—Cisco ISE comes with a built-in evaluation license, which is valid for 90 days. The evaluation license includes both base and advanced packages and limits the number of endpoints to 100 for both the base and advanced packages. Therefore, it is not required to install a regular license immediately upon installation.
    •Central Management—Licenses are centrally managed by the ISE administration node. In a distributed deployment, where two ISE nodes assume the Administration persona (primary and secondary), upon successful installation of the license file, the licensing information from the primary Administration node is propagated to the secondary Administration node. So there is no need to install the same license on each Administration node within the deployment.
    •Concurrent Endpoint Count—The Cisco ISE license includes a count value for base and advanced packages, which restricts the number of endpoints that use those services. The count value is the number of endpoints across the entire deployment that are concurrently connected to the network and accessing the service.
    Concurrent endpoints represent the total number of supported users and devices. An endpoint can be any combination of users, personal computers, laptops, IP phones, smart phones, gaming consoles, printers, fax machines, or other types of network devices.
    IMPORTANT : - Alarm is generated when the soft limit of endpoints is crossed and there is no functional impact on the users. To avoid service disruption, Cisco ISE continues to provide services to endpoints that exceed license entitlement. However there are plans to implement a hard limit on this soon.
    Regards,
    Jatin Katyal
    ** Do rate helpful posts **

  • Understand ISE Licensing

    Hello,
    I am going to Order (SNS-3415-K9) ISE product to deploy at my company, my concern is the size of license I shall order, and how to know the correct number
    I have workstations (PC’s), laptops, Printers, IP-CAM’s, and WLC with 50 AP.
    How I can determine the number of license I should get in order to have the benefits from Cisco ISE.
    Best reagrds,
    Samer Hasan

    Question:
    I am going to Order (SNS-3415-K9) ISE product to deploy at my company, my concern is the size of license I shall order, and how to know the correct number. I have workstations (PC’s), laptops, Printers, IP-CAM’s, and WLC with 50 AP. How I can determine the number of license I should get in order to have the benefits from Cisco ISE.
    Cisco Identity Services Engine (ISE) Ordering Steps
    Here’s guide which can help in finding solution of your problem
    1. Estimate the number of concurrent endpoints in the network.
    2. Estimate the number of appliances (physical or virtual) needed to support the number of concurrent endpoints
         in the network.
    3. Select the appropriate type of appliance suitable for your deployment. (Reference the appliance selection.)
    4. Select the appropriate type of license suitable for your deployment. (Reference the license selection.)
    5. Select the appropriate level of services available from Cisco Advanced Services or a Certified Partner for design,
        Deployment and sustaining services of the ISE deployment.
    Step 1: Estimate the Number of Concurrent Endpoints in the Network
    Estimating the total number of concurrent endpoints is dependent on a number of variables. An approach to consider would be to take into account:
    • Number of employees in the organization
    • Average number of devices per employee (desktop, laptop, smartphone, desk IP phone, etc.)
    • Number of switch ports currently in the organization
    • Number of access points deployed in the organization
    • Average number of devices per access point
    • Dynamic IP address range being used
    • Average number of guests expected to join the network
    • Inventory of non-user devices such as IP cameras, printers, IP-enabled projectors, etc.
    A combination of factors that includes but is not limited to the above factors could be used to determine the total number of concurrent endpoints in the network.
    Step 2: Cisco ISE Appliances and Servers* Options
    Cisco   Identity Services Engine Appliances
    Option 1: Cisco Identity Services   Engine Appliances and Servers*
    Product Number
    Endpoints Supported
    Cisco Secure Network Server 3415*
    SNS-3415-K9
    5,000
    Cisco Secure Network Server 3495*
    SNS-3495-K9
    20,000
    Step 3: Cisco Secure Network Server Support SKUs*
    Product   Number
    SMARTnet Part Number
    Description
    SNS-3415-K9*
    CON-SNT-SNS-3415
    Cisco SMARTnet support for   SNS-3415-K9 - 8x5 Next Business Day
    Step 4: Select the Type of License
    Step 5: Cisco ISE License Options
    License   Type
    Features Supported
    Deployment Type Supported
    License Prerequisite
    License Term(s)
    Base License
    AAA
    Guest Provisioning
    Link Encryption Policies
    Wired
    Wireless
    VPN
    Perpetual
    Advanced License
    Device Onboarding/Provisioning
    Device Profiling and Feed Service*
    Host Posture
    Security Group Access
    Integrated Vendor MDM Support*
    Wired
    Wireless
    VPN
    Base License
    3- and 5-Year Terms
    Wireless License
    Device Onboarding/Provisioning
    AAA
    Guest Provisioning
    Link Encryption Policies
    Device Profiling and Feed Service*
    Host Posture
    Security Group Access
    Integrated Vendor MDM Support*
    Wireless
    3- and 5-Year Terms
    Step 6. Cisco ISE Functionality-Based License Options
    License   Tiers (T)
    Number of Endpoints Supported
    Base License
    Advanced 3-Year License
    Advanced 5-Year License
    Wireless 3-Year License
    Wireless 5-Year License
    Wireless Upgrade 3-Year License
    Wireless Upgrade 5-Year License
    100
    100 Endpoints
    L-ISE-BSE-100=
    L-ISE-ADV3Y-100=
    L-ISE-ADV5Y-100=
    L-ISE-AD3Y-W-100=
    L-ISE-AD5Y-W-100=
    L-ISE-W-3UPG-100=
    L-ISE-W-UPG-100=
    250
    250 Endpoints
    L-ISE-BSE-250-
    L-ISE-ADV3Y-250=
    L-ISE-ADV5Y-250=
    L-ISE-AD3Y-W-250=
    L-ISE-AD5Y-W-250=
    L-ISE-W-3UPG-250=
    L-ISE-W-UPG-250=
    500
    500 Endpoints
    L-ISE-BSE-500=
    L-ISE-ADV3Y-500=
    L-ISE-ADV5Y-500=
    L-ISE-AD3Y-W-500=
    L-ISE-AD5Y-W-500=
    L-ISE-W-3UPG-500=
    L-ISE-W-UPG-500=
    1000
    1000 Endpoints
    L-ISE-BSE-1K=
    L-ISE-ADV3Y-1K=
    L-ISE-ADV5Y-1K=
    L-ISE-AD3Y-W-1K=
    L-ISE-AD5Y-W-1K=
    L-ISE-W-3UPG-1K=
    L-ISE-W-UPG-1K=
    1500
    1500 Endpoints
    L-ISE-BSE-1500=
    L-ISE-ADV3Y-1500=
    L-ISE-ADV5Y-1500=
    L-ISE-AD3Y-W-1500=
    L-ISE-AD5Y-W-1500=
    L-ISE-W-3UPG-1500=
    L-ISE-W-UPG-1500=
    2500
    2500 Endpoints
    L-ISE-BSE-2500=
    L-ISE-ADV3Y-2500=
    L-ISE-ADV5Y-2500=
    L-ISE-AD3Y-W-2500=
    L-ISE-AD5Y-W-2500=
    L-ISE-W-3UPG-2500=
    L-ISE-W-UPG-2500=
    3500
    3500 Endpoints
    L-ISE-BSE-3500=
    L-ISE-ADV3Y-3500=
    L-ISE-ADV5Y-3500=
    L-ISE-AD3Y-W-3500=
    L-ISE-AD5Y-W-3500=
    L-ISE-W-3UPG-3500=
    L-ISE-W-UPG-3500=
    5000
    5000 Endpoints
    L-ISE-BSE-5K=
    L-ISE-ADV3Y-5K=
    L-ISE-ADV5Y-5K=
    L-ISE-AD3Y-W-5K=
    L-ISE-AD5Y-W-5K=
    L-ISE-W-3UPG-5K=
    L-ISE-W-UPG-5K=
    10,000
    10K Endpoints
    L-ISE-BSE-10K=
    L-ISE-ADV3Y-10K=
    L-ISE-ADV5Y-10K=
    L-ISE-AD3Y-W-10K=
    L-ISE-AD5Y-W-10K=
    L-ISE-W-3UPG-10K=
    L-ISE-W-UPG-10K=
    25,000
    25K Endpoints
    L-ISE-BSE-25K=
    L-ISE-ADV3Y-25K=
    L-ISE-ADV5Y-25K=
    L-ISE-AD3Y-W-25K=
    L-ISE-AD5Y-W-25K=
    L-ISE-W-3UPG-25K=
    L-ISE-W-UPG-25K=
    50,000
    50K Endpoints
    L-ISE-BSE-50K=
    L-ISE-ADV3Y-50K=
    L-ISE-ADV5Y-50K=
    L-ISE-AD3Y-W-50K=
    L-ISE-AD5Y-W-50K=
    L-ISE-W-3UPG-50K=
    L-ISE-W-UPG-50K=
    100,000
    100K Endpoints
    L-ISE-BSE-100K=
    L-ISE-ADV3Y-100K=
    L-ISE-ADV5Y-100K=
    L-ISE-AD3Y-W-100K=
    L-ISE-AD5Y-W-100K=
    L-ISE-W-3UPG-100K=
    L-ISE-W-UPG-100K=

  • Is there a trial version of cisco ISE

    Is there a trial version of cisco ISE? I need to upgrade my knowledge from ACS to ISE and I am finding it difficult to find source material.
    Thanks
    Mark

    Q. Does the Identity Services Engine include an evaluation license?
    A. Yes. The Identity Services Engine includes a free 90-day evaluation license that can support up to 100 devices. The evaluation license supports Identity Services Engine Base and Advanced software packages.
    Q. Why isn’t there an evaluation license that includes the Plus software package?
    A. We want to make sure that prospective customers have an opportunity to explore all the ISE capabilities during an evaluation period. Moreover, with Plus being a subset of Advanced, there is no need to have a different evaluation license.
    Obtaining a Cisco ISE License from Cisco.com

  • How Cisco ISE 1.2 Base licenses are consumed and tracks concurrent endpoint connected to network

    Hello
    I am interested to know how the cisco ISE 1.2 base licences are consumed. As the cisco ise 1.2 user guide "The Base License is consumed whenever an authentication notification is received by Cisco ISE."
    Based on the above statement i have following queries :-
    Radius being the UDP based request, its only during the time endpoint is authenticated and authorized the base license is consumed and then its is released. Then how does cisco ISE tracks the concurrent endpoints connected to the network.
    Thanks
    Kumar

    thanks for the reply Tarik.
    As I understand, you mean that a base license is consumed by every radius authentication request and then the license is free to be utilised again
    Also would this means if Radius accounting is turned off, then concurrent sessions will not be tracked.
    Thanks
    Kumar

  • Cisco ISE functionally and license

    HI. 
    I wanna configure the following on Cisco ISE 1.2.1.
    Self-registration portal for guests (SSID: guests)
    802.1x user certificate check (Cisco NAM supplicant) for employees (SSID: Corporate) (EAP-TLS)
    Self provisioning portal (to deploy BYOD certificate and give access for BYOD devices) for BYOD devices (SSID: Corporate) (PEAP, MSHAPv2)
    Can I configure these things with PLUS license or do I need Adv or Wireless? I am not sure if one of these requires profiling functionally.

    With plus license all the above items should work.
    Here is what plus license supports:
    Bring Your Own Device (BYOD)
    Profiling
    Endpoint Protection Service (EPS)
    TrustSec SGT
    For more info, refer ISE license section:
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_man_license.html#41012
    Regards,
    Jatin Katyal
    **Do rate helpful posts**

  • Cisco ISE - expired demo license alarm

    Hi,
    We are implementing Cisco ISE 1.2.0.899 and have an alarm reporting expired license. This alarm refers to the Advanced License demo and is therefore a false positive.
    This issue is that we cannot remove the demo icense and stop the root cause of this false positive alarm.
    Does anyone has an idea?
    Thanks in advance.
    Regards,
    Telmo Oliveira

    Please refer the discussion below
    https://supportforums.cisco.com/discussion/12059041/ise-advanced-eval-license-alerts-after-full-base-install

  • How old licenses migration during basic and advanced cisco ise?

    Hello,
    How old licenses migration during basic and advanced cisco ise?
    Regards,
    Alvaro

    Hi,
    What do you mean by migration? you are migrating to another hardware? or you are upgrading from basic to advanced license?
    here is the install/upgrade process:
    http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_man_license.html#wp1059946
    If you are migrating from one device to another I think you need to use this link:
    https://tools.cisco.com/SWIFT/LicensingUI/Home
    HTH
    Amjad

  • Cisco ISE Active Endpoint Usage Reset

    Hi,
    I have a Cisco ISE running version 1.1 and I was wondering if it may be possible to reset the license usage/active endpoint shown on the dashboard? This was noticed after a restore of ISE due to replacement of hardware and I noticed that the license usage count/active endpoints does not seems to go down.
    The following methods have been tried however without any success:
    1. Reboot ise server/service
    2. Disable all network devices making use of ise such that there are no clients/devices accessing it; example switch/wlc/etc...
    3. Deleted all endpoints usage in identies/identies group
    4. Disable profiling on ise
    As the ise has been installed with a base license; not too sure if it may be either a bad restore (all service/application are working though) / bad radius accounting which does not timed out on the ise / etc...
    Any help is appreciated on how to reset the active endpoint/license usage.
    Thanks.                  

    Here is a method for removing the stale records. Please give this a try:
    http://www.cisco.com/en/US/docs/security/ise/1.1/api_ref_guide/ise_api_ref_ch2.html#wp1072950
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • ISE Licensing for IP Phones nodes

    Hi Guys,
    I'm currently worknig on an ISE design for a network where they have IP Phones for each end user device:
     Switch <--> IP Phone <--> End User Device.
    My concern is the licensing part; i'm not really interested in authenticating or profiling IP Phone nodes. rather i need only to provide full ISE services for End user devices behind IP Phones (Authenitcation,Authorizatino,Posturing....etc.). so i need to order a base and an advanced license that cover ONLY the number of end user devices without accounting for IP Phone units.
    Considering the above requirements ; what is the best deployment scenario to consider when configuring the switch interface that connect to each IP Phone with Single host port authentication (cdp bypass). would the ip phone consume from license count.
    What if we considered doing MAB for IP Phone nides and Dot1x for End users and considering MDA ? would it consume 2 units from total license number of nodes in this case ?
    What is the best practice for deploying and licensing ISE if i Cisco or a Third Party IP Telephony solution and i don't want to autheticate/authorize/profile ip phones ? 
    Thanks,
    Muayad Jallad,

    If you are using Cisco IP phones you can get away with single-host mode on the port which in effect ignores the phone. If the phone is a third party device you will most likely need to use multi-domain authentication and actually use ISE to allow the phone on the network.
    In summary - CIsco phone means potentially no license, if Avaya or other third party you will need to auth and use a license

  • Replace Cisco ISE 3355 Harddisk

    Dear All,
    I have single Cisco ISE 3355 appliance (600 GB of Harddisk Capacity) with IPN feature. In my 3355 appliance, port ethernet 0 is broken. I already got RMA devices, but unfortunately harddisk capacity is only 300 GB.
    So, is it possible to move old harddisk (600 GB) to new RMA's appliance? Because, the problem is only port ethernet, not harddisk.
    Kindly waiting for your answer.
    Thanks.
    Irvan.

    Hi Marvin,
    Below is show version of my appliance:
    show inventory
    NAME: "NAC3355-SVR        chassis", DESCR: "NAC3355-SVR        chassis"
    PID: NAC3355-SVR       , VID: V01 , SN: XXXXXXX   
    Total RAM Memory: 3887516 kB
    CPU Core Count: 4
    CPU 0: Model Info: Intel(R) Xeon(R) CPU           E5504  @ 2.00GHz
    CPU 1: Model Info: Intel(R) Xeon(R) CPU           E5504  @ 2.00GHz
    CPU 2: Model Info: Intel(R) Xeon(R) CPU           E5504  @ 2.00GHz
    CPU 3: Model Info: Intel(R) Xeon(R) CPU           E5504  @ 2.00GHz
    Hard Disk Count(*): 1
    Disk 0: Device Name: /dev/sda
    Disk 0: Capacity: 597.90 GB
    Disk 0: Geometry: 255 heads 63 sectors/track 72702 cylinders
    It says harddisk capacity is 600 GB. The Admin and IPN is using identical box actually.  If that is not problem to move my old harddisk to new appliance, there is next question then, what's about the license?
    Do i need to request again for license prior moving old harddisk to new appliance?
    Thanks.
    Irvan.

Maybe you are looking for

  • Total(LC) field updation fails randomly

    Dear experts, I have a problem when makes Sales Order. The problem is when I type quantity, it's not updated Total (LC) but it's occur sometime and randomly . I have set an FMS in unit price field and also some validations in discount and unit price

  • FM for popup to caputure multiple values

    HI, I need a popup box in F4 help which is having multiple input fileds...Like I need ti take a input of 6 fields frim the popup. Any standard FM is there to capture the values....

  • Want to improve Yosemite's UI?

    I've been experimenting with a couple of ways to make the Yosemite UI less obnoxious. One thing that helps is to replace the default system font with something more legible. There are now a couple of ways to do this. Of course you try such things at

  • Screen capture sees only Finder

    My screen capture function does seem to work, but the only thing it sees is the Finder. When I press command-shift-4, it works just like in Tiger (plus the little coordinate numbers), and after a second or two a picture file appears on the desktop. B

  • J2ME - Canvas - repaint

    Hi, I have a stupid question. As far as I know the Canvas class of J2ME doesn't have getGraphics() method. That means, that I can't get the graphic representation of the Canvas object and so I can't make changes calling the properly methods of the Gr