SlideShare a Scribd company logo
Updated: About Cisco ISR G2 SEC and HSEC Licensing FAQ
We discussed the main difference between SEC-K9 license and HSEC-
k9 license. What are the Cisco ISR G2 SEC and HSEC License used for?
The SEC-K9 license enables standard encryption (VPN payload and secure
voice) on the ISR G2 platforms. The SEC-K9 license is designed to comply
with both local and U.S. export requirements for global distribution to all
countries. This license enforces a curtailment on the maximum number of
encrypted tunnels and the maximum encrypted throughput on the ISR G2
platforms.
The HSEC-K9 license removes the curtailment enforced by the U.S.
government export restrictions on the encrypted tunnel count and encrypted
throughput. HSEC-K9 is available only on the Cisco 2921, Cisco 2951,
Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. With the HSEC-
K9 license, the ISR G2 router can go over the curtailment limit of 225 tunnels
maximum for IP Security (IPsec) and encrypted throughput of 85 -Mbps
unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of
170 Mbps.
The Cisco 1941, 2901, and 2911 already have maximum encryption capacities
within export limits.
Now, in this article, we will discuss the in the context of the security licensing
and export restrictions, a tunnel is a construct established between two
routers (peers) to transport insecure payloads using data-encryption
techniques.
Firstly you can read some general Qs about the security licensing and export
restrictions.
The SEC-K9 license limits the number of concurrent encrypted sessions and
maximum encrypted throughput per device. This limit helps ensure that the
ISR G2 complies with U. S. government export restrictions regardless of the
final destination country.
The SEC-K9 permanent licenses apply to the Cisco 1900, 2900, and 3900
ISR G2 platforms; these licenses limit all encrypted tunnel counts to 225
tunnels maximum for IP Security (IPsec), Secure Sockets Layer VPN (SSL
VPN), a secure time-division multiplexing (TDM) gateway, and secure Cisco
Unified Border Element (CUBE) and 1000 tunnels for Transport Layer Security
(TLS) sessions.
The SEC-K9 license limits encrypted throughput to less than or equal to 85-
Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional
total of 170 Mbps. This requirement applies for the Cisco 1900, 2900, and
3900 ISR G2 platforms.
All threat defense and VPN features that are supported on the Cisco ISR G2
routers are functionally available for configuration with the SEC-K9. The
image that includes this license is the universal -k9 image. For example, the
Cisco IOS release version is c3900-universalk9-mz.SPA.150-1.M1.
Q. Does the router require a reload after installing the SEC-K9 or the
HSEC-K9 license?
A. Reload is needed only for technology package licenses such as datak9,
uck9, and securityk9/securityk9_npe. Installing the SEC-K9 or the HSEC-K9
license does not require a reload. Also, moving from a temporary license to a
permanent license does not require a reload.
Q. Why do I need to purchase the SEC-K9 license as a spare?
A. If you purchase a Cisco ISR G2 chassis and later decide to turn on security
features, you must buy a SEC-K9 license. The administrator must download
the license to the router and follow the license installation instructions that
come with the license to be able to use the security features on the router.
Q. What information do I need to order either the SEC-K9 or the
HSEC-K9 license as a spare for my ISR G2 router?
A. To order the licenses as spares, you need the output of the following
command-line interface (CLI) command: show license udi, shown at the
end of this section. You must enter the product ID (PID) and the serial
number into the tool to complete the order. This information makes the
license unique for a particular router, and the license is not transferrable
between routers.
The command output follows:
3925-perf#sh license udi
Device# PID SN UDI
-----------------------------------------------------------------------------
*0 C3900-SPE100/K9 FOC133037J9 C3900-SPE100/K9:FOC133037J9
For more information about software license activation on the ISR G2
platforms, please
visit:http://www.cisco.com/en/US/docs/routers/access/sw_activation/SA_on_I
SR.html.
Q. What features does the npe-k9 image support?
A. The SECNPE image supports Cisco IOS Firewall, Integrated Protection
Services (IPS), and URL Filtering (basically all the threat-defense functions).
Standard encryption features are not supported on the ISR G2 platforms with
this image.
…
More Examples of installing a HSEC license from users and the rules for
ordering you can read the full FAQ information here
http://www.cisco.com/c/en/us/products/collateral/routers/3900-series-
integrated-services-routers-isr/q-and-a-c67-606268.html
More Related
Cisco SEC-K9 License vs. HSEC-K9 License
Cisco Licenses on Cisco ISR G2
Cisco Licenses on Cisco ISR G2
General Features of Cisco ASA Licensing
How to Activate a Cisco License?
Cisco 800 Series Licensing Options

More Related Content

What's hot

CCNA Icnd110 s06l02
CCNA Icnd110 s06l02CCNA Icnd110 s06l02
CCNA Icnd110 s06l02
computerlenguyen
 
Icnd210 s02l03
Icnd210 s02l03Icnd210 s02l03
Icnd210 s02l03
computerlenguyen
 
Icnd210 s04l02
Icnd210 s04l02Icnd210 s04l02
Icnd210 s04l02
computerlenguyen
 
Icnd210 s02l01
Icnd210 s02l01Icnd210 s02l01
Icnd210 s02l01
computerlenguyen
 
Eigrp authentication
Eigrp authenticationEigrp authentication
Eigrp authentication
computerlenguyen
 
Icnd210 s08l04
Icnd210 s08l04Icnd210 s08l04
Icnd210 s08l04
computerlenguyen
 
Icnd210 s06l01
Icnd210 s06l01Icnd210 s06l01
Icnd210 s06l01
computerlenguyen
 
Icnd210 s08l03
Icnd210 s08l03Icnd210 s08l03
Icnd210 s08l03
computerlenguyen
 
CCNA Icnd110 s05l01
CCNA Icnd110 s05l01CCNA Icnd110 s05l01
CCNA Icnd110 s05l01
computerlenguyen
 
Icnd210 s08l05
Icnd210 s08l05Icnd210 s08l05
Icnd210 s08l05
computerlenguyen
 
520scg basic
520scg basic520scg basic
520scg basic
97148881557
 
CCNA Icnd110 s06l01
 CCNA Icnd110 s06l01 CCNA Icnd110 s06l01
CCNA Icnd110 s06l01
computerlenguyen
 
Icnd210 s06l02
Icnd210 s06l02Icnd210 s06l02
Icnd210 s06l02
computerlenguyen
 
Icnd210 s03l02
Icnd210 s03l02Icnd210 s03l02
Icnd210 s03l02
computerlenguyen
 
CCNA Icnd110 s04l07
CCNA Icnd110 s04l07CCNA Icnd110 s04l07
CCNA Icnd110 s04l07
computerlenguyen
 
Icnd210 s05l02
Icnd210 s05l02Icnd210 s05l02
Icnd210 s05l02
computerlenguyen
 
CCNA 2 Routing and Switching v5.0 Chapter 9
CCNA 2 Routing and Switching v5.0 Chapter 9CCNA 2 Routing and Switching v5.0 Chapter 9
CCNA 2 Routing and Switching v5.0 Chapter 9
Nil Menon
 
CCNA Icnd110 s02l04
CCNA Icnd110 s02l04CCNA Icnd110 s02l04
CCNA Icnd110 s02l04
computerlenguyen
 
Icnd210 s08l01
Icnd210 s08l01Icnd210 s08l01
Icnd210 s08l01
computerlenguyen
 
CCNA Icnd110 s04l08
CCNA Icnd110 s04l08CCNA Icnd110 s04l08
CCNA Icnd110 s04l08
computerlenguyen
 

What's hot (20)

CCNA Icnd110 s06l02
CCNA Icnd110 s06l02CCNA Icnd110 s06l02
CCNA Icnd110 s06l02
 
Icnd210 s02l03
Icnd210 s02l03Icnd210 s02l03
Icnd210 s02l03
 
Icnd210 s04l02
Icnd210 s04l02Icnd210 s04l02
Icnd210 s04l02
 
Icnd210 s02l01
Icnd210 s02l01Icnd210 s02l01
Icnd210 s02l01
 
Eigrp authentication
Eigrp authenticationEigrp authentication
Eigrp authentication
 
Icnd210 s08l04
Icnd210 s08l04Icnd210 s08l04
Icnd210 s08l04
 
Icnd210 s06l01
Icnd210 s06l01Icnd210 s06l01
Icnd210 s06l01
 
Icnd210 s08l03
Icnd210 s08l03Icnd210 s08l03
Icnd210 s08l03
 
CCNA Icnd110 s05l01
CCNA Icnd110 s05l01CCNA Icnd110 s05l01
CCNA Icnd110 s05l01
 
Icnd210 s08l05
Icnd210 s08l05Icnd210 s08l05
Icnd210 s08l05
 
520scg basic
520scg basic520scg basic
520scg basic
 
CCNA Icnd110 s06l01
 CCNA Icnd110 s06l01 CCNA Icnd110 s06l01
CCNA Icnd110 s06l01
 
Icnd210 s06l02
Icnd210 s06l02Icnd210 s06l02
Icnd210 s06l02
 
Icnd210 s03l02
Icnd210 s03l02Icnd210 s03l02
Icnd210 s03l02
 
CCNA Icnd110 s04l07
CCNA Icnd110 s04l07CCNA Icnd110 s04l07
CCNA Icnd110 s04l07
 
Icnd210 s05l02
Icnd210 s05l02Icnd210 s05l02
Icnd210 s05l02
 
CCNA 2 Routing and Switching v5.0 Chapter 9
CCNA 2 Routing and Switching v5.0 Chapter 9CCNA 2 Routing and Switching v5.0 Chapter 9
CCNA 2 Routing and Switching v5.0 Chapter 9
 
CCNA Icnd110 s02l04
CCNA Icnd110 s02l04CCNA Icnd110 s02l04
CCNA Icnd110 s02l04
 
Icnd210 s08l01
Icnd210 s08l01Icnd210 s08l01
Icnd210 s08l01
 
CCNA Icnd110 s04l08
CCNA Icnd110 s04l08CCNA Icnd110 s04l08
CCNA Icnd110 s04l08
 

Viewers also liked

Ip phone boot up process
Ip phone boot up processIp phone boot up process
Ip phone boot up process
IT Tech
 
Cisco trouble shooting
Cisco trouble shootingCisco trouble shooting
Cisco trouble shooting
Hamid Younesi
 
Definitely, cisco mobility express solution eases your wi fi deployments solu...
Definitely, cisco mobility express solution eases your wi fi deployments solu...Definitely, cisco mobility express solution eases your wi fi deployments solu...
Definitely, cisco mobility express solution eases your wi fi deployments solu...
IT Tech
 
Cisco identity services engine (ise) ordering steps & guide
Cisco identity services engine (ise) ordering steps & guideCisco identity services engine (ise) ordering steps & guide
Cisco identity services engine (ise) ordering steps & guide
IT Tech
 
Huawei s5700 ei in network--sample deployments
Huawei s5700 ei in network--sample deploymentsHuawei s5700 ei in network--sample deployments
Huawei s5700 ei in network--sample deployments
IT Tech
 
How to recover password on the cisco catalyst fixed configuration layer 2&lay...
How to recover password on the cisco catalyst fixed configuration layer 2&lay...How to recover password on the cisco catalyst fixed configuration layer 2&lay...
How to recover password on the cisco catalyst fixed configuration layer 2&lay...
IT Tech
 
Implementation of cisco wireless lan controller (multiple wla ns)
Implementation of cisco wireless lan controller (multiple wla ns)Implementation of cisco wireless lan controller (multiple wla ns)
Implementation of cisco wireless lan controller (multiple wla ns)
IT Tech
 
Line cards that are available for cisco catalyst 4500 series switches
Line cards that are available for cisco catalyst 4500 series switchesLine cards that are available for cisco catalyst 4500 series switches
Line cards that are available for cisco catalyst 4500 series switches
IT Tech
 
Limited time 'countdown deals' on cisco items
Limited time 'countdown deals' on cisco itemsLimited time 'countdown deals' on cisco items
Limited time 'countdown deals' on cisco items
IT Tech
 
A new featured product cisco ie4010 series switches
A new featured product cisco ie4010 series switchesA new featured product cisco ie4010 series switches
A new featured product cisco ie4010 series switches
IT Tech
 
The new isr 4221, the new cisco dna ready platform
The new isr 4221, the new cisco dna ready platformThe new isr 4221, the new cisco dna ready platform
The new isr 4221, the new cisco dna ready platform
IT Tech
 
Sample deployments the ar3200 series
Sample deployments the ar3200 seriesSample deployments the ar3200 series
Sample deployments the ar3200 series
IT Tech
 
The latest isr 4000 model comparison
The latest isr 4000 model comparisonThe latest isr 4000 model comparison
The latest isr 4000 model comparison
IT Tech
 
Cisco one advanced security
Cisco one advanced securityCisco one advanced security
Cisco one advanced security
IT Tech
 

Viewers also liked (14)

Ip phone boot up process
Ip phone boot up processIp phone boot up process
Ip phone boot up process
 
Cisco trouble shooting
Cisco trouble shootingCisco trouble shooting
Cisco trouble shooting
 
Definitely, cisco mobility express solution eases your wi fi deployments solu...
Definitely, cisco mobility express solution eases your wi fi deployments solu...Definitely, cisco mobility express solution eases your wi fi deployments solu...
Definitely, cisco mobility express solution eases your wi fi deployments solu...
 
Cisco identity services engine (ise) ordering steps & guide
Cisco identity services engine (ise) ordering steps & guideCisco identity services engine (ise) ordering steps & guide
Cisco identity services engine (ise) ordering steps & guide
 
Huawei s5700 ei in network--sample deployments
Huawei s5700 ei in network--sample deploymentsHuawei s5700 ei in network--sample deployments
Huawei s5700 ei in network--sample deployments
 
How to recover password on the cisco catalyst fixed configuration layer 2&lay...
How to recover password on the cisco catalyst fixed configuration layer 2&lay...How to recover password on the cisco catalyst fixed configuration layer 2&lay...
How to recover password on the cisco catalyst fixed configuration layer 2&lay...
 
Implementation of cisco wireless lan controller (multiple wla ns)
Implementation of cisco wireless lan controller (multiple wla ns)Implementation of cisco wireless lan controller (multiple wla ns)
Implementation of cisco wireless lan controller (multiple wla ns)
 
Line cards that are available for cisco catalyst 4500 series switches
Line cards that are available for cisco catalyst 4500 series switchesLine cards that are available for cisco catalyst 4500 series switches
Line cards that are available for cisco catalyst 4500 series switches
 
Limited time 'countdown deals' on cisco items
Limited time 'countdown deals' on cisco itemsLimited time 'countdown deals' on cisco items
Limited time 'countdown deals' on cisco items
 
A new featured product cisco ie4010 series switches
A new featured product cisco ie4010 series switchesA new featured product cisco ie4010 series switches
A new featured product cisco ie4010 series switches
 
The new isr 4221, the new cisco dna ready platform
The new isr 4221, the new cisco dna ready platformThe new isr 4221, the new cisco dna ready platform
The new isr 4221, the new cisco dna ready platform
 
Sample deployments the ar3200 series
Sample deployments the ar3200 seriesSample deployments the ar3200 series
Sample deployments the ar3200 series
 
The latest isr 4000 model comparison
The latest isr 4000 model comparisonThe latest isr 4000 model comparison
The latest isr 4000 model comparison
 
Cisco one advanced security
Cisco one advanced securityCisco one advanced security
Cisco one advanced security
 

Similar to Updated about cisco isr g2 sec and hsec licensing faq

EMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdf
EMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdfEMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdf
EMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdf
jawed29
 
Cisco isr 900 series highlights, platform specs, licenses, transition guide
Cisco isr 900 series highlights, platform specs, licenses, transition guideCisco isr 900 series highlights, platform specs, licenses, transition guide
Cisco isr 900 series highlights, platform specs, licenses, transition guide
IT Tech
 
Licensing on Cisco 2960, 3560X and 3750X...
Licensing on Cisco 2960, 3560X and 3750X...Licensing on Cisco 2960, 3560X and 3750X...
Licensing on Cisco 2960, 3560X and 3750X...
IT Tech
 
cisco-air-cap3702i-k-k9-datasheet.pdf
cisco-air-cap3702i-k-k9-datasheet.pdfcisco-air-cap3702i-k-k9-datasheet.pdf
cisco-air-cap3702i-k-k9-datasheet.pdf
Hi-Network.com
 
cisco-air-cap3702i-s-k9-datasheet.pdf
cisco-air-cap3702i-s-k9-datasheet.pdfcisco-air-cap3702i-s-k9-datasheet.pdf
cisco-air-cap3702i-s-k9-datasheet.pdf
Hi-Network.com
 
ROUTER Cisco 1921- HOJA TECNICA DE FABRICA
ROUTER Cisco 1921- HOJA TECNICA DE FABRICAROUTER Cisco 1921- HOJA TECNICA DE FABRICA
ROUTER Cisco 1921- HOJA TECNICA DE FABRICA
JULIOCESARHERRERALEV
 
Introduction to Segment Routing
Introduction to Segment RoutingIntroduction to Segment Routing
Introduction to Segment Routing
MyNOG
 
Deploying Carrier Ethernet Features on Cisco ASR 9000
Deploying Carrier Ethernet Features on Cisco ASR 9000Deploying Carrier Ethernet Features on Cisco ASR 9000
Deploying Carrier Ethernet Features on Cisco ASR 9000
Vinod Kumar Balasubramanyam
 
Deploying Carrier Ethernet features on ASR 9000
Deploying Carrier Ethernet features on ASR 9000Deploying Carrier Ethernet features on ASR 9000
Deploying Carrier Ethernet features on ASR 9000
Vinod Kumar Balasubramanyam
 
CISCO Live SD-WAN Technology Bi-Diractional
CISCO Live SD-WAN Technology Bi-DiractionalCISCO Live SD-WAN Technology Bi-Diractional
CISCO Live SD-WAN Technology Bi-Diractional
sachidaddjrt
 
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docxAll contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
galerussel59292
 
Cisco NM1FE2W
Cisco NM1FE2WCisco NM1FE2W
Cisco NM1FE2W
savomir
 
cisco-air-cap3702i-q-k9-datasheet.pdf
cisco-air-cap3702i-q-k9-datasheet.pdfcisco-air-cap3702i-q-k9-datasheet.pdf
cisco-air-cap3702i-q-k9-datasheet.pdf
Hi-Network.com
 
cisco-air-cap3702i-d-k9-datasheet.pdf
cisco-air-cap3702i-d-k9-datasheet.pdfcisco-air-cap3702i-d-k9-datasheet.pdf
cisco-air-cap3702i-d-k9-datasheet.pdf
Hi-Network.com
 
Cisco WIC-2T
Cisco WIC-2TCisco WIC-2T
Cisco WIC-2T
savomir
 
Cisco 1921 review why take it into top list while selecting cisco routers
Cisco 1921 review why take it into top list while selecting cisco routersCisco 1921 review why take it into top list while selecting cisco routers
Cisco 1921 review why take it into top list while selecting cisco routers
IT Tech
 
cisco-air-cap3702i-r-k9-datasheet.pdf
cisco-air-cap3702i-r-k9-datasheet.pdfcisco-air-cap3702i-r-k9-datasheet.pdf
cisco-air-cap3702i-r-k9-datasheet.pdf
Hi-Network.com
 
P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.
Kapil Sabharwal
 
Network Enhancements on BitVisor for BitVisor Summit 12
Network Enhancements on BitVisor for BitVisor Summit 12Network Enhancements on BitVisor for BitVisor Summit 12
Network Enhancements on BitVisor for BitVisor Summit 12
cjchen22
 
cisco-air-cap3702i-n-k9-datasheet.pdf
cisco-air-cap3702i-n-k9-datasheet.pdfcisco-air-cap3702i-n-k9-datasheet.pdf
cisco-air-cap3702i-n-k9-datasheet.pdf
Hi-Network.com
 

Similar to Updated about cisco isr g2 sec and hsec licensing faq (20)

EMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdf
EMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdfEMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdf
EMEAR_Security_TAC_2021_IPSec_Site_to_Site_VPNs_on_FTD_Overview.pdf
 
Cisco isr 900 series highlights, platform specs, licenses, transition guide
Cisco isr 900 series highlights, platform specs, licenses, transition guideCisco isr 900 series highlights, platform specs, licenses, transition guide
Cisco isr 900 series highlights, platform specs, licenses, transition guide
 
Licensing on Cisco 2960, 3560X and 3750X...
Licensing on Cisco 2960, 3560X and 3750X...Licensing on Cisco 2960, 3560X and 3750X...
Licensing on Cisco 2960, 3560X and 3750X...
 
cisco-air-cap3702i-k-k9-datasheet.pdf
cisco-air-cap3702i-k-k9-datasheet.pdfcisco-air-cap3702i-k-k9-datasheet.pdf
cisco-air-cap3702i-k-k9-datasheet.pdf
 
cisco-air-cap3702i-s-k9-datasheet.pdf
cisco-air-cap3702i-s-k9-datasheet.pdfcisco-air-cap3702i-s-k9-datasheet.pdf
cisco-air-cap3702i-s-k9-datasheet.pdf
 
ROUTER Cisco 1921- HOJA TECNICA DE FABRICA
ROUTER Cisco 1921- HOJA TECNICA DE FABRICAROUTER Cisco 1921- HOJA TECNICA DE FABRICA
ROUTER Cisco 1921- HOJA TECNICA DE FABRICA
 
Introduction to Segment Routing
Introduction to Segment RoutingIntroduction to Segment Routing
Introduction to Segment Routing
 
Deploying Carrier Ethernet Features on Cisco ASR 9000
Deploying Carrier Ethernet Features on Cisco ASR 9000Deploying Carrier Ethernet Features on Cisco ASR 9000
Deploying Carrier Ethernet Features on Cisco ASR 9000
 
Deploying Carrier Ethernet features on ASR 9000
Deploying Carrier Ethernet features on ASR 9000Deploying Carrier Ethernet features on ASR 9000
Deploying Carrier Ethernet features on ASR 9000
 
CISCO Live SD-WAN Technology Bi-Diractional
CISCO Live SD-WAN Technology Bi-DiractionalCISCO Live SD-WAN Technology Bi-Diractional
CISCO Live SD-WAN Technology Bi-Diractional
 
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docxAll contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
All contents are Copyright © 1992–2012 Cisco Systems, Inc. A.docx
 
Cisco NM1FE2W
Cisco NM1FE2WCisco NM1FE2W
Cisco NM1FE2W
 
cisco-air-cap3702i-q-k9-datasheet.pdf
cisco-air-cap3702i-q-k9-datasheet.pdfcisco-air-cap3702i-q-k9-datasheet.pdf
cisco-air-cap3702i-q-k9-datasheet.pdf
 
cisco-air-cap3702i-d-k9-datasheet.pdf
cisco-air-cap3702i-d-k9-datasheet.pdfcisco-air-cap3702i-d-k9-datasheet.pdf
cisco-air-cap3702i-d-k9-datasheet.pdf
 
Cisco WIC-2T
Cisco WIC-2TCisco WIC-2T
Cisco WIC-2T
 
Cisco 1921 review why take it into top list while selecting cisco routers
Cisco 1921 review why take it into top list while selecting cisco routersCisco 1921 review why take it into top list while selecting cisco routers
Cisco 1921 review why take it into top list while selecting cisco routers
 
cisco-air-cap3702i-r-k9-datasheet.pdf
cisco-air-cap3702i-r-k9-datasheet.pdfcisco-air-cap3702i-r-k9-datasheet.pdf
cisco-air-cap3702i-r-k9-datasheet.pdf
 
P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.P&G BT Global Services - LLD Final Revision Year 2008.
P&G BT Global Services - LLD Final Revision Year 2008.
 
Network Enhancements on BitVisor for BitVisor Summit 12
Network Enhancements on BitVisor for BitVisor Summit 12Network Enhancements on BitVisor for BitVisor Summit 12
Network Enhancements on BitVisor for BitVisor Summit 12
 
cisco-air-cap3702i-n-k9-datasheet.pdf
cisco-air-cap3702i-n-k9-datasheet.pdfcisco-air-cap3702i-n-k9-datasheet.pdf
cisco-air-cap3702i-n-k9-datasheet.pdf
 

More from IT Tech

Cisco ip phone key expansion module setup
Cisco ip phone key expansion module setupCisco ip phone key expansion module setup
Cisco ip phone key expansion module setup
IT Tech
 
Cisco catalyst 9200 series platform spec, licenses, transition guide
Cisco catalyst 9200 series platform spec, licenses, transition guideCisco catalyst 9200 series platform spec, licenses, transition guide
Cisco catalyst 9200 series platform spec, licenses, transition guide
IT Tech
 
Hpe pro liant gen9 to gen10 server transition guide
Hpe pro liant gen9 to gen10 server transition guideHpe pro liant gen9 to gen10 server transition guide
Hpe pro liant gen9 to gen10 server transition guide
IT Tech
 
The new cisco isr 4461 faq
The new cisco isr 4461 faqThe new cisco isr 4461 faq
The new cisco isr 4461 faq
IT Tech
 
New nexus 400 gigabit ethernet (400 g) switches
New nexus 400 gigabit ethernet (400 g) switchesNew nexus 400 gigabit ethernet (400 g) switches
New nexus 400 gigabit ethernet (400 g) switches
IT Tech
 
Tested cisco isr 1100 delivers the richest set of wi-fi features
Tested cisco isr 1100 delivers the richest set of wi-fi featuresTested cisco isr 1100 delivers the richest set of wi-fi features
Tested cisco isr 1100 delivers the richest set of wi-fi features
IT Tech
 
Aruba campus and branch switching solution
Aruba campus and branch switching solutionAruba campus and branch switching solution
Aruba campus and branch switching solution
IT Tech
 
Cisco transceiver module for compatible catalyst switches
Cisco transceiver module for compatible catalyst switchesCisco transceiver module for compatible catalyst switches
Cisco transceiver module for compatible catalyst switches
IT Tech
 
Cisco ios on cisco catalyst switches
Cisco ios on cisco catalyst switchesCisco ios on cisco catalyst switches
Cisco ios on cisco catalyst switches
IT Tech
 
Cisco's wireless solutions deployment modes
Cisco's wireless solutions deployment modesCisco's wireless solutions deployment modes
Cisco's wireless solutions deployment modes
IT Tech
 
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dellCompetitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
IT Tech
 
Four reasons to consider the all in-one isr 1000
Four reasons to consider the all in-one isr 1000Four reasons to consider the all in-one isr 1000
Four reasons to consider the all in-one isr 1000
IT Tech
 
The difference between yellow and white labeled ports on a nexus 2300 series fex
The difference between yellow and white labeled ports on a nexus 2300 series fexThe difference between yellow and white labeled ports on a nexus 2300 series fex
The difference between yellow and white labeled ports on a nexus 2300 series fex
IT Tech
 
Cisco transceiver modules for compatible cisco switches series
Cisco transceiver modules for compatible cisco switches seriesCisco transceiver modules for compatible cisco switches series
Cisco transceiver modules for compatible cisco switches series
IT Tech
 
Guide to the new cisco firepower 2100 series
Guide to the new cisco firepower 2100 seriesGuide to the new cisco firepower 2100 series
Guide to the new cisco firepower 2100 series
IT Tech
 
892 f sfp configuration example
892 f sfp configuration example892 f sfp configuration example
892 f sfp configuration example
IT Tech
 
Cisco nexus 7000 and nexus 7700
Cisco nexus 7000 and nexus 7700Cisco nexus 7000 and nexus 7700
Cisco nexus 7000 and nexus 7700
IT Tech
 
Cisco firepower ngips series migration options
Cisco firepower ngips series migration optionsCisco firepower ngips series migration options
Cisco firepower ngips series migration options
IT Tech
 
Eol transceiver to replacement model
Eol transceiver to replacement modelEol transceiver to replacement model
Eol transceiver to replacement model
IT Tech
 
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngipsCisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngips
IT Tech
 

More from IT Tech (20)

Cisco ip phone key expansion module setup
Cisco ip phone key expansion module setupCisco ip phone key expansion module setup
Cisco ip phone key expansion module setup
 
Cisco catalyst 9200 series platform spec, licenses, transition guide
Cisco catalyst 9200 series platform spec, licenses, transition guideCisco catalyst 9200 series platform spec, licenses, transition guide
Cisco catalyst 9200 series platform spec, licenses, transition guide
 
Hpe pro liant gen9 to gen10 server transition guide
Hpe pro liant gen9 to gen10 server transition guideHpe pro liant gen9 to gen10 server transition guide
Hpe pro liant gen9 to gen10 server transition guide
 
The new cisco isr 4461 faq
The new cisco isr 4461 faqThe new cisco isr 4461 faq
The new cisco isr 4461 faq
 
New nexus 400 gigabit ethernet (400 g) switches
New nexus 400 gigabit ethernet (400 g) switchesNew nexus 400 gigabit ethernet (400 g) switches
New nexus 400 gigabit ethernet (400 g) switches
 
Tested cisco isr 1100 delivers the richest set of wi-fi features
Tested cisco isr 1100 delivers the richest set of wi-fi featuresTested cisco isr 1100 delivers the richest set of wi-fi features
Tested cisco isr 1100 delivers the richest set of wi-fi features
 
Aruba campus and branch switching solution
Aruba campus and branch switching solutionAruba campus and branch switching solution
Aruba campus and branch switching solution
 
Cisco transceiver module for compatible catalyst switches
Cisco transceiver module for compatible catalyst switchesCisco transceiver module for compatible catalyst switches
Cisco transceiver module for compatible catalyst switches
 
Cisco ios on cisco catalyst switches
Cisco ios on cisco catalyst switchesCisco ios on cisco catalyst switches
Cisco ios on cisco catalyst switches
 
Cisco's wireless solutions deployment modes
Cisco's wireless solutions deployment modesCisco's wireless solutions deployment modes
Cisco's wireless solutions deployment modes
 
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dellCompetitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
 
Four reasons to consider the all in-one isr 1000
Four reasons to consider the all in-one isr 1000Four reasons to consider the all in-one isr 1000
Four reasons to consider the all in-one isr 1000
 
The difference between yellow and white labeled ports on a nexus 2300 series fex
The difference between yellow and white labeled ports on a nexus 2300 series fexThe difference between yellow and white labeled ports on a nexus 2300 series fex
The difference between yellow and white labeled ports on a nexus 2300 series fex
 
Cisco transceiver modules for compatible cisco switches series
Cisco transceiver modules for compatible cisco switches seriesCisco transceiver modules for compatible cisco switches series
Cisco transceiver modules for compatible cisco switches series
 
Guide to the new cisco firepower 2100 series
Guide to the new cisco firepower 2100 seriesGuide to the new cisco firepower 2100 series
Guide to the new cisco firepower 2100 series
 
892 f sfp configuration example
892 f sfp configuration example892 f sfp configuration example
892 f sfp configuration example
 
Cisco nexus 7000 and nexus 7700
Cisco nexus 7000 and nexus 7700Cisco nexus 7000 and nexus 7700
Cisco nexus 7000 and nexus 7700
 
Cisco firepower ngips series migration options
Cisco firepower ngips series migration optionsCisco firepower ngips series migration options
Cisco firepower ngips series migration options
 
Eol transceiver to replacement model
Eol transceiver to replacement modelEol transceiver to replacement model
Eol transceiver to replacement model
 
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngipsCisco firepower 2100 series, as a ngfw or a ngips
Cisco firepower 2100 series, as a ngfw or a ngips
 

Recently uploaded

cyber crime.pptx..........................
cyber crime.pptx..........................cyber crime.pptx..........................
cyber crime.pptx..........................
GNAMBIKARAO
 
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
dtagbe
 
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
APNIC
 
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
APNIC
 
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
thezot
 
How to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdfHow to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdf
Infosec train
 
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
rtunex8r
 
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
3a0sd7z3
 
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
3a0sd7z3
 
HijackLoader Evolution: Interactive Process Hollowing
HijackLoader Evolution: Interactive Process HollowingHijackLoader Evolution: Interactive Process Hollowing
HijackLoader Evolution: Interactive Process Hollowing
Donato Onofri
 
Bengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal BrandingBengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal Branding
Tarandeep Singh
 

Recently uploaded (11)

cyber crime.pptx..........................
cyber crime.pptx..........................cyber crime.pptx..........................
cyber crime.pptx..........................
 
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
 
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
 
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
 
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
 
How to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdfHow to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdf
 
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
 
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
 
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
 
HijackLoader Evolution: Interactive Process Hollowing
HijackLoader Evolution: Interactive Process HollowingHijackLoader Evolution: Interactive Process Hollowing
HijackLoader Evolution: Interactive Process Hollowing
 
Bengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal BrandingBengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal Branding
 

Updated about cisco isr g2 sec and hsec licensing faq

  • 1. Updated: About Cisco ISR G2 SEC and HSEC Licensing FAQ We discussed the main difference between SEC-K9 license and HSEC- k9 license. What are the Cisco ISR G2 SEC and HSEC License used for? The SEC-K9 license enables standard encryption (VPN payload and secure voice) on the ISR G2 platforms. The SEC-K9 license is designed to comply with both local and U.S. export requirements for global distribution to all countries. This license enforces a curtailment on the maximum number of encrypted tunnels and the maximum encrypted throughput on the ISR G2 platforms. The HSEC-K9 license removes the curtailment enforced by the U.S. government export restrictions on the encrypted tunnel count and encrypted throughput. HSEC-K9 is available only on the Cisco 2921, Cisco 2951, Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. With the HSEC- K9 license, the ISR G2 router can go over the curtailment limit of 225 tunnels maximum for IP Security (IPsec) and encrypted throughput of 85 -Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of 170 Mbps. The Cisco 1941, 2901, and 2911 already have maximum encryption capacities within export limits. Now, in this article, we will discuss the in the context of the security licensing and export restrictions, a tunnel is a construct established between two routers (peers) to transport insecure payloads using data-encryption techniques. Firstly you can read some general Qs about the security licensing and export restrictions.
  • 2. The SEC-K9 license limits the number of concurrent encrypted sessions and maximum encrypted throughput per device. This limit helps ensure that the ISR G2 complies with U. S. government export restrictions regardless of the final destination country. The SEC-K9 permanent licenses apply to the Cisco 1900, 2900, and 3900 ISR G2 platforms; these licenses limit all encrypted tunnel counts to 225 tunnels maximum for IP Security (IPsec), Secure Sockets Layer VPN (SSL VPN), a secure time-division multiplexing (TDM) gateway, and secure Cisco Unified Border Element (CUBE) and 1000 tunnels for Transport Layer Security (TLS) sessions. The SEC-K9 license limits encrypted throughput to less than or equal to 85- Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of 170 Mbps. This requirement applies for the Cisco 1900, 2900, and 3900 ISR G2 platforms. All threat defense and VPN features that are supported on the Cisco ISR G2 routers are functionally available for configuration with the SEC-K9. The
  • 3. image that includes this license is the universal -k9 image. For example, the Cisco IOS release version is c3900-universalk9-mz.SPA.150-1.M1. Q. Does the router require a reload after installing the SEC-K9 or the HSEC-K9 license? A. Reload is needed only for technology package licenses such as datak9, uck9, and securityk9/securityk9_npe. Installing the SEC-K9 or the HSEC-K9 license does not require a reload. Also, moving from a temporary license to a permanent license does not require a reload. Q. Why do I need to purchase the SEC-K9 license as a spare? A. If you purchase a Cisco ISR G2 chassis and later decide to turn on security features, you must buy a SEC-K9 license. The administrator must download the license to the router and follow the license installation instructions that come with the license to be able to use the security features on the router. Q. What information do I need to order either the SEC-K9 or the HSEC-K9 license as a spare for my ISR G2 router? A. To order the licenses as spares, you need the output of the following command-line interface (CLI) command: show license udi, shown at the end of this section. You must enter the product ID (PID) and the serial number into the tool to complete the order. This information makes the license unique for a particular router, and the license is not transferrable between routers. The command output follows: 3925-perf#sh license udi Device# PID SN UDI ----------------------------------------------------------------------------- *0 C3900-SPE100/K9 FOC133037J9 C3900-SPE100/K9:FOC133037J9 For more information about software license activation on the ISR G2 platforms, please visit:http://www.cisco.com/en/US/docs/routers/access/sw_activation/SA_on_I SR.html.
  • 4. Q. What features does the npe-k9 image support? A. The SECNPE image supports Cisco IOS Firewall, Integrated Protection Services (IPS), and URL Filtering (basically all the threat-defense functions). Standard encryption features are not supported on the ISR G2 platforms with this image. … More Examples of installing a HSEC license from users and the rules for ordering you can read the full FAQ information here http://www.cisco.com/c/en/us/products/collateral/routers/3900-series- integrated-services-routers-isr/q-and-a-c67-606268.html More Related Cisco SEC-K9 License vs. HSEC-K9 License Cisco Licenses on Cisco ISR G2 Cisco Licenses on Cisco ISR G2 General Features of Cisco ASA Licensing How to Activate a Cisco License? Cisco 800 Series Licensing Options