Cisco Identity Services Engine: Ordering Guide
Cisco Identity Services Engine: Ordering Guide
Cisco Identity Services Engine: Ordering Guide
February 2019
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 16
Contents
1. Introduction .......................................................................................................................................................... 3
2. Cisco Identity Services Engine ........................................................................................................................... 3
3. Cisco ISE appliances ........................................................................................................................................... 3
3.1 Appliance ordering information ....................................................................................................................... 3
4. Cisco ISE licenses ............................................................................................................................................... 4
4.1 License consumption ...................................................................................................................................... 5
4.2 License enforcement ....................................................................................................................................... 7
5. Ordering information ........................................................................................................................................... 7
5.1 Cisco ISE Device Administration license ......................................................................................................... 8
5.2 Cisco ISE Base licenses ................................................................................................................................. 8
5.3 Cisco ISE Plus licenses .................................................................................................................................. 9
5.4 Cisco ISE Apex licenses ............................................................................................................................... 10
5.5 Cisco ISE IPsec license ................................................................................................................................ 11
6. Frequently Asked Questions ............................................................................................................................ 11
7. Service offerings ................................................................................................................................................ 16
8. License management ........................................................................................................................................ 16
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 2 of 16
1. Introduction
®
Purpose: This document describes the packaging structure and ordering information for the Cisco Identity
Services Engine (ISE).
Audience: This guide is for Cisco sales, partners, distributors, and customers.
Cisco ISE virtual appliances are supported VMware ESXi 5.x and 6.x, KVM on Red Hat 7.x, and Microsoft Hyper-V
on Microsoft Windows Server 2012R2 and later. Virtual appliances should be run on hardware that equals or
exceeds the configurations of the physical platforms listed in the Cisco ISE data sheet. Cisco ISE Policy Service
Node (PSN) persona requires the virtual target to have at least 16 GB of memory and at least 200 GB of hard drive
space available.
For both physical and virtual appliances, make sure to select the appropriate support contract desired for each
®
appliance: Cisco Smart Net Total Care service for physical appliances and Software Support Service (SWSS) for
virtual appliances. Please note that ISE appliances always ship with the latest version of software but the software
version can be changed manually. This would be in the form of a fresh installation. Please refer to the release
notes and administrator guide of the ISE release you plan to install.
SNS-3515-K9 Small Secure Network Server for ISE Applications Customer must choose software option
SNS-3595-K9 Large Secure Server for ISE Applications Customer must choose software option
SNS-3615-K9 Small Secure Network Server for ISE Applications Customer must choose software option
SNS-3655-K9 Medium Secure Network Server for ISE Applications Customer must choose software option
SNS-3695-K9 Large Secure Network Server for ISE Applications Customer must choose software option
R-ISE-VMS-K9= Cisco ISE Virtual Machine Small At least 12 CPU and 16 GB RAM
R-ISE-VMM-K9= Cisco ISE Virtual Machine Medium At least 16 CPU and 64 GB RAM
R-ISE-VML-K9= Cisco ISE Virtual Machine Large At least 16 CPU and 256 GB RAM
A deployment can use a higher level license and still be compliant. For example, you may choose to configure your
ISE node as a small VM and have installed a medium VM license.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 3 of 16
Table 2 lists the Secure Network Server component spares that can be used as Field-Replaceable Units (FRUs).
3515/3595 UCS-HD600G10K12G 600-GB 12-Gb SAS 10K RPM SFF hard disk; hot pluggable; drive sled
mounted
3615/3655/3695 UCS-HD600G10K12N 600-GB 12-Gb SAS 10K RPM SFF hard disk; hot pluggable; drive sled
mounted
3515/3595/3615/3655/3695 UCSC-PSU1-770W= 770W power supply
Evaluation Limited use of Cisco ISE product for Temporary (90 days) Full Cisco ISE functionality (Device
presales customer trials/evaluations Admin, Base, Plus and Apex) is
provided for 100 sessions. See license
details below. Included in the Cisco ISE
software
Device Administration Enables Device Administration/TACACS+ Perpetual Needs a minimum of 100 Base licenses
support for networking devices
Plus Provides context about sessions for more Subscription (1, 3, or 5 years) Does not include Base services; Base
detailed access policies licenses are required to install Plus
licenses
Apex Provides compliance details about Subscription (1, 3, or 5 years) Does not include Base or Plus services;
sessions for more detailed access policies Base licenses are required to install
Apex licenses. Please note that Cisco
AnyConnect® Apex user licenses are
required in addition to Cisco ISE Apex
licenses when making use of Cisco
AnyConnect posture services across
wired, wireless, and VPN
All licenses are available as traditional PAK-based licenses and can be converted to Smart licenses.
Understanding Cisco ISE service and license relationships is important for license ordering and deployment.
Table 4 provides a cross-reference for Cisco ISE features and services and the licenses where these features and
services are found.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 4 of 16
Cisco ISE Feature or Service License
Profiling No No Yes No
Device registration (My Devices portal) and provisioning for Bring Your Own No No Yes No
Device (BYOD) with built-in Certificate Authority (CA)
Rapid Threat Containment (RTC) (using Adaptive Network Control and No No Yes No
pxGrid)
Enterprise Mobility Management and Mobile Device Management (EMM and No No No Yes
MDM) integration
Cisco AnyConnect Unified Agent (requires Cisco AnyConnect Apex license; No No No Yes
see “Ordering information” section)
®
For deployments looking to use Cisco AnyConnect technology for posture across wired, wireless, and VPN, Cisco
AnyConnect Apex licenses should be ordered in addition to Cisco ISE Base, Plus, and Apex licenses. See the
“Ordering information” section for more details.
Cisco ISE Service Cisco ISE When the License Is Consumed When the License Is Released
License
Authentication Base A Base license is consumed when an endpoint establishes an active The session ends
(RADIUS/AAA) network session
Authentication Mobility A Mobility license is consumed when a wireless or VPN endpoint The session ends
(RADIUS/AAA) establishes an active network session
Authentication Mobility A Mobility Upgrade license is consumed when a wired endpoint The session ends
(RADIUS/AAA) Upgrade establishes an active network session
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 5 of 16
Cisco ISE Service Cisco ISE When the License Is Consumed When the License Is Released
License
Profiling Plus A Plus license is consumed when an endpoint with an active session The session ends
uses profiling classification in an authorization policy
BYOD client Plus A Plus license is consumed when an endpoint with an active session The session ends
provisioning and uses its registration status in an authorization policy
enablement
MDM (partner) checks Apex An Apex license is consumed when an endpoint uses an MDM The session ends
attribute in an authorization policy
Threat Centric NAC Apex An Apex license is consumed when an endpoint uses or triggers The session ends
threat based information or action as part of the authorization policy
Posture Apex An Apex license is consumed when an endpoint with an active The session ends or the endpoint
session receives an authorization based on a posture status other reauthenticates to a session that
than “Not applicable” (for example, Compliant, Not compliant, does not require posture
Pending, or Unknown)
Table 6 shows the subset of Cisco ISE features that do not result in license consumption recorded in the ISE user
interface.
Cisco AnyConnect Use of Cisco AnyConnect for posture Service is enabled with a valid Cisco ISE Apex license and Cisco
Unified Agent services across wired, wireless, and VPN AnyConnect Apex licenses. Please note that Cisco AnyConnect Apex
licenses are needed for every unique user that will make use of Cisco
AnyConnect services (posture, VPN, etc.). This includes standalone nodes
(e.g. sensors) or multiuser shared computing platforms
PassiveID Gathering, collating, and caching Cisco Only Subscribers: Service is enabled with a valid Base license
authentication data (username, IP address Non Cisco Subscribers: Service is enabled with a valid Plus license.
and MAC) from other servers in the data Requires a 1:1 Plus to Base license sessions
center and distributing the authentication
data to subscribing systems through
pxGrid
Device Support for IT enterprise administrators Service is enabled with a valid Device Administration license
Administration accessing switches, wireless controller,
(TACACS+) routers, etc., to comply with device
administration policies defined in ISE
before any configuration changes can
occur
The My Devices portal is enabled when a Plus license is installed and by itself does NOT consume any licenses.
When a device registered through My Devices Portal connects to the network, a Plus license is consumed.
Advanced Cisco TrustSec and ACI integration, multiple matrixes, and Rapid Threat Containment require 1:1 Plus-
to-Base license sessions.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 6 of 16
Table 7. Context exchange licensing requirements
For term licenses, alerts will be provided 30 days prior to expiry on a daily basis to the administrator. When the
term licenses expire, they are considered to be out of compliance. ISE will provide a grace period of 45
consecutive days, after which enforcement will begin.
When 25 percent more sessions are authorized than are entitled by the license, the license is considered out of
compliance (the 25 percent overage is provided to account for a temporary burst). If the license is out of
compliance for 45 consecutive days, enforcement will kick in.
Alerts will be provided every day that a license is out of compliance. When enforcement kicks in, there will be no
impact to end users. However, visibility and management of the features associated with an out-of-compliance
license will be affected.
Enforcement will be for Plus and Apex licenses. These enforcement actions and impacts on licenses may change
in the future.
Note: The term of a Cisco ISE subscription license (Plus, Apex, Mobility, Mobility Upgrade) begins when the
PAK is dispatched; this generally occurs 24 hours after the sales order is processed.
5. Ordering information
All Cisco ISE licenses are orderable in the Cisco Commerce Workspace (CCW) and are listed on the Global Price
List (GPL).
Cisco ISE endpoint session-based licenses can be ordered in any quantity starting with 100 sessions.
Subscription licenses can be ordered with 1-, 3-, or 5-year terms. Please note that support contracts on all the
Cisco ISE appliances (physical or virtual) in a deployment are a prerequisite to purchasing and using ISE
term-based licenses.
By default, subscription licenses begin immediately and are for 3 years. The subscription licenses can also be
ordered with specific start and end dates. The start date can be up to 60 days out from the current date. The term
can be between 12 and 60 months, allowing the licenses to be co-termed.
To order a Cisco ISE Device Administration perpetual license, select the ISE Device Administration license as
separate optional add-on license. Please note that one ISE Device Administration license is needed per ISE node.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 7 of 16
When selecting Cisco ISE Apex licenses with the intent of using AnyConnect for posture, please add Cisco
AnyConnect Apex licenses. The Cisco AnyConnect Apex licenses have to be ordered as a separate line item with
a count equal to the total number of possible users that will make use of Cisco AnyConnect services within the
Cisco ISE deployment. Please note that Cisco AnyConnect Plus and Apex licenses will work with Cisco ISE Base,
Plus, or Apex for basic VPN authentication. If endpoint contextual data collection with Cisco ISE is required in
addition to basic VPN authentication, then Cisco AnyConnect Plus and Cisco ISE Plus licenses have to be
ordered. If endpoint posture and consistent access policy enforcement across wired and wireless is needed in
addition to basic VPN authentication, then Cisco AnyConnect Apex and Cisco ISE Apex have to be ordered.
The number of Cisco AnyConnect licenses needed is based on all the possible unique users that would use any
Cisco AnyConnect service. The exact number of Cisco AnyConnect Plus or Apex licenses should be based on the
total number of unique users that require the specific services associated with each license type. Please see the
Cisco AnyConnect Ordering Guide for additional information regarding AnyConnect licenses. Similar to Cisco ISE
subscription licenses, a SWSS service contract is included with Cisco AnyConnect Apex licenses for the duration
of the subscription term.
To order Cisco AnyConnect Plus or Apex licenses from a Cisco partner, please refer to their Cisco AnyConnect
specific SKU structures for Plus license (AC-PLS…) and Apex license (AC-APX…).
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 8 of 16
Part Number (SKU) Description
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 9 of 16
Term Subscription Description
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 10 of 16
Table 15. Cisco ISE Apex 1-year subscription licenses
Q. We purchased VM previously and it had no PAK or license key associated. We are planning to upgrade to 2.4
now. What do I need?
A. Upon upgrade to 2.4, you would be prompted to install VM licenses keys. But if you purchased ISE VM
previously with no PAK or license key associated, please reach out to ise-vm-license@cisco.com with the
Sales Order (SO) number reflecting the VM purchases.
Note: 2.4 only provides license warning for the VM licenses. The ISE deployment continues to operate without
disruption.
Q. We purchased Device Admin previously. Do I need to buy more licenses if I upgrade to 2.4?
A. If you purchased Device Admin as a deployment-wide license, you can continue to utilize all nodes in the
deployment for TACACS+ transactions. This means the license entitles your deployment to the maximum
number of nodes supported by ISE for the deployment.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 11 of 16
Q. What license do I need with pxGrid?
A. There is no single license associated with pxGrid. Cisco licenses features that may or may not leverage pxGrid
to communicate between systems. A session using these features will consume a license, though context
sharing itself will not. See the section titled “Cisco ISE licenses” for details about the various features that
might make use of pxGrid and the appropriate license for each.
Q. Can I mix separate Base, Plus, and Apex licenses with Mobility licenses in a Cisco ISE deployment?
A. No. A Cisco ISE deployment cannot mix Base, Plus, and Apex licenses with the Mobility or Wireless licenses
in the same deployment.
Q. Can an ISE deployment operate with just the ISE Device Administration license?
A. No, an ISE deployment requires at least 100 ISE Base session licenses in order to operate. The ISE Device
Administration should be added to the deployment after the ISE Base licenses.
Q. Does an endpoint with a session authorized by MAC Authentication Bypass (MAB) consume a license?
A. Yes. A Base license will be consumed by an endpoint that receives MAB to access the network.
Q. What happens to an existing customer with Plus, Advanced, or Wireless licenses when they upgrade to Cisco
ISE 2.0 or later releases?
A. Cisco ISE 2.0 has no impact on existing licenses in terms of services, count, and term. Existing customers with
Wireless licenses that migrate to 2.0 or later releases will see a Wireless to Mobility name change in the
administrative console, but they will have exactly the same functionality, plus the ability to provide VPN access
control. Existing Plus customers will continue to function as they do in Cisco ISE 1.2. Existing Advanced
customers that migrate to Cisco ISE 2.0 or a later release will see the Advanced name decomposed into Plus
and Apex in the administrative console, but they too will have same functionality.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 12 of 16
Q. What is the status of the advanced license in Cisco ISE 2.0 and later releases?
A. An Advanced license can still be consumed in ISE 2.0 or a later release deployment, but customers should
find that separate Plus and Apex licenses are more cost effective allowing a la carte consumption.
Q. Can the older (non-“S”) Advanced, Wireless, or Wireless Upgrade licenses be co-termed or renewed?
A. No.
Q. Can a deployment include a mix of Plus with Apex licenses on top of Base licenses?
Yes. This configuration would be useful in a number of environments. One example: a deployment of 7500
sessions that requires profiling for 5000 sessions and posture for 2500 sessions. In this case the configuration
would be 7500 Base, 5000 Plus, and 2500 Apex, and AnyConnect Apex based on number of users.
Q. Can a Cisco ISE deployment have just Base and Apex licenses?
A. Yes. ISE Base, Plus, and Apex licenses can be consumed a la carte. Valid license choices are Base only;
Base and Plus; Base and Apex; Base, Plus and Apex; or Base, Plus, Apex and Cisco AnyConnect Apex.
Q. Is there an equivalent of the Base license for Mobility use cases (wireless and VPN)?
A. No. The Base license supports wired, wireless, and VPN sessions with the features described above in this
ordering guide. The Mobility license enables all the features offered by the Base, Plus, and Apex described
above in this ordering guide, but for wireless and VPN sessions only.
Q. Can the Plus or Apex or the sum of Plus and Apex licenses count be greater than the total Base count?
A. No.
Q. Is a Cisco AnyConnect Plus license required with a Cisco ISE Plus license?
A. No. However, using a Cisco AnyConnect Plus license with Cisco ISE Plus enables the collecting and sharing
of endpoint context for VPN uses cases. Please note that the Cisco AnyConnect Plus license will work with the
Cisco ISE Base license, but the detailed endpoint information will not be collected. For additional information
on AnyConnect Plus, please refer to the Cisco AnyConnect Ordering Guide.
Q. What are the different services enabled by Cisco ISE Apex as opposed to Cisco ISE Apex with Cisco
AnyConnect Apex?
A. Cisco ISE Apex is the license tier to enable compliance context collection and the use of that information as
authorization attributes within ISE policies. For example, using a third-party MDM/EMM platform to detect and
control access based on “PIN lock status” and “jailbreak status” requires a Cisco ISE Apex license. The Cisco
ISE Apex license count required in this use case is the maximum number of potential concurrent MDM/EMM
enrolled mobile sessions active on the network and controlled by Cisco ISE, and not every MDM/EMM
enrolled endpoint. Cisco ISE Apex with AnyConnect Apex enables AnyConnect as the unified agent for PC
compliance along with all the additional value-add Cisco AnyConnect services such as “always on,” trusted
network detection, etc.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 13 of 16
As in the previous example, the Cisco ISE Apex license count would be for the maximum number of
concurrent sessions where Cisco AnyConnect acts as the unified agent in the Cisco ISE deployment for
posture, etc., and not, necessarily, every endpoint that will be running AnyConnect. The number of Cisco
AnyConnect Apex licenses needed is based on all the possible unique users that may use Cisco AnyConnect
Apex services and not each and every device running Cisco AnyConnect. Please note that AnyConnect Plus
and Apex fall under a separate user-based license structure, which is different from the Cisco ISE endpoint
session-based license structure. For additional Cisco AnyConnect information, please review the Cisco
AnyConnect content on Cisco.com.
Q. Are there specific renewal license SKUs to order when renewing a license, and is there a built-in
renewal discount?
A. No, there is no specific Cisco ISE license SKU for renewals. Customers must reorder or renew the general
licenses. There is no built-in renewal discount, but a nonstandard discount might be arranged through your
Cisco Certified Partner or Cisco sales team.
After that gaming system is turned off, the Cisco ISE license count is returned and made available for
another device. Note that having a Plus license is required to enable the My Devices portal and native
supplicant provisioning.
Q. If I have both Plus and Apex licenses, and I am using endpoint profiling within an authorization rule as well as
posture information, which license type gets used?
A. Both a Plus and an Apex license session will be consumed in this use case.
Q. If I deploy Cisco ISE with primary and secondary Administration nodes, can I have the licenses registered to
both nodes?
A. Yes. The Cisco PAK registration page allows a PAK and the associated license file to be registered to the
Unique Device Identifiers (UDIs) of the primary and secondary Administration nodes. The registration of the
PAK to the primary Administration node is mandatory; the registration of the secondary Administration node
is optional.
Q. If I upload a license file only to the primary Administration node, will it propagate license information to the
other Cisco ISE nodes on the network?
A. All nodes in a Cisco ISE deployment use the license applied to the primary Administration node. If the primary
node fails, the secondary Administration node is promoted and uses the licenses acquired from the primary
Administration node.
Q. What is a UDI?
A. A UDI is the unique device identifier of each Cisco ISE appliance. The UDI comprises three values: the
Product ID (PID), the Version ID (VID), and the serial number.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 14 of 16
Q. I need to change or upgrade my Administration node. Do I need to buy new licenses?
A. No. Valid ISE licenses can be rehosted to the UDI of a new node (see
https://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html for more information).
Q. I want to extend support on my ISE virtual appliances but I bought the non “R-” SKUs. Do I need to buy new
appliances?
A. No. Please apply for a PAK according to the ISE release notes. Once a PAK is received, the installed base
record is updated so you can continue with ISE under service as a medium VM.
Q. If I installed 5-year Mobility licenses and have 3 years remaining in the term before they expire, and I want to
install Mobility Upgrade licenses, what license term should I select?
A. The Mobility Upgrade license is no longer available. Customers who purchased wireless or mobility licenses
will need to maintain their current configurations until expiration.
Q. When does the term begin for a Cisco Identity Services Engine license?
A. Consistent with Cisco policy, the Identity Services Engine license term starts 24 hours after dispatch. All
Identity Services Engine licenses are electronically delivered and are typically dispatched within 48 hours after
order processing.
Q. When is the earliest that a license renewal can be quoted and placed?
A. In accordance with Cisco policy, Cisco ISE license renewals can be quoted 6 months in advance of the license
expiring and placed 60 days prior to the license expiring.
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 15 of 16
Q. Whom should I contact for additional information?
A. Please contact your local Cisco sales representative or Cisco Certified Partner.
Q. What is the difference between the Cisco Temporal Agent and NAC Web Agent?
A. The Cisco Temporal Agent is replacement solution for the NAC Web Agent. Like the NAC Web Agent, the
Cisco Temporal Agent is designed to address posture use cases where a persistent agent is unworkable
(e.g., guest). But unlike the NAC Web Agent, the Cisco Temporal Agent supports both Windows and macOS
and does not rely on the endpoint’s browser for embedded launch.
Q. Which license do I need to purchase to make use of the Cisco Temporal Agent?
A. You will need to purchase one Cisco ISE Apex license in addition to one Cisco Base license for each active
session making use of the Cisco Temporal Agent.
7. Service offerings
SWSS support is included for the duration of the all Cisco ISE subscription licenses.
Please note that Smart Net Total Care or SWSS support contracts for Cisco ISE physical and virtual appliances
must be purchased separately and are required to consume any ISE subscription licenses. Smart Net Total Care
and SWSS support contracts for Cisco ISE physical and virtual appliances cover Base and Device Administration
deployments as well. Please also note that Cisco does not offer stand-alone ISE software upgrade services SKUs
or separate support SKUs for subscription licenses.
8. License management
Cisco offers a variety of license management tools at the License Registration Portal. A valid Cisco.com user name
and a password are required to access the portal. Key features of the Cisco License Registration portal include:
● Simplified asset management: identifies PAKs registered to a customer and the devices with
installed licenses
● Automated software activation: quickly processes PAK registration and license file distribution
● License transfers: rehosts existing licenses to new Cisco ISE Administration nodes
● Replacement of devices: uses the “return materials authorization” to request replacement PAKs
and licenses
© 2019 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 16 of 16