With the release of the Q2 2022 FortiNet price list, they have decided to split FortiCare up into three different versions
FortiCare Essentials: Is the base-level service, and it is targeted toward devices that require a limited amount of support. This service is only offered to FortiGate models 8x and below and to low-end FortiWifi devices. Support includes web only tickets & chat, with next day business response.
FortiCare Premium: The previous 24×7 FortiCare offering, including ‘follow the sun support’, one-hour response for critical issues and the next business-day response for non-critical issues.
FortiCare Elite: The previous ASE (Advanced Support and Engineering) FortiCare offering now enabling coverage of a broader product range. This level provides 24×7 follow the sun support and optimum response times of 15 minutes. FortiCare Elite services offers enhanced service-level agreements (SLAs) and accelerated issue resolution. This advanced support offering provides access to a dedicated support team. Single-touch ticket handling by the expert technical team streamlines resolution. This option also provides Extended End-of-Engineering-Support (EoE’s) of 18 months for added flexibility and access to the new FortiCare Elite Portal. This intuitive portal provides a single unified view of device and security health.
Related Articles, References, Credits, or External Links
Both licenses are available as 1, 2 and 5 (not 3 as listed on the Cisco website) year subscription, or you can buy Plus licenses with a perpetual license option.
Note: For PLUS Licences looks at SKUs starting L-AC-PLS, for APEX Licences look SKUs starting at L-AC-APX
(Note: if you have a Plus Perpetual license you still need to purchase a software applications support plus upgrades (SASU) contract.
Regardless of which you buy, the SASU for AnyConnect is NOT included in the support contract for the parent device e.g. the SmartNet on your Cisco ASA Firewall.
To purchase support you order the parent license (SKU: L-AC-PLS-P-G) which has no cost, then you add in the relevant license for the amount of clients you have e.g. AC-PLS-P-500-S for 500 users, AC-PLS-P-2000-S for 2000 users etc.
BE AWARE: AnyConnect 4 Licenses will display as AnyConnect Premium licenses when you issue a ‘show version’ command. When adding an AnyConnect 4 License (regardless of the quantity of licenses added), will license to the maximum permitted AnyConnect Premium license count for the ASA hardware platform, those being;
New AnyConnect VPN Only Licences (Perpetual)
You can now purchase VPN Only perpetual licences, they are sold by ‘Concurrent VPN Connection‘. You order them like so;
L-AC-VPNO-25 (for 25 concurrent VPN connections) you can also buy in 50, 100, 250, 500, 1K, 2500, 5K ,and 10K versions. Depending on what you device will physically support (see below)
I get asked this at least once a month, “What’s the score with this DNA Licensing?” It took long enough for everyone to get used to Lan Base, IP Base, and IP Services!
The cynic in me would say, Cisco have learned from Meraki that selling subscription licences is much better than selling products that you don’t get any recurring revenue from. But I’ll try an give you the short answer so you can get the correct license.
Solution: Buying Cisco Catalyst 9K Switches
Firstly: Not sure who decided that Cisco would release 9000 series Catalyst switches, when they had 9000 series Nexus switches? (Thanks for that!)
Catalyst 9200 or 9300?
As a rule of thumb 9200 series are typically used as access switches i.e. replacements for things like the Catalyst 2960, 2960-X, and 2960-XR). And the 9300 series are a replacement for things like Cisco Catalyst 3750G, 3750-X, and 3850.
Note: There’s also a Catalyst 9400 switch, which is a modular (line card) based chassis switch to replace the Catalyst 4500 and 6000 series. Note2: There’s also a Catalyst 9500 switch that replaced the 10Gbps catalyst 3850 models (traditional 1U size). Note3: There’s also a Catalyst 9600 switch which is modular (line card) based chassis switch to replace the Catalyst 6000 Series. Note4: There’s also a Catalyst 9800 series which, just to confuse everyone further, is a range of wireless controllers?
So which switch to buy? Cisco keep adding models to both ranges so the first thing to do is decide 9200 or 9300, then look at the current Cisco Data Sheet for that range.
What uplink ports do you need? (Some models have fixed (built in) uplinks, others need a network module (modular) uplink. Remember modular uplinks have their own part number (SKU), and will need to be ordered separately. (Note:9200L and 9300L have fixed uplinks)
Do you need additional (redundant) power supplies?
Do you need to ‘Stack’ your switches, if so don’t forget to get a stack cable (theres no separate stacking modules).
They were cheaper than you expected right?
That’s because now we need to add on a DNA licence as well.
DNA Licensing
Cisco DNA (Digital Network Architecture) is the name given collectively to a suite of products that are aimed towards being software driven, automated, with built in security.
There’s three types;
DNA Essentials: (Lan Base in old money) Basically Layer 2 functionality and static routing.
DNA Advantage: (Combines IP Base and IP Services in old money) Basically full Layer 3 functionality, (and all the functionality of DNA Essentials).
DNA Premier: Combines all the functionality of DNA Essentials and DNA Advantage, and adds on ISE integration and Cisco Secure Network Analytics (formerly Stealthwatch) support.
Each licence comes in either a 3 Year, 5 Year, or 7 Year subscription model.
Example DNA Licensing SKU: C9200- DNA-E-24-3Y
C9200 – for a Cisco Catalyst 9200 series switch.
DNA – Digital Network Architecture licence.
E – Essentials (A would be advantage, and P would be premier).
24 – For a 24 port switch
3Y – 3 Year Subscription
Related Articles, References, Credits, or External Links
When Cisco released the 8.2 version of the ASA code, they changed their licensing model for AnyConnect Licenses. There are two licensing models, Premium and Essentials.
Solution
Cisco ASA AnyConnect Premium Licenses.
You get two of these free with your firewall*, with a ‘Premium License’ you can use the AnyConnect client software for remote VPN Access, and you can access Clientless SSL facilities via the web portal.
*As pointed out by @nhomsany “The two default premium licenses available are NOT cross-platform, (i.e. only Mac or Windows).
Additionally you can use this license’ model with the Advanced Endpoint Assessment License’, this is the license’ you require for Cisco Secure Desktop. You can also use this license’ with the AnyConnect Mobile license’ for access from mobile devices like phones or tablets, (both these licenses are an additional purchase).
For most people wishing to buy extra AnyConnect licensing, this will be the one you want. Their type and size differ depending on the ASA platform in question, e.g. the 5505 premium licenses. are available as 10 session and 25 session licenses. the 5510 are in 10, 25, 50, 100 and 250 Sessions. (Note: These are correct for version 8.4 and are subject to change, check with your re seller).
Failover: If you are using failover firewalls you can (but don’t have to) use a shared license’ model, this lets you purchase a bundle of Premium licenses. and share them across multiple pieces of hardware, This requires an ASA to be setup as the license’ server’. Before version 8.3 you needed to purchase licenses for both firewalls. After version 8.3, Cisco allowed the licenses. to be replicated between firewalls in a failover pair. The exception is Active/Active where the amount of licenses. is aggregated together from both firewalls and ALL are available providing the figure does not exceed the maximum for the hardware being used.
Cisco ASA AnyConnect Essential Licenses
When you enable ‘Essential Licensing’, your firewall changes it’s licensing model and the two Premium licenses. you get with it are disabled*. The Firewall will then ONLY accept AnyConnect connections from the AnyConnect VPN client software.
Note: The portal still exists, but can only be used to download the AnyConnect Client Software.
With Essentials licensing enabled, the firewall will then accept the maximum VPN sessions it can support for that hardware version (see here), without the need to keep adding licenses.
Note: Remember these are “Peer VPN Sessions”. If you have a bunch of other VPN’s (including IPSEC ones), then these are taken from the ‘pot’.
Additionally, you can also use this license’ with the AnyConnect Mobile license’ for access from mobile devices like phones or tablets, this license’ is an additional purchase.
Failover: Prior to version 8.3, if you have failover firewalls and are using Essentials licenses you need to purchase an Essentials license’ for BOTH firewalls. After version 8.3 Cisco allowed the licenses. to be replicated between firewalls in a failover pair.
*To re-enable the built in Premium Licenses. you need to disable Essentials licensing by using the ‘no anyconnect-essentials” command or in the ASDM> Configuration > Remote Access VPN > Network (Client) Access > Advanced > AnyConnect Essentials.
Related Articles, References, Credits, or External Links