ISE integration with Prime Infrastructure,

Hi Team,
  I would like to know what are the advantages and Disadvantages of the ISE integration with Prime Infrastructre.Also  how the LAN, wifi, and identity management part (guest access etc) will work together.
Cheers!!!
Minakshi

Prime Infrastructure manages the wired and the wireless clients in the network. When Cisco ISE is used as a RADIUS server to authenticate clients, Prime Infrastructure collects additional information about these clients from Cisco ISE and provides all client relevant information to Prime Infrastructure to be visible in a single console.
When posture profiling is enforced in the network, Prime Infrastructure talks to Cisco ISE to get the posture data for the clients and displays it along with other client attributes. When Cisco ISE is used to profile the clients or an endpoint in the network, Prime Infrastructure collects the profiled data to determine what type of client it is, whether it is an iPhone, iPad, an Android device, or any other device.
Cisco ISE is assisting Prime Infrastructure to monitor and troubleshoot client information, and displays all the relevant information for a client in a single console.

Similar Messages

  • Ask the Expert: One Management with Prime Infrastructure 1.2

    With Tejas Shah
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions from Cisco expert Tejas Shah on One Management with Prime Infrastructure 1.2 Combining the wireless functionality of Cisco Prime Network Control System (NCS) with the wired functionality of Cisco Prime LAN Management Solution (LMS),  Cisco Prime Infrastructure simplifies and automates many of the day-to-day tasks associated with maintaining and managing the end-to-end network infrastructure from a single pane of glass. The new converged solution delivers all of the existing wireless capabilities for RF management, user access visibility, reporting, and troubleshooting along with wired lifecycle functions such as discovery, inventory, configuration and image management, automated deployment, compliance reporting, integrated best practices, and reporting.
    Tejas Shah is a senior technical marketing engineer for Cisco Prime Infrastructure and Collaboration products. He has deployed Cisco Prime Collaboration Manager at various customer sites to help customers monitor and troubleshoot their video infrastructure. In addition, he is part of the Network Operations Center team at Cisco Live events for six years. Shah joined Cisco in 1995 and was in the Technical Assistance Center team supporting various network management system products for more than six years.
    Remember to use the rating system to let Tejas know if you have received an adequate response. 
    Tejas might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the Wireless Mobility sub-community discussion forum shortly after the event. This event lasts through Sept 21, 2012. Visit this forum often to view responses to your questions and the questions of other community members.

    Raun, please see my responses inline:
    Can you go over the licensing method with Prime Infrastructure 1.2 please? 
    Raun, you can check out the following link for ordering guide at
    http://www.cisco.com/en/US/products/ps12239/products_data_sheets_list.html
    I currently have NCS and do NOT currently have LMS.  I know I can move to Prime Infrastructure through Cisco Product Upgrade Tool.  However, what I am confused about is do I still have to buy LMS to have LMS functionality in Prime Infrastructure 1.2? 
    ==> Not at all.  The converged product will give you basic management capability for routers and switches that LMS provided in this release.   Feature/Functionality will keep on growing with upcoming releases.
    If not, do the licenses I transfer into Prime Infrastructure 1.2 from NCS also work for devices to work under LMS? 
    ==> Licensing is different than NCS or LMS.  You don't have to transfer the license.  Each install of Prime Infrastructure will have a unique UID string on which the licenses are based.  A new license will be applied to the product.
    Mean, can my currently 350 licenses be used for AP's as in NCS and routers in the LMS portion of Prime Infrastructure 1.2?
    ==> I would recommend getting a total count of your wired and wireless devices and match the right SKU based on that.
    Hope this helps.. Let me know if you have any further questions,
    Tejas

  • Managing vty ACLs with Prime Infrastructure?

    I have a number of devices -- various models of Nexus, (2k - 7k), 6500s and some 1U stackables.
    I'm trying to come up with a good way to leverage PI (2.1) to apply a vty ACL to the switches. There does not appear to be a template for this. The problem of course is not only the order of operation (remove ACL from vty if there is one so Prime doesn't lock itself out, only then do the rest of the stuff) but that the syntax seems to differ very aggravatingly -- some require "line vty 0 1509," some "line vty 0 1510," some platforms accept named ACLs for vty ACLs, some don't...
    Any tips, tricks, or best practices on how to install and update vty ACLs on IOS and/or NX-OS devices with Prime Infrastructure?

    I am also interested in this topic. We have vty ACLs in place but with different names. Would like to be able to find and update the ACL's and vty config. Using PI 2.1.

  • Cisco ISE integration with third-party firewalls

    Can Cisco ISE be integrated with a third-party firewall (such as Checkpoint), to provide authentication/authorization services to remote VPN user devices (based on device MAC address)?
    The remote user would establish a VPN connection to a third-party firewall, based on a username/password authentication, but the user would only be allowed to send/receive traffic to the internal network if the MAC address of the device being used was authorized by Cisco ISE.
    Thank you in advance.

    Rui,
    I do not think the vpn client sends the ip address in a called-station-id, that might be the public ip address that the client is initiating the request from. If you have an existing radius server or can run a packet capture you should be able to verify that.
    If the client does send the mac address in the radius packet then you can create a custom condition that can be used to check the mac address along with the username to allow it access to the session. However in VPN deployments there is no concept of profiling since 802.1x deployments usually include the client's mac address.
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • ISE integration with Mobile Device Management ( MDM ) help required

    Dear Techies,
         Am here bring to your notice an different issue and no much resources to support even in PEC or Cisco Document.
         We are conduction a Proof Of Concept (PoC) on  Secure Bring Your Own Device ( BYOD ) using Cisco ISE and gonna test all the scenarios like Wired, Wireless and VPN user access.
    Setup Brief :
    =========
          Our Setup has  ISE VM acting as Admin, Monitor and Profiling Device, we have NAC 3315 physical Appliance as Inline posture Device, Wireless LAN controller, Access point and the Identity source as Microsof Active Directory
         Having Plans to Integrate Mobile Device Management ( MDM ) and Citrix VDI setup also.
    Activity Brief:
    =========
         As of now we have tested the Wired Scenario Authentication and authorization for guest users and gonna carry out the profiling and posture.
    Clarifications Required
    ================
    Wired Scenario - Require some configuration / steps on how to carryout posture for the guest wired users i.e. LAPTOP.
    Wireless Scenario
    MDM can be integrated to ISE ? 
    How the MDM can be integrated to Cisco ISE configuration or Guide to show the same?
    What is the demarcation between MDM and ISE ( i.e. What is the role of ISE and MDM on Mobile Devices ) ?
    If MDM is available so then when the control of ISE ends, does MDM do management or ISE will do management of the devices ?
    Is MDM will do client provisioning or ISE should do ?
    Is MDM send or update patches of Mobile Devices ?
    As of now these are the scenarios, kindly revert if any good documents to show this or share your expertise on the Integration Part.
    Thanks for Reading...
    Arun

    I would like to avail your valuable inputs to understand on the  Client provisioning part for the Mobile Devices/ Laptop. I understand  from your reply that MDM integration is not available in the current  release ISE 1.1 - That is correct.
    Kindly let me know your views or any documents on the following scenarios with the current release in mind
    1. User  with Mobile devices connecting to Wireless  ( both Employee  and Guest ) , How the Flow differs for the Employee and Guest.  How the  client provisioning is done ( i.e. Like Posturing  or Compliance Check  ).
    The posturing and compliance check is done based on the user authentication information (i.e. AD memberOf vs Guest user) combined with the users endpoint (windows, mac osx, or a mobile device), ISE then has a few decisions to make based on the authorization policies. For example, if a Domain User coming from a Windows 7 machine joins the network, then can either use the nac agent, or the web agent. Then you can scan for registry settings, file settings, program requirements, hotfix compliance...and the list goes on. If the user fails a check then you can either assign an acl for the user so they only have guest access, or you can place them into a remediation vlan the options are entirely up to the requirements and however the solution is implemented.
    2. User  with Laptop  connecting to Wireless  ( both Employee  and Guest ). How the client provisioning is done ( i.e. Like Posturing   or Compliance Check ).
    Guests are usually redirected to the guest portal which they authenticate and their user group falls within the Guest container that is on the ISE internal database, that is usually coupled with an authorization profile that grants them internet access. For the client provisioning, that is usually done based on the operating system, via profiling (dhcp, and user agent string., netmap...etc) and can be fine tuned for all laptops or to a specific set of users based on their group membership.
    3. What are advantages of having ISE also in  place for Mobile devices, since most of the Mobile related tasks ( like  Authentication, Authorization, Profiling and  Posture ) are carried out  by MDM. I am checking for the significant advantage of having ISE for  Client network having only Mobile devices. Kindly clarify.
    Currently the advantage of Cisco ISE is that it supports profiling within wireless and really fits well within a network that has mostly Cisco products since they are all part of of the Borderless security initiative being driven on the backend. The product teams for wireless, wired, security (vpn..etc) and ISE are pretty close in building their solutions so that you can get connected with any device any where (sorry for the sales pitch). The latests wireless code is improving and is going to have support similar to the ios sensor for wired devices where dhcp, cdp, and other attributes can be sent in the radius packet for better profiling decisions. With integration for an MDM platform coming soon, and also support for TACACS rumored (have to verify with your account rep) you have options that really stand out from a unit that only supports MDM. Cisco ISE also comes with a wireless product ID so that makes the budget work when it comes to deploying ISE if you arent looking for enforcement on your wired devices.
    4. Do you recommend 802.1X Authentication to use for the Employee and Contractor? The Guest user  authentication as Open ?
    For internal users and vendors the best option by far is dot1x, almost all operating systems are capable of performing dot1x and the 1.1.1 MR has a piece now that can provision the supplicant for the users, by using scep to enroll certificates or configure peap settings.
    There is a feature within the guest portal that allows you to statically assign guests into endpoint group, that feature is called device registration web authentication. It seems like an open network but uses mac filtering to assign these devices to an endpoint without requiring users to enter any credentials. They are presented with an AUP page, once they accept their mac address is mapped to the endpoint group
    5. How can we ensure the Encryption of traffic from the Guest user to the NAD ( Network Access devices ) ?
    This may be a wireless question but I am sure the encryption is done using AES and using dot1x as the key management here is a brief background for this - http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807f42e9.shtml#L2
    You can also use the anyconnect client which can provide macsec which is layer 2 encryption for wired - http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-622477_ns1049_Networking_Solutions_Q_and_A.html
    6. We are also looking for VDI  ( Citrix, VMware ) solution for the  client  ( both Employee and Guest ) , how ISE can play a role in  securing the VDI environment.
    For most thin clients you can perform dot1x authentication on the device itself, however that is something the manufacturer will have to support. This is a little gray for me.
    7. Is that any integration required  with Citrix or VMware. How the  VDI can be offered based on the User  role ( i.e. Employee, Contractor or Guest ), since Guest database is  available only with ISE, how the checks are made from the VDI  environment.
    IN ISE there is an identity sequence which can authenticate users in AD first, if the user is not found then it can look in the internal database.
    Our solution demands  MDM in the integrated  solution, As on today ISE cant be integrated with MDM. so what kind of  solution we can propose to have MDM and Cisco ISE .Do the clients now  enter the network should have already installed the MDM agent (or) any  other way of pushing the same to the Client.
    Today there is no integration between the devices, the last release time I heard was December for this feature. However it would be best to confirm with your Cisco Account rep on this issue.
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • Cisco ISE integration with SMS passcode Device

    HI Experts,
    i have a scenario where the requirement is to integrate the ISE device with SMSpasscode device which will trigger the OTP to the mobile devices 
    Currently i have my authentication configured to work with the AD 
    When my VPN users connects  its authenticates against AD and the users get the access . 
    Now as per the new requirement once the user is authenticate against AD ,  the user should be prompted for the OTP password send to the users  using SMS passcode device 
    Anyone had worked on similar requirement please help me to resolve the issue .
    Thanks in advance 
    Angus

    Hi all
    I am working exactly for a month on this topic with no success.
    I need to integrate VASCO OTP solution. But VASCO do not support any external authentication backend for virtual/SMS token. Only passcode or local authentication.
    I need to implement an external authentication against LDAP somewhere...
    Gunnar, do CISCO clearly says it is not able to participate to such setup?
    So, my need would be to be able to insert in the flow an authentication in ISE against the LDAP.
    The flow is:
    WebApplication send login+password (LDAP) to ISE
    ISE checks the credentials and if it is OK forward the request to VASCO
    VASCO does not check for password but generate the OTP and send it via SMS
    VASCO replies with a access-challenge
    ISE forward the challenge to Web Application
    WebApplication send login+OTP response to ISE
    ISE forward to VASCO
    VASCO checks for OTP and replies to ISE with accept
    ISE forward to Web Application
    User is logged in...
    All the flow is working if the user enters a passcode
    I would like to implement a Identity source sequences where the user is checked again all the entries not the first match
    First LDAP then VASCO...

  • ISE integration with Oracle LDAP

    Does ISE integrate with Oracle OID LDAP (Version 11G)? If yes, which version?

    ISE supports any LDAPv3 compliant servers

  • FortiGate MIB Compatibility with Prime Infrastructure

    I have a Cisco Prime Infrastructure deployment that I would like to monitor various third-party devices. I have successfully discovered my FortiGate 60D device, but it has no monitoring functionality.
    I am trying to create a custom SNMP polling template to deploy to the device and I'm wondering is the FortiGate MIB is even supported by PI? If so, which SNMP MIB do you select when creating a new template?

    The FortiGate SNMP page on the FortiGate Web GUI links two MIB downloads:
    FORTINET-FORTIGATE-MIB
    FORTINET-CORE-MIB
    I have successfully uploaded the FORTINET-CORE-MIB file to the Prime Infrastructure MIB list and I am able to successfully apply that MIB to a template and the template to a dashlet, which outputs data. The issue is when I try to upload the FORTINET-FORTIGATE-MIB file, it produces an error message showing:
    Regards,
    Tom

  • Help with Prime Infrastructure Client Tracking

    I'm running PI 1.2.1.012 and I'm having issues populating client information. Most of my switches are 2960 series. Specifically I get a lot of MAC Address "Unknown" and nothing in the IP address field. I probably get about 25% of the correct MAC address and 10% of the IP addresses. I also run CiscoWorks Prime LMS 4.3.2. and the user tracking information is about 98% correct pertaining to MAC address and IP address. My other network management tools also are very accurate. Any help would be greatly appreciated.

    Same Problem here. I've discovered all the access switches in the environment and they are "Managed" in Device Work Center. Previously we used CiscoWorks and that populated the Mac address, IP address, along with what switch the end host was connected to. That was very helpful for our Helpdesk in troubleshooting. Im now trying to setup the same thing in Prime. Looking at a individual switch the MAC would populate but nothing on IP Address.
    Im at a loss. I've newly taken over the position of Network Analyst so maybe there is a licensing issue that we didnt get that im not aware of thats not bringing the ISE or LMS portion of Prime into play?

  • Cisco ISE integration with AD fails

    Cisco ISE Ver: 1.1.2.145
    Windows : Win 2003 Server
    I am attempting to integrate ISE with AD, but ISE won't join AD and joining attempts fails, though I am able to add same domain as external LDAP identity store ?
    1.user used to join the domain has admin permission on AD
    2. ISE resolved the domain correctly
    3.There is a firewall inbetween ISE (192.168.100.10) & AD (172.16.100.1), but all the traffic are permited.
    4. No NATing taking place, Firewall is forwarding all trafic between ISE & AD
    Can't really understand why AD connection fails
    From ISE Interface - Detailed Test Connection
    Adinfo (CentrifyDC 4.5.0-357)
    Host Diagnostics
      Uname: Linux Iseadn 2.6.18-274.17.1.el5PAE #1 SMP Wed Jan 4 22:49:48 EST 2012 I686
      OS: Linux
      Version: 2.6.18-274.17.1.el5PAE
      Number Of CPUs: 1
    IP Diagnostics
      Local Host Name: Iseadn
      Local IP Address: 192.168.100.10
      FQDN Host Name:iseadn.gnet.cp
    Domain Diagnostics
      Domain: Gnet.cp
      Subnet Site: Default-first-site-name
        DNS Query For: _ldap._tcp.gnet.cp
        Found SRV Records:
          Gnet.cp:389
      Testing Active Directory Connectivity:
        Domain Controller: Gnet.cp
          Ldap:      389/tcp - Good
          Ldap:      389/udp - Good
          Smb:       445/tcp - Good
          Kdc:        88/tcp - Good
          Kpasswd:   464/tcp - Good
          Ntp:       123/udp - Good
      Domain Controller: Gnet.cp:389
        Domain Controller Type: Windows 2003
        Domain Name:            GNET.CP
        IsGlobalCatalogReady:   TRUE
        DomainFunctionality:           2 = (DS_BEHAVIOR_WIN2003)
        ForestFunctionality:           0 = (DS_BEHAVIOR_WIN2000)
        DomainControllerFunctionality: 2 = (DS_BEHAVIOR_WIN2003)
      Forest Name: GNET.CP
        DNS Query For: _gc._tcp.GNET.CP
      Testing Active Directory Connectivity:
      Forest Name: GNET.CP
    Kerberos Error: Rc=-1765328377 SASL Bind To Ldap/[email protected] - GSSAPI Mechanism With Kerberos Error  : Server Not Found In Kerberos Database
    Computer Account Diagnostics
      Not Joined To Any Domain
    System Diagnostic
      Not Joined To Any Domain
    Centrify DirectControl Status
      Not Joined To Any Domain
    Licensed Features: Enabled
    SELinux Status:                 Disabled
    Amavis1.1.0
    Ccs1.0.0
    Clamav1.1.0
    Dcc1.1.0
    Dnsmasq1.1.1
    Evolution1.1.0
    Ipsec1.4.0
    Iscsid1.0.0
    Milter1.0.0
    Mozilla1.1.0
    Mplayer1.1.0
    Nagios1.1.0
    Oddjob1.0.1
    Pcscd1.0.0
    Postgrey1.1.0
    Prelude1.0.0
    Pyzor1.1.0
    Qemu1.1.2
    Razor1.1.0
    Ricci1.0.0
    Smartmon1.1.0
    Spamassassin1.9.0
    Virt1.0.0
    Zosremote1.0.0
    From Ad-agent log

    Hi Jallaluddin
    I work for Centrify Support and saw your posting. Here our analysis on checking the adlogs.txt.zip:
    Server not found in Kerberos database" (reference base/adbind.cpp:495 rc: -1765328377)
    That error is likely coming from the KDC - meaning there is some problem with server side SPNs
    We need the following:
    1) A network trace.
    2) adcheck output.
    3) adinfo --support output
    4) Run dcdiag or netdiag on the server side.
    Also we partner with Cisco and so would it possible to work with your partners and I am pretty sure they have seen this before with DC issues etc. Can you please work with them and see?. TIA
    Best Regards
    Raghu Srinivasan

  • ISE integration with XenMobile

    We are trying to leverage XenMobile with ISE and have it added and it Test successfully.  Devices have already been enrolled into MDM, we are wanting to query the MDM to determine if the device is Registered, JailBroke, etc to determine access.  In testing the reports show that that a known device in MDM is "un-registered" and all the other fields are unknown.  From ISE I can see that the endpoint id is a identifier within the XenMobile Device Manager.  I am not part of the group that does the configuration of the MDM so I have limited access to it.  I can login to the portal and check the device in question but I don't see any fields that reflect the exact definitions that are in ISE.
    As I stated the "Test" comes back successful.
    Thanks,
    Joe

    2015-01-12 08:29:40,225 INFO   [Thread-42][] cisco.cpm.mdm.api.MdmBaseApi -::0a1f06840002becc54b3da2b:::- GETMDM Server URL: https://xdm.XXXX.com:443/zdm/ciscoise/dev
    ices/0/macaddress/48437C7ACFA0/all
    2015-01-12 08:29:41,034 INFO   [Thread-42][] cisco.cpm.mdm.api.MdmBaseApi -::0a1f06840002becc54b3da2b:::- MDM Server Response Code: 500
    2015-01-12 08:29:41,035 WARN   [Thread-42][] cisco.cpm.mdm.api.MdmBaseApi -::0a1f06840002becc54b3da2b:::- Failled to connect to MDM Server 500 : Internal Server Error
    2015-01-12 08:29:41,040 WARN   [MdmEventHandler-25-thread-2][] cisco.cpm.mdm.util.MDMUtil -::0a1f06840002aab854b008ad:::- Couldn't find the endpoint information for mac
     address 48:43:7c:7a:cf:a0
    Looks like ISE isn't getting a response from the mdm server, is it possible to check the mdm api to verify it is up and running?
    Thanks,
    Joe

  • ISE integration with SMS gateway required license

    Hello All,
    We have cisco WLC with guest wireless access configured to use local database. the managment requires new solution to send cridintials to user throug SMS after the user signup through portal.
    we decided to use the cisco ISE. my question is what is the required license to integrate ISE with WLC and SMS gateway. should we use the Basic license, advanced or the wireless license.
    Thanks,
    Amr

    Hi Charles,
    why do you say "you would need Base and Plus Licenses at a minimum"? 
    Looking at the ISE licensing guide (table 2):
    http://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/datasheet-c78-730772.pdf
    it seems that Guest Portal services are already included in Base License (and all the AAA stuff too),
    therefore enough for the "Wireless Guest Access with SMS authentication" needed by Amr.
    Finally, the advantage of 'Base' license is that is Perpetual ...no annual fee to pay ;-)
    Regards.
    Gio

  • ISE integration with WLC 7.0 code

    Hi friends,
    i just need to get clear the douts about the features are not supporting in 7.0 code
    The features does not support in this integration are as follows:
    No support for guest clients – posture for guest user is not supported
    H-reap local switching is not supported -
    No support for WLAN(s) without 802.1x support.
    Client will go through posture during slow roam – when client is associated used 802.1x (not wpa2 or cckm) then when client roams from one WLC to other – WLC will send new session ID hence client will again go through posture validation process.
    No support for guest tunneling mobility.
    Mac auth. bypass is not supported
    VLAN pooling is not supported
    No support for AP group
    what are VLAN pooling and Mac Auth. and guest tunneling mobility can you plz explain?
    and i need to know that these features are supporting? if yes than in wich code?
    specially CWA, VLAN pooling and AP groups?
    appreciate your reply!
    Thanks

    VLAN Pooling:
    Integration of VLAN Pooling, or the VLAN Select feature, in the       7.0.116.0 release provides a solution to this restriction where the WLAN can be       mapped to a single interface or multiple interfaces using interface group.       Wireless clients associating to this WLAN will receive an IP address from a       pool of subnets identified by a MAC hashing algorithm which is calculated based       on the MAC address of the client and the number of interfaces in the interface       group. In the instance that the interface selected from the interface group by       the MAC hashing algorithm does not serve the IP address to the client for some       reason (dhcp server unreachable, dhcp scope exhausted, etc.), that interface       will be marked as dirty and a random interface is selected from the interface       group.
    Guset Tunneling:
    Mobility, or roaming, is a wireless LAN client's  ability to maintain its association seamlessly from one access point to  another securely and with as little latency as possible. For more detail you can see
    http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70mobil.html

  • Prime Infrastructure 2.1 problem with sorting devices in device groups

    Hi,
    I have a problem with prime infrastructure, namely prime is not doing appropriate sorting of devices in default device groups.
    Example: device type > routers > Cisco 2800 series integrated services routers - under shown results there are Cisco 2911 Integrated Service router, Cisco 2901 etc.
    Any solution? 
    Tnx

    Hi all:
    I have tried using Designing Monitoring Template to set the Health Check Polling time from default 15 minutes to 5 minutes and also tried also 1 minute.
    The result is 5 minutes is working but 1 minute is not working.
    May I know any one can help on this?
    Many thanks!
    Best regards,
    tangsuan

  • Prime infrastructure 1.2

    Hi all,
    Yesterday I installed my first Cisco prime infrastructure 1.2.
    I'm a bit confused now, is this the integrated version of LMS and NCS? At first sight, there's not a lot LMS in it.
    I don't see topology services, netconfig etc.
    Since the release of LMS 4.0 I'm struggeling with the licenses every time. No exeptions this time, our customer has + 100 access points and + 100 switches.
    We have 125 NCS licenses
    Do we need separate licenses for the switches? Or are they included in the NCS license. According to a cisco licensing engineer LMS and WAN are not compatible with Prime Infrastructure 1.2.
    Can anyone clarify this for me?
    Thanks
    Best Regards,
    Joris              

    You are correct in saying there's not much LMS in Cisco Prime Infrastructure.  They are essentially still 2 different products even thought future plans are to combine both wireless and wired mgmt in future releases of Prime Infrastructure.
    Licensing will also stay separate for now even though Cisco is generating LMS and WAN license files with Prime Infrastructure...both of which are useless and have only confused the fact. 
    Certain contracts allow for migrating LMS licenses to Prime Infrastructure but it makes no sense to do that because the current version of Prime Infrastructure has only a couple of LMS features currently available. 

Maybe you are looking for