Professional Documents
Culture Documents
lab
LTRCRS-2579
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda
• Introduction
• Smart Accounts overview
• Products Registration
• On-Prem solution
• License Reservation
• License Conversion
• Troubleshooting scenarios
• Conclusion
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Other Smart Licensing Sessions
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Introduction
Why do we need a new Licensing Model?
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Software Licensing Transition
Classic Licensing Smart Licensing
Complete View
Limited View
Software, services, and devices in
Customers do not know what they own.
easy-to-use portal.
Device-Specific Company-Specific
Licenses are specific to only one device. Flexible licensing. Use across devices.
Locked Unlocked
Use only what you paid for. Add users and licenses as needed.
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Smart Accounts
overview
Smart Accounts – Virtual Accounts
Assets are represented as company owned allowing effortless sharing across your
enterprise
Licenses
Campus Access
bigu.edu
Devices
Computer Lab
Agreements
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Smart Accounts Types
Customer Partner
Smart Account Holding Account
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Use Case 1: Smart Account Layers
by TECHNOLOGY DOMAIN
Details:
Domain Name COMPANY.COM
Small/Medium Enterprise Size
Centralized IT Organization
Centralized Budgets and Security Smart Accounts COMPANY.COM (COMPANY)
Policies
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Use Case 1: Smart Account Structure
COMPANY.COM
Domain Name
COMPANY.COM
Smart Account
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Use Case 1: Smart Account Topology
Cisco Smart Software
Manager (CSSM)
cisco.com
COMPANY.COM Smart Account
ENTERPRISE NETWORKING COLLAB DEFAULT
Virtual Account Virtual Account Virtual Account
ENT
COLLAB ENT COLLAB
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Use Case 2: Smart Account Topology
by REGION and TECHNOLOGY DOMAIN
Details:
Domain Name COMPANY.COM
Medium/Large Enterprise Size
Centralized IT Organization
Separate Budgets and/or Security Smart Accounts COMPANY.COM (COMPANY)
Policies per Region
On-Prem
[Technology Domain]
Virtual Accounts
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Use Case 2: Smart Account Structure
COMPANY.COM
Domain Name
Default
COMPANY.COM Virtual Account
Smart Account
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Use Case 2: Smart Account Topology
Cisco Smart Software
Manager (CSSM)
cisco.com
COMPANY.COM Smart Account
DEFAULT NALA EMEA On-Prem NALA On-Prem EMEA On-Prem APAC APAC
VA VA VA VA VA VA VA
ENT
COLLAB
NALA ENT EMEA APAC COLLAB ENT
COLLAB
On-Prem NALA ENT
NALA ENT On-Prem NALA Collab
EMEA ENT On-Prem EMEA ENT
CL-OnPrem-EMEA-ENT
NALA CSR4
CL-OnPrem-EMEA-Collab
EMEA CSR5
CSSM CL-OnPrem-APAC-ENT
all products!
Security Policy
Cisco Products send usage information over the internet via a Proxy
Server. Any off-the-shelf Proxy will work.
Ease of use
HTTP
Cisco Proxy Cisco.com Usage Info
Product
File Transfer
3 Access Through On-Premise License Management
Cisco products send usage information to a locally installed satellite.
+ Periodically, exchange information with Cisco to keep satellite sync. This
4 synchronization can occur automatically in connected environments or Cisco
HTTPs
Cisco.com Usage Info
Cisco
manually in disconnected environments. Product Satellite
Availability
5 Full Offline Access – License Reservation
Limited
Request License
Use copy/paste information between product and Cisco.com to manually Copy / Paste
check in and out licenses. Functionally equivalent to current node locking, License Response
Cisco Cisco.com Usage Info
but with Smart License tracking. Product
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Smart Licensing Transport
• Smart Transport
• New transport mechanism for Smart Licensing
• Might be not supported on older Cisco products / software version
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Smart Call Home for Smart Licensing Transport
Option 1 - Default
Smart License
Cisco Smart
(Packet Delivery) Software Manager
SCH
Smart Agent
of data)
Home Server
Smart Call
Cisco Smart Call
Product Home
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Smart Transport
Option 2
• Smart License messages are sent to the Cisco SSM portal using Direct
URL
• Information is exchanged using
Smart License
Cisco Smart
HTTPS (TLS/SSL encryption Software Manager
of data)
Smart Agent
Product
(config)# license smart transport smart
(config)# license smart url <…>
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Smart Licensing Data Interchange & Visibility
Information exchanged with Cisco
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Smart Licensing Work Flow
Agreements
SL State=
Un-identified Customer Smart
Account identified SL State= Out-of
Registered Compliance
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Smart Licensing Workflow - ID Tokens
Example:
YWJkNWNhYTEtNDhjZC00YTcyLTllABCtZDE1ZjMyNWIxMGI4LTE1NzcyNzk4%0AMDY1NzB8QUg0M29wRElVMjhJaGp3UXJsNFUrdDBE
TnJrVTQ3MmxxMEdCSDMx%0AZ3RuUT0%3D%0A
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Smart License Product States
Un-
Registered
Failed
Register
Product
Registered
State
Consume
License
Out Of
Authorization Authorized
Compliance
Expired State
State
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Smart License Product States
• Registered state
Product has been associated with a valid Smart Account
Un-
Registered
Failed
Register
Product
Registered
State
Consume
License
Out Of
Authorization Authorized
Compliance
Expired State
Note: Platforms may differ with timeouts, State
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Smart License Product States
• Registered state
Product has been associated with a valid Smart Account
Un-
• Authorized state (In Compliance) Registered
Registered
State
Consume
License
Out Of
Authorization Authorized
Compliance
Expired State
Note: Platforms may differ with timeouts, State
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Smart License Product States
• Registered state
Product has been associated with a valid Smart Account
Un-
• Authorized state (In Compliance) Registered
Out Of
Authorization Authorized
Compliance
Expired State
Note: Platforms may differ with timeouts, State
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Smart License Product States
• Registered state
Product has been associated with a valid Smart Account
Un-
• Authorized state (In Compliance) Registered
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Evaluation Period
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Direct Access
Smart License Deployment models
The Cisco Product is configured to use Smart Licensing at install/provisioning time.
Direct cloud access is the default option
Options
1 Direct cloud access (default)
Cisco product sends usage information directly over the internet. No HTTPs
additional components are needed. Cisco Cisco.com Usage Info
all products!
Security Policy
Cisco Products send usage information over the internet via a Proxy
Server. Any off-the-shelf Proxy will work.
Ease of use
HTTP
Cisco Proxy Cisco.com Usage Info
Product
File Transfer
3 Access Through On-Premise License Management
Cisco products send usage information to a locally installed satellite.
+ Periodically, exchange information with Cisco to keep satellite sync. This
4 synchronization can occur automatically in connected environments or Cisco
HTTPs
Cisco.com Usage Info
Cisco
manually in disconnected environments. Product Satellite
Availability
5 Full Offline Access – License Reservation
Limited
Request License
Use copy/paste information between product and Cisco.com to manually Copy / Paste
check in and out licenses. Functionally equivalent to current node locking, License Response
Cisco Cisco.com Usage Info
but with Smart License tracking. Product
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Direct Cloud Access
Steps:
1. Setup layer 3 connectivity to tools.cisco.com
• DNS server (vrf?)
• Source interface for DNS communication (vrf?)
• Source interface for HTTP client (vrf?)
• Routing (vrf?) Cisco Smart
Software
2. Register to CSSM
License
Smart
Manager
Product
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
LAB Time: Scenario 1-2
Product Direct registration Lab topology - Pod01
LAB Time: Scenario 1-2
Cisco Smart Software
Manager (CSSM)
cisco.com
CL-DEFAULT-
Cisco Systems,
COMPANY.COM
Inc. (JAMES.CISCO.COM)
Smart Account
Smart Account Pod01
CL-Direct-NALA- CL-Direct-EMEA-
CL-DEFAULT- CL-Direct-NALA- CL-OnPrem-NALA-
CL-Direct-EMEA- CL-OnPrem-EMEA-
CL-OnPrem-NALA- CL-OnPrem-APAC-
CL-OnPrem-EMEA- CL-Direct-APAC-
CL-OnPrem-APAC- CL-Direct-EMEA-
Pod01
Pod01 Pod01 Pod01 Pod01 Pod01 Pod01 Pod01Pod01 Pod01
Pod01 Pod01
Pod01
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
On-Prem solution
Smart License Deployment models
The Cisco Product is configured to use Smart Licensing at install/provisioning time.
Direct cloud access is the default option
Options
1 Direct cloud access (default)
Cisco product sends usage information directly over the internet. No HTTPs
additional components are needed. Cisco Cisco.com Usage Info
all products!
Security Policy
Cisco Products send usage information over the internet via a Proxy
Server. Any off-the-shelf Proxy will work.
Ease of use
HTTP
Cisco Proxy Cisco.com Usage Info
Product
File Transfer
3 Access Through On-Premise License Management
Cisco products send usage information to a locally installed satellite.
+ Periodically, exchange information with Cisco to keep satellite sync. This
4 synchronization can occur automatically in connected environments or Cisco
HTTPs
Cisco.com Usage Info
Cisco
manually in disconnected environments. Product Satellite
Availability
5 Full Offline Access – License Reservation
Limited
Request License
Use copy/paste information between product and Cisco.com to manually Copy / Paste
check in and out licenses. Functionally equivalent to current node locking, License Response
Cisco Cisco.com Usage Info
but with Smart License tracking. Product
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
How does Cisco SSM On-Prem Work?
1 2 3
Install/Register Synchronize Local
Register/Report
CSSM On-Prem Database
Usage
Info
Cisco.com
HTTP / HTTPs
Cisco
CSSM
Product
On-Prem
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Smart Software Manager On-Prem -
Requirements
The Free installation package is available in ISO installable via Bootable Media
System Requirements
ISO (Customer Provided):
HTTPS://<On-prem-IP:8443> HTTPS://<On-prem-IP:8443>/admin
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Deployment Modes – Connected and
Disconnected
Connected Disconnected
Automatic
Updates
Periodic
Updates
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Change Product Configuration for On-Prem Model
CSSM On-Prem
• To ensure that Certificate Common Name match the DNS record.
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
LAB Time: Scenario 3
On-Prem solution Lab topology - Pod01
LAB Time: Scenario 3
Cisco Smart Software
Manager (CSSM)
cisco.com
CL-DEFAULT-
Cisco Systems,
COMPANY.COM
Inc. (JAMES.CISCO.COM)
Smart Account
Smart Account Pod01
CL-Direct-NALA- CL-Direct-EMEA-
CL-DEFAULT- CL-Direct-NALA- CL-OnPrem-NALA-
CL-Direct-EMEA- CL-OnPrem-EMEA-
CL-OnPrem-NALA- CL-OnPrem-APAC-
CL-OnPrem-EMEA- CL-Direct-APAC-
CL-OnPrem-APAC- CL-Direct-EMEA-
Pod01
Pod01 Pod01 Pod01 Pod01 Pod01 Pod01 Pod01Pod01 Pod01
Pod01 Pod01
Pod01
all products!
Security Policy
Cisco Products send usage information over the internet via a Proxy
Server. Any off-the-shelf Proxy will work.
Ease of use
HTTP
Cisco Proxy Cisco.com Usage Info
Product
File Transfer
3 Access Through On-Premise License Management
Cisco products send usage information to a locally installed satellite.
+ Periodically, exchange information with Cisco to keep satellite sync. This
4 synchronization can occur automatically in connected environments or Cisco
HTTPs
Cisco.com Usage Info
Cisco
manually in disconnected environments. Product Satellite
Availability
5 Full Offline Access – License Reservation
Limited
Request License
Use copy/paste information between product and Cisco.com to manually Copy / Paste
check in and out licenses. Functionally equivalent to current node locking, License Response
Cisco Cisco.com Usage Info
but with Smart License tracking. Product
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Introduction to License Reservation
The Smart Account must be authorized for License Reservation:
• Must have enough available licenses (Over subscription is not allowed)
• Smart Account must be authorized for any Export Restricted Functionality
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Specific License Reservation
3
Choose Licenses
5 4
Copy Auth String
Paste Auth String
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
License Reservation Cancellation
When licenses are reserved on a Product Instance, there are two ways to remove a
PID from a Smart Account and release all of the licenses reserved for that PID:
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
License
Conversion
License Conversion methods
• Convert manually:
• PAK conversion
• License conversion
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Device Led Conversion (DLC)
• Ensure correct license is the current running license as the DLC procedure
can only be done once!
• Steps:
1. Configure and setup Smart Licensing like normal
2. Register the device to CSSM / On-Prem
3. Licenses will be "Out Of Compliance” state after Registration
4. Check "show platform software license dlc" for licenses that will be converted during DLC
5. Start conversion
• When you start you will see status changes to “Waiting for response” and next status is 1h later
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Which licenses will be included in DLC?
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
DLC started…
ISR4331-lab# show license status
<..>
License Conversion: Automatic Conversion Enabled: False
Status: Waiting for response on Nov 05 08:54:25 2019 UTC
Next response check: Nov 05 09:54:30 2019 UTC
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Licenses not considered in the DLC path
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Troubleshooting
scenarios
CLI Commands
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Debugs
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
HTTP used instead of HTTPS
• HTTP is no longer supported for call-home, the below config will NOT work
call-home
profile “CiscoTAC-1”
destination address http http://tools.cisco.com/its/service/oddce/services/DDCEService
• Change it to:
destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
no destination address http http://tools.cisco.com/its/service/oddce/services/DDCEService
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Non-default call-home profiles
• Call-home profile not active or SL reporting not enabled:
call-home
contact-email-addr <myemail@abc.com> Not in the default config for a new
profile "Cisco-SL-01“
call-home profile !
active
reporting smart-licensing-data
destination transport-method http
no destination transport-method email
destination address http https://9.0.0.58:80/Transportgateway/services/DeviceRequestHandler
profile "CiscoTAC-1"
no active
reporting smart-licensing-data
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
DNS not working
• If DNS is not possible, obtain the IP address:
• perform an NSLOOKUP for tools.cisco.com
• ping tools.cisco.com from another device with DNS local to device being
converted
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
License Authorization "Failure reason: Fail to
send out Call Home HTTP message."
• Behavior:
• Device unable to register or renew authorization
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
License Authorization "Failure reason: Fail to
send out Call Home HTTP message."
• What to look into:
• Verify HTTP server configuration on the switch is correct.
• "show run | s http"
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
LAB Time: Scenario 4-6
On-Prem solution Lab topology - Pod01
LAB Time: Scenario 4-6 Cisco Smart Software
Manager (CSSM)
cisco.com
CL-DEFAULT-
Cisco Systems,
COMPANY.COM
Inc. (JAMES.CISCO.COM)
Smart Account
Smart Account Pod01
CL-Direct-NALA- CL-Direct-EMEA-
CL-DEFAULT- CL-Direct-NALA- CL-OnPrem-NALA-
CL-Direct-EMEA- CL-OnPrem-EMEA-
CL-OnPrem-NALA- CL-OnPrem-APAC-
CL-OnPrem-EMEA- CL-Direct-APAC-
CL-OnPrem-APAC- CL-Direct-EMEA-
Pod01
Pod01 Pod01 Pod01 Pod01 Pod01 Pod01 Pod01Pod01 Pod01
Pod01 Pod01
Pod01
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Conclusion
Call to Action
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Other Smart Licensing Sessions
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
LTRCRS-2579 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Thank you