Cisco VPN :: SSL Feature License On 1941 Not Deployed
Jul 18, 2011
I have recently purchased 2 x 1941 routers with 2 L-SL-19-SEC-K9= and 2 L-FL-SSLVPN10-K9= licenses. I've installed the licenses through Cisco Configuration Pro ver 2.5 and installation did not generate any errors. After saving config and reloading the device, on the License dashboard, the deploy status for the SSL VPN is "Not deployed" and I have no way of deploying it. The state also says "Active, Not in use". I have tried reinstalling the license via command line but get error "license duplicate - already installed" suggesting the installation was OK. The sec license deployed without any issues. Is there any way to manually deploy this SSL_VPN license?
I have installed Cisco Prime Infrastructure 1.2 separately from LMS4.2. LMS4.2 is in production. I just want to run PI1.2 in parallel with LMS4.2 before migrating to PI1.2. Currently I have LifeCycle permanent license. Why don't I have the assurance lfeature set license. it is running in evaluation mode.
I currently purchased, Cisco 1941/K9 with 2 onboard GE, 2 EHWIC slots, 1 ISM slot, 256MB CF default, 512MB DRAM default, IP Base.
Questions
1. With IP Base License, will I be able to run Frame Relay? I really need reference on what works and what doesn't between these different technology package licenses ? Actually frame relay is running on it right now, hope it doesn't suddenly stop after 60 days...
2. As I understand in order to run MPLS, I will need to upgrade to Data License "SL-19-DATA-K9". Since, I already have a Cisco 1941 to upgrade it, I need to order a spare license / paper PAK?
3. Does the IP Base License support site to site IPSEC VPN or do I need to purchase a security license "SL-19-SEC-K9"
4. Can I have both security and data license activated on the same device ?
5. If I do activate security or data license will I be able to use the IP Base features at the same time?
6. If I purchase a new Cisco 1941 with Data or Security License do I need to purchase the IP Base License then upgrade the license?
7. Is the 1941 suited for voice application routing ?
I have installed Cisco Prime Infrastructure 1.2 separately from LMS4.2. LMS4.2 is in production. I just want to run PI1.2 in parallel with LMS4.2 before migrating to PI1.2. Currently I have LifeCycle permanent license. Why don't I have the assurance lfeature set license. it is running in evaluation mode.
i have 2921 router with base license . i want to upgrade to it to security k9 feature or want to enable it. i have license file with product activation key. how should i do it. if any body have screen shot file
Lately we have been comsidering an upgrade in our organization involving a 1921 router. The main role it will play is a load balancer/failover between 2 connections from 2 different ISPs. what additions are required to be added to this piece of equipment to make the configuration work. Im researching the matter now and it seems an extra card whould be purchased in addition to the router. Also, i cant seem to find much information on the available licenses to go with the router. will i need a special license to utilize the balancer/failover feature? (ip base, data, SEC).
I have an ASR1001 installed and I want to implement the firewall feature set.The current license level is IPbase and I have the firewall feature installed. The firewall feature shows acive, Not in use. I have tried to activate it without success. My question is: do I need to get a license for advipservices or adventerprise to activate the firewall feature set?
The model WS-C3750X-24T-L is only Lan Base. We need this switch to use EIGRP Protocol. Does it exist a License for supportting IP Base o IP Services Feature Set?
I have a cisco router 1941 and i have uploaded before evaluation license , now i have already bought cisco security license .I have already installed on cisco router , but the problem the router is still using the evaluation license not the new license .
I have 1941, 2901 ISR routers. I will use 3G backup when primary link (metro ethernet / G.SHDSL) goes down. Do I have to use Data License (SL-19-DATA-K9 / SL-29-DATA-K9) in order to switch back to 3G when primary link is not reachable) ?
I have a Cisco 1941 router... ipbasek9. I want to use this at home for my primar LAN->WAN interface. So i need the Security license enabled.I have enabled the Security temp/eval license but can not find a way to manage it.I have tried downloading the Cisco Configuation Assitant, but this errors with "Unsupported Device type"
License output and config outbout below (no WAN interface on 10.0.x is just internal testing WAN IP. This device is not yet directly connected to the internet.
cisco1941#show lic Index 1 Feature: ipbasek9 Period left: Life time License Type: Permanent License State: Active, In Use License Count: Non-Counted
Can a Cisco PIX 515E with an Unrestricted License (UR) be deployed as a VPN concentrator? For example, remote users having VPN clients installed on their desktops connect through the Internet and are authenticated by the PIX 515E at the main site.
How to successfully deployed a WGB with a 5508 WLC?5508 code is 6.0.202.0 and the WGB is an AP1131AG?The documentation is ambiguous in that it states you can't use VLANs and then shows VLANs being used.I have a WLAN called wgb-link set up on the WLC with WPA-2 AES and PSK. The WLAN points to a logical interface called wgb-link which is configured to be in VLAN 9 and the default gateway is the VLAN SVI on the core switch.On the WGB I have configured the same SSID and security setup.
I am using the 5GHz radio and have set it to be a work group bridge.I have a sub interface dot11radio 1.9 configured:
encapsulation dot1q 9 native bridge group 1
I also have an ethernet sub interface configured:
encapsulation dot 1q 9 native bridge group 1
Int BVI1 is configured with an IP address in VLAN 9.The WGB links up fine and I can see it as a client on the WLC.
From the WGB CLI I can ping the interface on the WLC and the SVI on the core switch and any other device on the network in any VLAN.From the WLC I can ping the BVI1 address of the WGB.From the core switch I can ping the WLC interface and the WGB BVIi interface.
If I connect a laptop to the WGB ethernet port with a static IP address in VLAN 9 I cannot ping from the laptop to the WLC interface or the SVI on the core. I can only ping to the BVI address of the WGB.
I'm using LMS 4.0.1, migrating data from 3.2. When I select My menu, My dashboards, Functional (or any other view) I can get a list of non deployed port lets.
I have deployed a number of AIR-LAP1142N-E-K9 access points at a site, but I have an issue where all access point have defaulted to Channel 1. I have set the perameters on the Lightweight AP Template correctly to allow dinamic power and channel selection. The positioning of the AP's are as per the WCS planning tool.
What's the difference between VPN Plus license and Security Plus license. I have new 5520 shipped with VPN Plus license.Also does it require a seperate license for Anyconnect for Mobile and AnyConnect Essentials.
I’m stuck in some problem with installation of LMS4.0 in customer site.
- we purchase a LMS4.0(CWLMS-4.0-100-K9) but couldn’t install it on Windows server 2008 R2 64bit because those things don’t support each other. - I need to upgrade the LMS4.0 to LMS4.2 that is supporting Windows server 2008 R2 64bit. - So, I ordered following items via product update tool (url...) [code]
- In this status, how to install LMS4.2 with license for 100 devices? If I install R-PI12-BASE-K9 first, can i enter a licese for 100 devices for CWLMS-4.0-100-K9 into PI1.2?
I am attempting to send net and IPTV multicast to an Entone STB. This STB has some OTT features such as Vudu that need internet access. The DHCP address that we receive from our ISP strictly sends multicast streams to the STB.The first challenge is allowing DHCP options to pass through to the STB.Then I need to figure out a way to pass both the net and multicast to the STB.
I'm running a cisco 891 with ios Version 15.2(4)M3 ,now I have a dialer 0 interface with fast0 and 1 as well, all is working fine.now I just read about the new sh int 'INT' history feature but when I do it I get nothing.. not a graph or anything I get just nothing as if I just hit enter.anything I need to do to enable the feature?,if I do a sho proc cpu history that works just fine but not the sh int XYZ history commands
I have cisco 3560G with C3560 Software (C3560-IPSERVICESK9-M), Version 12.2(53)SE1 Image. I want to configure it for EEM feature so that when my Gig 0/7 port goes on it will automatically shutdown the port Gig 0/1.
I'm a bit confused about new NAT functionality in Ver 8.4(2). I've gone through all the documentation as well as different blogs but still not clear about the various things.One of these is NAT-CONTROL. I understand that this has now been removed. Does this means that traffic traversing the ASA doesn't need any NAT'ing commands unless specifically required by the administrator? In other words by default traffic is allowed through the firewall without any NAT'ing.
My Second Query
I've ASA5520 running ver 8.4(2). For inside interface, I've created 13 x sub-interfaces under Gi0/1. All have same security level i.e. 100. What I want to achieve is that:Traffic from these sub-interfaces should be NATTed to outside interface when going to internetBut, intra sub-interface traffic should be allowed without NAT'ing. I'm using RFC1918 on both sides i.e. source / destination The first point is not a problem it's working, however. I'm struggling with the second point. On ver 8.2, it wasn't a problem, I used NAT 0 with access-list permitting RFC1918 addresses as source and destination.
My problem with ASR 1006 as i tried to use the feature IRB ( integrated routing and bridging ) but i find that this feature is not supported i assume it may be a problem with IOS version or may be i made he configuration not in the proper way
so i am asking to try this feature on ASR 1000 series and work with it as I test this feature on other routers and it work just fine.
I've a new Dlink DIR-632. All ports snif from outside are answering stealth by default. And the port forwarding feature works good.The problem is that I would like to allow a trusted net IP to reach my computer, whatever the request may be (whatever tcp/udp and on any ports). A kind of DMZ just for a precise IP. I tried the inbound filter feature. I've choosen allow, and I've put the remote IP start and end the same IP. It has been added correctly to the list. However, this IP still doesn't seem to be able to access to my computer on any port unless it tries on an already forwarded port.
I've looked in many places but cannot see how or if it is possible to configure a phone, in CUCM to have a feature ring instead of the normal ring.In CUCME you go into the ephone x configuration mode, and assign the DN to the phone with the button xfx command. What this gives you is a slightly different ring tone when a call comes through. If I am not mistaken it is the same ringtone they use on the show "24".Is there a way to do this "feature" with CUCM?
We are currently installing RV-042 V3 Dual WAN VPN Routers for a Customer with an HQ Office & 3 Branch Offices. The Customer recently requested to use the WEB Filter feature available in the RV-042 V3 Router to do the followng : - " Block all the HTTP Traffic Except for the company Website " We tried all the Combinations between " Access Rules " & " Content Filtering " available under the " Firewall " but we always reach the result that either to Allow ALL HTTP Tarffic to All Websites or to Block ALL HTTP Traffic.
how to Block all HTTP Traffic except for certain URL ( Using the URL Name NOT the IP Address ).
We have 6500 chassises in our set up. But using CWLMS 4.0 , we are unable to manage VSS feature of 6500.Also User tracking for Nexus 7K Switches subnets are not working.
I would like to use the ip address-helper feature of my 3560 switch to point 10.1.0.0/24 to my Windows DHCP Server on 10.0.0.0/24 and I am unsure how to go about doing this.
Should we active IPS feature in ASA 5500-x by useing license?in the 5500-x ordering guide:IPS is only sold as ASA-IPS combo SKUs i.e., one cannot add IPS service as an option on top of ASA SKU. For example, if IPS service is desired on ASA 5515-X appliance, the relevant SKU is ASA5515-IPS-K8 or ASA5515-IPS-K9.But my customer has actived it by using the ASA5525-IPS-SSP on ASA5525-K9.