01-08-2020 03:48 PM
After 2.4, We need Device Admin for each PSN, which does TACACS and authentication, however, in the based license, AAA is included.
Just wondering what would be difference then?
Thanks,
Hamed
Solved! Go to Solution.
01-08-2020 04:06 PM
Base licenses are consumed for endpoints using RADIUS for network connectivity or for network devices using RADIUS for device administration (if they do not support TACACS+).
The Device Admin license specifically enables support for TACACS+
From the ISE Ordering Guide:
"License Consumption: Device Administration licenses are consumed per policy service node. Each policy service node that is setup to support Device Administration must have a Device Administration license.
Device Administration using TACACS+ does not consume endpoint sessions but an ISE installation must have a minimum of 100 Base licenses. There is no limit on network devices for Device Administration."
Cheers,
Greg
01-08-2020 04:06 PM
Base licenses are consumed for endpoints using RADIUS for network connectivity or for network devices using RADIUS for device administration (if they do not support TACACS+).
The Device Admin license specifically enables support for TACACS+
From the ISE Ordering Guide:
"License Consumption: Device Administration licenses are consumed per policy service node. Each policy service node that is setup to support Device Administration must have a Device Administration license.
Device Administration using TACACS+ does not consume endpoint sessions but an ISE installation must have a minimum of 100 Base licenses. There is no limit on network devices for Device Administration."
Cheers,
Greg
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide