Question about Cisco ISE

Good morning. We want to separate the access privilege of staff and students by using the same SSID. Currently, we are using free radius linked with the Active Directory. If we want to purchase Cisco ISE, could you please tell us what kind of license shall we buy (Base, advanced 5-year, or wireless 5-year)?  We have more than 50,000 staff and students, and the maximum simultaneous user is around 9,000 now. We noticed that the wireless license is quite expensive and has to be renewed every 5 years (For 10,000 licenses, it costs almost $200,000)! In our short term plan, we do not need BYOD, is the base license enough for our situation?If it's possible, could you please briefly introduce how does ISE work for our requirement?
Thank you, and have a nice day.
Yours,
Linchuan Yang
Concordia University

Hello Linchuan,
Wireless
Capabilities: Basic network access, guest access, profiler, posture, and SGA
Network deployment support: Wireless
License prerequisite: None
Term license: 3- and 5-year terms
Licenses are available for 100, 250, 500, 1000, 1500, 2500, 3500, 5000, 10,000, 25,000, 50,000, and 100,000 endpoints
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5712/ps11637/ps11195/qa_c67-658591.html
PS: If i were you the BYOD thing should be a thing to consider in a near future

Similar Messages

  • Basic questions about CISCO IOS

    Hi everybody, Jack here,
    I have some basic questions about the Cisco IOS, could someone help me addressing some of them please? Any feedback would be greatly appreciated.
    Basically, I have two IP addresses assigned by our Cable ISP. From what I understood you can configure a Cisco router for multiple IP addresses using the IOS, thereby allowing someone like myself to take advantage of having multiple IP addresses. This may seem unnecessary to some, but I've always wanted to put the 2nd IP address to use, since after all, I've been paying for it.
    I was just wondering if someone could confirm that what I'm hoping to accomplish is indeed within the capability of the Cisco IOS (i.e. Fully utilize my 2 IP addresses). As well, if someone could kindly suggest a decent CISCO router for online gaming home use that would be super awesome!
    Thank you all so much for reading through the wall of text:)
    Jack

    Jack
    Certainly using multiple IP addresses is in the capability of Cisco IOS routers. How they can be used depends on the relationship of the IP addresses. I am assuming that we are talking about IP addresses assigned for the user to use and that the IP address for the ISP connection is not one of these that we are talking about.
    If both of the IP addresses that you have been assigned are within the same subnet then you would assign one of the addresses to the router interface to establish IP communication between the router and the ISP and to enable Internet connectivity for the devices inside your network that will use the router as their gateway to the Internet. The other address that is assigned can be used for address translation and in particular for static address translation which would make one of your devices inside to be reachable for connections initiated from the Internet (if that is something that you might want to do).
    If the addresses that are assigned to you are in different subnets then you could assign one address to the outside router interface and assign the other address to the router inside interface. Or you could use the second address for address translation.
    I do not have much expertise with online gaming, but I would think that either the Cisco 881 router or the 890 router might be appropriate for you. If 100 Mb connection is sufficient then probably the 881 would be the one to look at. If you need Gig connection then look at the 890.
    HTH
    Rick

  • Some question about Cisco Prime Infrastructure

    Dear all
    I have some question about using Cisco prime Infrastructure:
    - Can I show how many user access to one Access Point (AP) ?
    - If I can. What is display information of user ? etc Ip address, MAC, username access, name of device (notebook, tablet, phone ..)
    - How many time do Cisco Prime Infrastructure refesh user  informantion .?
    Please help me and send picture about it if you can.
    Thank you so much.

    Hi,
    I don't have the Prime Infrastructure to post you image, but you can simply find all the answers you want on the config guide:
    http://www.cisco.com/en/US/docs/wireless/prime_infrastructure/1.2/configuration/guide/clientmgmt.html#wp1232242
    1- You can surely find how many clients associated to a specific AP.
    - Informaiton of the client usually includes username, SSID, ip address, mac address, RSSI, device vendor...etc. I don't think it contains the device type (ipad or iphone both appear as apple vendor. it does not destinguish between this and that.
    3- The time of the refreshment is configurable. You need to configure the corresponding background task for the poll period. (this is also metnioned in the link above).
    HTH
    Amjad
    Rating useful replies is more useful than saying "Thank you"

  • Quick Question about Cisco 3560 and the Web Device Manager

    Alright, I have a quick question that I am curious about but I haven't found any information
    about it.
    When I log into my Cisco 3560 using the web portal to get to the Device Manager. Below the
    diagram of the switch, then under the Dashboard there is section called Switch
    Health, Port Utilization.
    Under the Switch Health there is Bandwidth Used, Packet Error. Those two options just sit
    at zero and do not move. The Port tilization graph is also sitting at zero.
    Is there a way to make them functional?

    Anyone notice performance increase or decrease of their HD when using the nVidia IDE SW drivers?  particularly with a 74GB Raptor?  I've also heard of burner issues when installing the IDE SW but have not used my burner yet.

  • Question about Cisco Tec support Rep Live chat issue .

    Hello guys, I recently just tried to do a session of live tech support on cisco web site about a issue trying to get my router to change the speed of the wireless connection from 54mbps to the potiental maxium of 300mbps. Well This is my second time using the live chat feature and the 2nd time, the guy was asking for my router name and passowrd. I didnt feel to comformtable doing that since my first time using the live chat , the tech guy didnt ask for my operating system, or my passowrds or anything of that nature? Is that normal for a live chat guy to do that? I figured hes was trying to do a remoate access to my computer and I was thinking, they probably dont do that for free especially over a live chat. Anyeone thoughts or am i being over crictical. thanks

    if you are not comfortable then dont give them the info.
    i have not had a reason to ask then to do this, however back in the day i had a sony live rep (we were on the phone too) remote into my router to allow me to setup my sony base station (think slingbox but its made by sony) so i could get it to work when away form the home. this was a few years ago so it happens today. some businesses/stores even offer it as a solution. so dont freak out that they asked you that. dell does this for example...
    give them a call and have them on the phone with you instead.just have them give you the directions on what to do.... if not, come here and ask the questions...

  • Question about Cisco SAFE Architecture....

    All,
    I have searched high and low on the following question for a master's class and hope someone can answer or point me in the right direction. I have studied Cisco of the last many weeks and our professor asked us whether or not the SAFE architecture has any limitations... After much reading and research, I honestly came up with nothing. I am starting to think, limitations isn't the issue but issues might surface if Cisco's best practices aren't implemented. Any help for a student is greatly appreciated and thanks.
    Bob Jones

    Hi Bro
    Cisco SAFE is merely a guideline in deploying Cisco’s best practices for Cisco products and those of its partners ONLY. In fact, if you were to read on the Cisco SAFE Architecture Lifecycle, the planning phase should include a gap analysis to unveil the strengths and weaknesses of the current architecture. If the planning stage isn’t done correctly, then you should know the end results :-)
    Limitations are not on Cisco SAFE approach, but limitations are always there on either Cisco products or the software version, based on certain given scenarios. For this reason, when you were to read any of Cisco's configuration examples on certain technologies, there will always be a chapter on Guidelines and Limitations.
    P/S: If you think this comment is useful, please do rate them nicely :-)

  • Quick question about Cisco 9951

    Hi Guys,
    I'm not a VOIP guy so apologies if this is a simple question. I have a couple of Cisco 9951 phones and wanted to know if there is a way to manually setup the Call Manager ( Active Server) IP address?
    I've looked through the menu on the phone but I can't seem to see it as an option.
    Does it have to be configured for DHCP with option 150, or a tftp server directly to get the configuration details?
    cheers.

    Nope, no battery. If the behavior is consistent every reboot, you might have a defective NVRAM, this is assuming you are saving the config, this is a 2948G-L3, so it must be saved, if it's a 2948G, then it's a switch and running CatOS and therefore any configuration changes gets saved in the NVRAM as soon as you press the enter key after a "set" commmand.
    Please rate all posts.

  • Question about cisco unified callconnector for mscrm

    Hi
    I've successfully installed software on both workstation and MSCRM server, and it works well.
    However, when I use "click to call" in MSCRM,  a blank window keep poping up with message "The webpage you are viewing is trying to close the window. Do you want to close the window?"
    My question is how to let IE close the window without the confirmation window.
    I found some people use following Javascript to close the IE window.
                  <script language=javascript>
                      function CloseWindow()
                        window.open('','_self','');
                        window.close();
                  </script>
    However, if anyone can let me know where is the place to add this code into, I would appreciate
    Thanks
    Eric

    Hi!
    No, it does not work with CUCM, it works with express only. Please refer to the data sheet below:
    "Cisco Unified CallConnector for Microsoft Windows, especially designed for the small and medium-sized business (SMB) or branch-office user, is supported by Cisco Unified Communications Manager Express 4.0 and later."
    http://www.cisco.com/en/US/prod/collateral/voicesw/ps6789/ps7046/ps7274/ps7067/product_data_sheet0900aecd8053c8ad.html
    Hope this helps!
    Regards,
    Teresa.
    If it helps, please rate :)

  • Question about cisco nac agent

    When I deploy Cisco NAC appliance, the main different between using cisco nac appliance with or without agent? I see Cisco NAC agent has two function: scan and remediation. If Cisco NAC appliance without agent, Cisco NAC server will scan device and remediation. That is right?
    Please answer me early. Thank you for your answer.

    Sorry, I believe daldden is correct, without the agent you can still scan using the built-in Nessus scanner.
    We don't use the Nessus scanner, but these are some things to consider if you use the scanner. These are from memory though so anyone who actively uses the scanner may be able to give more up to date or complete info:
    1) You have to decide which vulnerabilities you want to scan for.
    2) The more plug-ins you enable, the longer (obviously) the scan takes.
    3) There are configuration steps for many of the plug-ins
    4) Your users will still need to go to a login page in order to be scanned.
    5) You have to configure the remediation information (URL, steps, etc) for each plug-in you enable.
    From our view point, the only reason we would enable the scanner is if we were looking for a specific vulnerability, perhaps a new threat that didn't yet have a patch. If it had a patch, we would watch for the patch using the agent (installed or web based).
    It was much easier for us to use the agent, to scan their system and make sure that the MS critical hot fixes were installed and/or an AV system was installed and up to date. As mentioned, if there is a patch for a vulnerability, you can use the agent to make sure that specific hot fix is installed.
    Remember that there is also a web agent. The web agent is an ActiveX or Java (you pick which one you want to use) applet that is loaded onto the person's machine, the system scanned, then the applet is unloaded.
    Of course, the agent is only for MSoft (with some MAC options), so if you have Linux systems, the Nessus scanner would be your only option.

  • Hi, I have a question about CISCO 1841 router.

    I have 4 devices which are named 1841.
    But, I have trouble handling these..
    To help my question, I suppose that router's name is set A, B respectively.
    A (DCE) ------- (DTE) B (slot0 ,1 --> WIC-1T)
    Now, I connected routers upper contents.
    But WIC-1T's CONN LED does not shining...
    I did below following steps...
    1. I did commands in the routers : no shutdown, encapsulation ppp, clock rate 115200 (In this case, I designated at DCE)
    2. Change another cable which was NEW one.
    3. Change another router (Of course WIC-1T is put in)
    I really don't know what can I do...to perform it.....
    Ah... plz response my question...
    Thank you.
    Regards,

    And I did "show ip interface brief" command.
    Router#show ip int b
    Interface                    IP-Address      OK? Method Status                Protocol
    FastEthernet0/0        unassigned      YES NVRAM  up                     down
    FastEthernet0/1        unassigned      YES NVRAM  up                     down
    Serial0/0/0                unassigned      YES unset      down                 down
    Serial0/1/0                unassigned      YES unset      down                 down
    Router#
    I definitely "show down" at f0/0, f0/1, s0/0/0, s0/1/0
    But, only f0/0, f0/1 were up. 
    I don't know why Serial does not changed down to up
    Hmmm....
    It is really difficult to me ...
    The harder study in network, the more difficult...
    Anyway! 
    Please reply me!
    Regards,

  • Quick easy question about cisco 2948 l3 switches..

    Hi Everyone,
    I was wondering is there a battery backup in the cisco 2948 L3 switches. I have googled for this and checked the manuals and i cannot find anything. I only ask this because everytime one of our two 2948's are rebooted they lose their configs and have to be manually reconfigured. So I am hoping it is a battery problem rather then the NV ram has gone bad (if that is possible)
    Thanks,
    Adam

    Nope, no battery. If the behavior is consistent every reboot, you might have a defective NVRAM, this is assuming you are saving the config, this is a 2948G-L3, so it must be saved, if it's a 2948G, then it's a switch and running CatOS and therefore any configuration changes gets saved in the NVRAM as soon as you press the enter key after a "set" commmand.
    Please rate all posts.

  • A question about Cisco Security Manger 3.1.

    Hello at all.
    I want to manage a couple of FWSM installed on a 6500 chassis.
    What version of CSM must I use: standard or professional?
    Thanks.
    Andrea.

    You need professional, since standard doesn't support the FWSM's.
    More details here: http://www.cisco.com/en/US/products/ps6498/products_tech_note09186a0080849150.shtml

  • Question about Cisco Meraki MR32

    Hope you were good at math.
    You need to get the Avg Metric by calculating the signal strength, speed of wireless channel and distance. If your value is under 2,000 you're fine. Apologies for not remembering 

    I'm having a hard time locating information about suggested distance between access points. I'm aware of firewall, other radios, etc which will hinder the strength. Any suggestions?
    Thanks
    Mike
    This topic first appeared in the Spiceworks Community

  • Question about Cisco Works LMS 3.2

    Hi Mr Joe Clarke,
    Can CiscoWorks 3.2 discover and monitor non-Cisco devices too? Non-cisco brands such as Hirschmann, 3com and HP.

    RME and the Health and Utilization Monitor add-on can do some monitoring of non-Cisco devices, but LMS is designed for Cisco-only networks.  Managing non-Cisco devices will give you very limited functionality, and will count against your overall license.

  • Question about Cisco 7940 ip phones

    I always have the same problem with Cisco 7940 ip phones.
    I only have direct access to one speed dial with the button near of the screen and I think that it isn't good because to get access to the rest speed dials I must to use short dials and I must to have it written in a paper to remember the number where I have each speed dial.
    Is there any way to solve this problem?.
    I use CCM 4.1.
    Thanks, Carlos.

    7914 should supports with 7940, 7960 and 7970. But in CCM4.1, I couldnt add phone button under 7940. I guess 7940 no longer suppot 7914.
    After CCM 4.0, you have to create phone button template. For example, if you have one 7914 which has 14 buttons, then you have to create phone button template with additional buttons.
    Under phone device, you can pick the new phone button template, and then select "Expansion Module Information" 7914 module.
    Thanks
    Please rate helpful post.
    Ken

Maybe you are looking for

  • 500   Internal Server Error while deploying InteractiveForm in Webdynpro

    I tried to deploy the Sample template from SDN when i tried to Deploy it on Server i am getting the ERROR <b>500   Internal Server Error</b> WebServices of the Server are installed properly and the settings are done. i will be thankful for Quick Resp

  • Automatic PO

    I created an assigned PR and tried to convert it into PO automatically using ME59N. But i got the following error: Message class: MEPO Doc header : PO still contains faulty items. Pl guide regards VS

  • SQL Server 2005 installation after VS 2005 installation

    I saw in another thread that someone had trouble installing SQL Server 2005 after installing Visual Studio 2005.  The answer alluded to the fact that the default/standard installation of VS 2005 results in the installation of SQL Server Express at th

  • Queue monitoring, best practice

    Hi,           I have had a go at reading the Programming guides supplied on the website, however I still am unsure as to the best approach...           Situation:           Server1, Weblogic Server 8.1 with a JMS Queue.           Server2, Tomcat 6.0.

  • Help needed with Lion software update

    I've upgraded from Snow Lepord to Lion. Downloaded Lion from app store which takes several hrs here in Aus. Installed Java then did software update, it gets stuck when almost installed at 'moving items into place' stage. Tried full combo also to no a