Cisco AnyConnect Licensing FAQs – Part 4

Q. Is a Cisco AnyConnect Plus license needed while using an ISE Plus license?

A. No. Nonetheless, utilizing a Cisco AnyConnect Plus license with Cisco ISE Plus allows the gathering and sharing of endpoint circumstance for VPN use cases. The AnyConnect Plus license does work with the Cisco ISE Base license; however, the comprehensive endpoint data will not be able to be collected.

Q. Which different services are enabled by Cisco ISE Apex versus Cisco ISE Apex with Cisco AnyConnect Apex?

A. Cisco ISE Apex is the license level to allow compliance context gathering and the employment of that data as permission characteristics within Cisco ISE policies. For example, utilizing a 3rd-party MDM/EMM platform to find and manage access founded on “PIN lock status” and “jailbreak status” needs a Cisco ISE Apex license. The Cisco ISE Apex license count needed in this scenario is the maximum amount of possible simultaneous MDM/EMM registered mobile endpoints active on the network and managed by Cisco ISE, and not each MDM/EMM registered endpoint. Cisco ISE Apex with AnyConnect Apex allows AnyConnect as the integrated agent for PC compliance together with all the extra value-added AnyConnect features such as “always on,” dependable network detection, etc. Like in the preceding example, the Cisco ISE Apex license count would be for the maximum quantity of simultaneous sessions where Cisco AnyConnect plays the role of the incorporated agent in the Cisco ISE installation for posture, etc., and not, essentially, each and every endpoint that will be using AnyConnect. The number of Cisco AnyConnect Apex licenses needed is based on all the possible unique users that may use Cisco AnyConnect Apex services and not each and every device running Cisco AnyConnect. Please note that AnyConnect Plus and Apex go under a distinct user-based license edifice, which is not the same as the Cisco ISE endpoint session-based license structure.

Q. If I am utilizing Cisco AnyConnect for a non-VPN service or a Cisco IOS head-end, which licenses do I have to buy?

A. License needs are identified by the head-end utilized and the services obtainable in that specific head end. Cisco AnyConnect Plus is needed for VPN service to Cisco IOS head-ends although you can also utilize Cisco AnyConnect Apex. To utilize Cisco AnyConnect’s posture features with ISE 1.3 you must order AnyConnect Apex as well as ISE Apex. For any other scenarios having Network Access Manager, Cisco Cloud Web Security (CWS), etc. you must have Cisco AnyConnect Plus however they can also utilize Cisco AnyConnect Apex. IOS head-ends are also necessitated to have a Security License prior to the use of AnyConnect services. Cisco AnyConnect is compatible with Cisco ISR G2, CSR 1000V and ASR 1000 platforms.  Available attributes vary by platform. The physical Product Activation Key (PAK) registration on Cisco’s licensing portal is only applicable to the Cisco ASA.  For ASAv and IOS head-ends alongwith non-VPN scenarios, you must store the PAK in a secure location as proof of purchase. You will still have to complete Contract registering for Software Center access and Cisco TAC support.

Q. Which minimum OS version is needed for the Cisco ISR G2 or CSR 1000v to support Cisco AnyConnect?

A. ISR G2 – IOS 15.0(1)M, CSR1000v – IOS XE 3.12 S.

To learn more, please speak to our licensing specialists today.

Cisco AnyConnect Licensing FAQs – Part 1

Q. Which causes contributed to the change in AnyConnect licensing models?

A. Cisco has taken in to consideration advice from clients over numerous years asking for a streamlined licensing model. Therefore, the latest license model removes all of the add-on licensing complications while maintaining support for the co-existence of license types.  This model enables shared licensing over all alternatives without the requirement to have equipment to impose licenses and removes the need to buy AnyConnect licenses on a per ASA base (thus helping with Hardware migrations).  Furthermore, this model has an inbuilt pandemic support feature. All term licenses comprise support and software privileges, so buying these licenses will at all times give you access to present software releases.

Q. What are the obtainable official user counts for the new Cisco AnyConnect licenses?

A. The Plus and Apex licenses are obtainable through banding-based licenses (L-AC-PLS-LIC= and L-AC-APX-LIC=) which empower you to choose a precise user count (e.g. 873), a precise term length (e.g. 30 months) and initiation date (e.g. term begins on date X, and goes up to 60 days from that date). The monthly cost per user goes down as the user count is increased and/or the term length goes up. This methodology should be employed to order Plus and Apex term licenses as an alternative of the L-AC-PLS-xYR-G/L-AC-APX-xYR-G methodology. The L-AC-PLS-LIC= and L-AC-APX-LIC= ordering methodology will give more flexibility for user counts, license term duration and easier, more streamlined renewals.

Q. How is the 4.x migration being handled for mobile forms of Cisco AnyConnect?

A. The use of Cisco AnyConnect on iOS & Android devices excluding an active Plus, Apex or VPN Only license (term or contract) has expired on April 30, 2016. Cisco AnyConnect users with Essentials/Premium and Mobile (obsolete) licenses can no longer benefit from this software option. Newer platforms like Windows Phone 8.1, Windows 10 Mobile, BlackBerry 10 and Chrome OS have always needed active Plus, Apex or VPN Only licensing.

Q. Are we able to purchase a perpetual AnyConnect license? What are the features of Cisco AnyConnect VPN Only and AnyConnect Plus Perpetual?

A. Cisco AnyConnect Plus is available as a perpetual license with term options of 1, 3 or 5 years.

Cisco also has a perpetual VPN-only license.  This gives the same functionality of previous AnyConnect Premium along with Advanced Endpoint Assessment plus Mobile plus Phone VPN.

The VPN-only Licenses are developed for VPN only settings which have a huge amount of possible end users but extremely rare usage (e.g. a university having 10,000 students but having just 100 active users at any given point in time). Using either the Plus Perpetual or VPN-only licenses, you have to separately buy support services or you are not going to be able to access software or any technical support.   

Cisco AnyConnect VPN Only is licensed based on a single headend device and on concurrent connections (not authorized users). For active/standby pairs, only the main headend is needed to possess a VPN Only license. VPN Only licenses are a substitute to the Cisco AnyConnect Plus and Apex licensing model.  No other AnyConnect function or service (Web Security Module, ISE Posture, Network Visibility, ASA Multi-context VPN, etc) is accessible via the AnyConnect VPN Only licensing. VPN Only licenses do have support for Clientless SSL VPN, third party IPsec IKEv2, Suite B and VPN HostScan with an ASA device. The VPN Only licenses are not able to be moved, rehosted, shared, joined, split, or directly upgraded to another different VPN Only license size. These licenses are not able to co-occur with Plus or Apex licensing or even any retired AnyConnect licenses.

Both the VPN Only and Plus Perpetual licenses need a SWSS contract on each of the head-ends so that they are eligible for SW access, updates, and tech support.

To learn more, please speak to our licensing specialists today.

Differences between the Cisco SEC-K9 and HSEC-K9 Licenses

The HSEC-K9 license eliminates the restriction enforced by the U.S. government’s export limitations on the encrypted tunnel count and encrypted throughput. HSEC-K9 is obtainable for the Cisco 2921, Cisco 2951, Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. Utilizing the HSEC-K9 license, the ISRG2 router can exceed the limitation limit of 225 tunnels for IP Security (IPsec) and encrypted throughput of 85-Mbps unidirectional traffic in and out of the ISR G2 router, with a bidirectional total of 170 Mbps. The Cisco 1941, 2901, and 2911 already have the maximum encryption volumes within the export restrictions.

The HSEC license and restriction was announced in the Cisco IOS Software Release 15.0(1)M1 and will be imposed on all images subsequent to that release.

Intended to conform with local and U.S. export requirements for worldwide dissemination to all nations, the SEC-K9 license allows standard encryption (VPN payload and secure voice) on the ISR G2 platforms. This license imposes a limitation on the maximum quantity of encrypted tunnels and the maximum encrypted throughput on the ISR G2 platforms. The SEC-K9 license restricts the quantity of concurrent encrypted sessions and maximum encrypted throughput per device. This boundary helps ensure that the ISR G2 conforms with U. S. government export limitations regardless of the end user destination nation.

If you buy a Cisco ISR G2 chassis and subsequently elect to activate the security features, you will have to purchase a SEC-K9 license. The administrator will need to download the license to the router and follow the license installation commands that accompany the license to be able to benefit from the security features on that router.

The SEC-K9 permanent licenses can be applied to the Cisco 1900, 2900, and 3900 ISR G2 platforms; these licenses restrict all encrypted tunnel counts to 225 tunnels maximum for IP Security (IPsec), Secure Sockets Layer VPN (SSL VPN), a secure time-division multiplexing (TDM) gateway, and secure Cisco Unified Border Element (CUBE) and 1000 tunnels for Transport Layer Security (TLS) sessions.

The SEC-K9 license confines encrypted throughput to <= 85-Mbps unidirectional traffic in and out of the ISR G2 router, with a bidirectional total of 170 Mbps. This condition applies for the Cisco 1900, 2900, and 3900 ISR G2 platforms.

All risk protection and VPN structures that are supported on the Cisco ISR G2 routers are functionally accessible for configuration with the SEC-K9. The image that contains this license is the universal-k9 image. As an example, the Cisco IOS release version is c3900-universalk9-mz.SPA.150-1.M1.

To find out more please contact one of our Cisco Licensing Specialists here.

Cisco AnyConnect Reduces Threats from Non-Corporate Mobile Applications

Take the example of a sales executive who is required to check a client’s order from his company- authorized tablet in the client’s lobby. Another case could be a contractor with his private smartphone who needs to be able to access project emails from his place of residence.

What is the big issue here? The rush to give access to these off-site devices implies that we have abridged or even thrown away much needed security controls when it comes to remote connectivity for mobile devices. Providing access from any device, any location, anytime, can grant unauthorized access to possible security threats. The mobile endpoint is a threat trajectory with 68% of companies stating that their mobile devices were besieged by malware in the last year.

What if we protect these mobile devices using VPN tools in the same manner as laptops? “Turning On” VPN on any endpoint implies that all traffic and apps (personal and company) are all communicated over the same VPN channel to access company networks. This co-mingling of company and user applications increases the risk of compromised user apps contaminating the company network and enhances the possibility of threats to the network.

So now what? I don’t wish to enable VPN every single time I have to look for a document or use salesforce.com or try to access my company email. This would increase the complications for the user and provide them with a motive to either find a way around the procedure or invalidates the productivity which all businesses wish to encourage with their mobile workforce.

The solution lies with Cisco AnyConnect which offers companies the capability to provide per-application protected access for only permitted company apps in a manner which is seamless to the users. By simply clicking on the registered company app I wish to use, I can automatically initiate a protected connection for JUST that app every time. This implies that I don’t blend access to company assets between sanctioned apps and possibly infected user apps. It even minimizes bandwidth and IT resource usage as user apps will not get tunneled back to the company network and have to go through user networks (mobile or WiFi).

Companies want to enable their mobile users to work remotely, while IT staff wants a simplified method of controlling and securing enterprise access reliably across all connected devices whether these are on or off-site. Cisco AnyConnect continues to develop to deliver unified and elastic protection and access control for all remote and/or mobile endpoints.

To find out more about Cisco AnyConnect features, plans and pricing please reach out to our AnyConnect professionals here.