Cisco IOS Software Feature Licenses – Part 1

There are four Cisco IOS Software feature licenses for the Cisco Catalyst 2K and 3K switches.

  1. LAN Lite: Enterprise Entry Level Layer 2 Switching
  2. LAN Base: Enterprise Access Layer 2 Switching
  3. IP Base: Enterprise Access Layer 3 Switching
  4. IP Services: Advanced Layer 3 Switching

For the sake of simplicity, we will focus on the most popular Cisco Catalyst switches series: Cisco Catalyst 2960, Catalyst 2960-S, Catalyst 3560-X and Catalyst 3750-X.

LAN Lite License for Cisco Catalyst 2960 and 2960-S Series Switches

The LAN Lite and LAN Base are two common licenses for the 2960 and 2960-S switches. As the name implies, LAN Lite is an entry level license for enterprise layer 2 access switches with a plethora of useful features like 802.1Q trunking, (M)STP, STP extensions, CDP, DTP, UDLD, VTPv2, PAGP/LACP, and LLDP. It also supports critical safety features such as TACACS+, RADIUS, port security, 802.1X and DHCP snooping. A LAN lite license does not give layer 3 routing capabilities. Nor does it contain advanced security and management aptitudes like Dynamic ARP Inspection and cutting-edge QoS outside some rudimentary functions like priority queuing.

LAN Base License for Cisco Catalyst 2960, 2960-S, 3560-X, and 3750-X Series Switches

LAN Base is a potent license for layer 2 access switches. Its wide array of access features encompasses all LAN Lite capabilities and also gives more vigorous features such as VTPv3 and FlexLinks. VTP version 3 gives improved administrative regulation over VLAN topology information sharing to minimize inadvertent or troublesome changes. It also gives more VLAN environment support like expanded ISL VLAN support range. FlexLinks enhances Layer 2 resiliency by adding a pair of fast converging active and backup links between access and distribution switches. LAN Base allows layer 3 routing by adding static routing support. Many robust security capabilities are added in LAN Base, too. Examples include Flexible Authentication, Radius Change of Authorization and advanced 802.1X features. On the management side, a large number of capabilities become accessible via LAN Base like a broader array of MIBs, Ingress policing, Trust Boundary, AutoQoS, and DSCP mapping.

If you possess a basic layer 2 access network with fundamentally no routing requirements and no advanced security or management needs, you may wish to consider LAN Lite. For a majority of enterprise layer 2 networks, LAN Base is a minimum need. It provides you a secure layer 2 access network with outstanding network manageability, security and user experience.

To find out more, please speak with our Cisco Licensing Specialists here.

Cisco IOS Software Feature Licenses – Part 2

The IP Base License for the Cisco Catalyst 3560-X and 3750-X Series Switches

Dynamic routing gives you network scalability, flexibility and resilience. IP Base is a standard enterprise services license intended for the 3560-X and 3750-X switches having dynamic routing support. It comprises all layer 2 functions included in the LAN Base license, along with a remarkable list of layer 3 abilities like static routing, RIP, EIGRP stub, Protocol Independent Multicast (PIM) stub and OSPF for Routed Access. Here EIGRP implies that the switch partakes in EIGRP routing as a counterfoil and the EIGRP paths will not be drawn-out to any downstream hardware connected with the switch. Also, please note that OSPF for Routed Access is developed precisely to encompass Layer 3 routing aptitudes to the wiring closet. It supports only one OSPFv2 and one OSPFv3 occurrence, with a maximum number of 200 dynamically learned paths. On the security facade, a large amount of network security features are incliuded in IP Base. Some examples are ACLs, Private VLANs, TrustSec SXP, and IEEE 802.1AE (also known as MACsec). A novel and stimulating security advantage is device sensor. It is part of the IOS software running on the Cisco switch and gathers definite endpoint device characteristics and directs such information to the Cisco Identify Services Engine (ISE) via RADIUS accounting packets. Cisco ISE then relates the suitable rules as a component of the Bring Your Own Device (BYOD) solution. In addition, innovative management competences have been added to the Cisco IP Base image. A worthy example is Embedded Event Manager (EEM). This is a policy-based structure which permits you to adapt a script for real-time network event discovery and onboard computerization. Also, Cisco Medianet support empowers you with the capability to troubleshoot and tailor business apps like video-based collaborations.

The IP Services License for Cisco Catalyst 3560-X and 3750-X Series Switches

Cisco IP Services is a complete enterprise services license. It supports all the functionality given by IP Base. It then further includes competencies to allow a high-quality user experience which one comes to expect from the next-generation modern day workplace. At the top of the list are complete abilities of EIGRP and OSPF routing protocols with no limits on network topology or routing table size. In addition, the BGP routing protocol is supported which we have seen was not a part of IP Base. Another significant area is IPv6 support. IP Services gives OSPFv3 and EIGRP for IPv6 which are not a feature of IP Base. As many clients are running out of IPv4 addresses, IPv6 support is quickly becoming a great concern and an integral requirement for the networks. Yet another critical area is full scale support for PIM for IP multicast routing, including PIM sparse mode (PIM-SM), PIM dense mode (PIM-DM), PIM sparse-dense mode and Source Specific Multicast (SSM). The full PIM routing support vastly enhances network efficacy as multimedia, interactive video and business collaborations produce explosive traffic growth. Here is another critical improvement whch IP Services enables: VRF-lite support is not in a feature of IP Base but it is included in IP Services. As you may recollect, VRF-lite is a great method to divide a physical network into numerous logical networks for the purpose of network virtualization. Additional IP Services competences are Web Cache Coordination Protocol (WCCP) and policy-based routing (PRB) support.

Now let’s see some data on the assorted license SKUs, so we can easily distinguish between them.

For the Cisco Catalyst 2960 and 2960S series switches, the SKU group ending with

-S signifies LAN Lite

-L signifies LAN Base

For the Cisco Catalyst 3560-X and 3750-X series switches, the SKU group ending with

-L signifies LAN base

-S signifies IP Base

-E signifies IP Services

To find out more, please speak with our Cisco Licensing Specialists here.

Licensing Options for the Cisco 800 Series

The Cisco 890, 860, and 880 Series Routers support universal images with numerous feature groups such as the Cisco IOS Software Advanced Security and Advanced IP Services feature groups. A universal image comprises all the features supported by any given platform. The Cisco Software Activation feature on these platforms allows and permits the use of a Cisco software feature or feature sets. A special file contained in the router device, known as a license file, is inspected by Cisco software when the router is turned on. According to the license file installed, Cisco software empowers the requisite feature set(s). You can modify or upgrade license files to support a different feature set.

Cisco IOS Content Filtering License

The Cisco 890 and 880 Series Integrated Service Routers also provision the new Cisco IOS Software Content Filtering. Cisco IOS Content Filtering is a web security methodology which can assist your company in protecting against known and latest Internet security threats, increase employee output, and impose business policies for governing compliance.

Installed on Cisco integrated services routers, Cisco IOS Content Filtering gives category-based production and security assessments. Content-aware security assessments defend against malware, malicious code, phishing attacks, and spyware. URL and keyword blocking assist in ensuring that staff are industrious when accessing the Internet. This subscription-based hosted solution uses Trend Micro’s global TrendLabs threat database to the best possible benefit, and is meticulously integrated with Cisco IOS Software. You must buy the annual subscription prior to being able to use this feature.

Cisco IOS SSL VPN License

The Cisco IOS SSL VPN is the first router-based solution giving Secure Sockets Layer (SSL) VPN remote-access connectivity included with industry-leading security and routing features on a congregated data, voice, and wireless platform. SSL VPN gives mobile workers a malleable, protected VPN substitute whereas the security is crystal clear to you and easy for IT to manage.

With Cisco IOS SSL VPN, you obtain right of entry securely from your home or any Internet-enabled site including wireless hotspots. Cisco IOS SSL VPN also can permit your organization to encompass corporate network access to offshore associates and advisors while keeping corporate data safe.

All Cisco IOS SSL VPN features are embedded in a singular, cost-effective license which is bought separately. There is no software key to empower the feature. You can buy the 25- or 10-user SSL VPN Feature License for the Cisco 890 and 880 Series straight from the Cisco.com configuration solution.

Cisco IOS IPS

Cisco IOS Intrusion Prevention System (IPS) is an aligned, deep-packet scrutiny-based solution which allows Cisco IOS Software to efficiently alleviate a wide array of network attacks. While it is a usual practice to protect against attacks by examining traffic at data centers and corporate headquarters, dispensing the network level protection to halt malicious traffic nearby to its entry point at division or telecommuter offices is also of critical importance.

As an essential component of the Cisco Self-Defending Network, Cisco Services for IPS defends and improves the efficiency of the Cisco Intrusion Prevention System. It gives repeated threat defense updates and Cisco SMARTnet support in one complete service subscription. Reinforced by the Cisco Global Security Intelligence organization, Cisco Services for IPS gives constantly updated, complete, and precise detection technology to detect and stop quick-moving and developing threats before they are able to hurt your computing assets.

To find out more, please speak with our Cisco Licensing Specialists here.

Differences between the Cisco SEC-K9 and HSEC-K9 Licenses

The HSEC-K9 license eliminates the restriction enforced by the U.S. government’s export limitations on the encrypted tunnel count and encrypted throughput. HSEC-K9 is obtainable for the Cisco 2921, Cisco 2951, Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. Utilizing the HSEC-K9 license, the ISRG2 router can exceed the limitation limit of 225 tunnels for IP Security (IPsec) and encrypted throughput of 85-Mbps unidirectional traffic in and out of the ISR G2 router, with a bidirectional total of 170 Mbps. The Cisco 1941, 2901, and 2911 already have the maximum encryption volumes within the export restrictions.

The HSEC license and restriction was announced in the Cisco IOS Software Release 15.0(1)M1 and will be imposed on all images subsequent to that release.

Intended to conform with local and U.S. export requirements for worldwide dissemination to all nations, the SEC-K9 license allows standard encryption (VPN payload and secure voice) on the ISR G2 platforms. This license imposes a limitation on the maximum quantity of encrypted tunnels and the maximum encrypted throughput on the ISR G2 platforms. The SEC-K9 license restricts the quantity of concurrent encrypted sessions and maximum encrypted throughput per device. This boundary helps ensure that the ISR G2 conforms with U. S. government export limitations regardless of the end user destination nation.

If you buy a Cisco ISR G2 chassis and subsequently elect to activate the security features, you will have to purchase a SEC-K9 license. The administrator will need to download the license to the router and follow the license installation commands that accompany the license to be able to benefit from the security features on that router.

The SEC-K9 permanent licenses can be applied to the Cisco 1900, 2900, and 3900 ISR G2 platforms; these licenses restrict all encrypted tunnel counts to 225 tunnels maximum for IP Security (IPsec), Secure Sockets Layer VPN (SSL VPN), a secure time-division multiplexing (TDM) gateway, and secure Cisco Unified Border Element (CUBE) and 1000 tunnels for Transport Layer Security (TLS) sessions.

The SEC-K9 license confines encrypted throughput to <= 85-Mbps unidirectional traffic in and out of the ISR G2 router, with a bidirectional total of 170 Mbps. This condition applies for the Cisco 1900, 2900, and 3900 ISR G2 platforms.

All risk protection and VPN structures that are supported on the Cisco ISR G2 routers are functionally accessible for configuration with the SEC-K9. The image that contains this license is the universal-k9 image. As an example, the Cisco IOS release version is c3900-universalk9-mz.SPA.150-1.M1.

To find out more please contact one of our Cisco Licensing Specialists here.