Mar 01, 2021 Move or Remove Licenses from FTD Devices. Use this procedure to manage licenses for Firepower Threat Defense devices managed by an Firepower Management Center. For example, you can move a license from one FTD device to another device registered to the same FMC, or to remove a license from a device. Cisco Firepower allows for feed based filtering of networks (IP addresses), as well as URLs, and DNS requests through security intelligence polices. From my understanding, network feeds when applied block traffic with the destination IP addresses, and DNS feeds inspect DNS requests inline and drop traffic to flagged domains. Cisco Firewall ASA-FTD-X License Part Number. Cisco ASA5516 FirePOWER AMP License: $0.00: L-ASA5516-URL: Cisco ASA5516 FirePOWER URL Filtering Service License. Also, you must purchase and enable an RA VPN license, any of the following: AnyConnect Plus, AnyConnect Apex, or AnyConnect VPN Only. These licenses are treated the same for FTD devices, although they are designed to allow different feature sets when used with ASA Software-based headends.
Applying a New Smart License to an FTD Device
Perform one of the following procedures to Smart License the Firepower Threat Defense (FTD) device:
- Smart license an FTD device when onboarding using a registration key.
- Smart license an FTD device after onboarding the device using a registration key or the administrator's credentials.
Note: The FTD device may be using a 90-day evaluation license, or the license could be unregistered.
Reimage ASA To FTD - Licensing - Cisco Community
FTDv Tiered Licenses in Version 7.0
Version 7.0 supports performance-tiered Smart Licensing for virtual FTD (FTDv) devices based on throughput requirements and RA VPN session limits. When the FTDv is licensed with one of the available performance licenses, two things occur: session limits for RA VPNs are determined by the installed FTDv platform entitlement tier, and enforced via a rate limiter.
CDO does not fully support tiered smart licensing at this time; see the following limitations:
- You cannot modify the tiered license through CDO. You must make the changes in the FDM UI. See Managing Smart Licenses for more information.
- If you register an FTDv to CDO for cloud services, the tiered license selection automatically resets to Variable, which is the default tier.
- If you onboard an FTDv running 7.0 and select a license that is not a default license during the onboarding process, the tiered license selection automatically resets to Variable, which is the default tier.
We strongly recommend selecting a tier for your FTDv license after onboarding your device to avoid the issues listed above.
Smart-License an FTD Device When Onboarding Using a Registration Key
Note: If you onboarded an FTDv running Version 7.0 and smart-licensed the device during the onboarding process, you must manually re-select the tiered-performance smart license in the FDM UI.
- Log on to the Cisco Smart Software Manager and generate a new Smart License key. Copy the newly generated key. You can watch the Generate Smart Licensing video for more information.
- Begin onboarding an FTD using a registration key. For more information, see Onboard an FTD Running Software Version 6.6+ Using a Registration Key or Onboard an FTD Running Software Version 6.4 or 6.5 Using a Registration Key.
- In step 4 of the onboarding wizard, in the Smart License here box, paste the Smart License in the Activate field and click Next.
- Click Go to devices page to go to the Devices & Services page and see the progress of the onboarding process.
The device starts synchronizing and applies the Smart License. - Open the Devices & Services page. You should see that the device is now in the Online connectivity state.
If the device is not in the online connectivity state, look in the Device Actions pane on the right and clickManage Licenses > Refresh Licenses to update the connectivity state.
See More Results
- After applying the Smart License successfully to the FTD device, click the Manage Licenses. The device status shows 'Connected, Sufficient License.' You can enable or disable the optional licenses. For more information, see FTD Smart Licensing Types.
Smart-License an FTD Device After Onboarding the Device Using a Registration Key or its Credentials
- In the navigation pane, click Devices & Services and select the FTD device that you want to license.
- In the Device Actions pane on the right, click Manage Licenses.
- Follow the on-screen instructions and enter the Smart License generated from Cisco Smart Software Manager.
- Paste the new license key in the box and click Register Device. After synchronizing with the device, the connectivity state changes to 'Online'.
After applying the Smart License successfully to the FTD device, the device status shows 'Connected, Sufficient License.' You can enable or disable the optional licenses. For more information, see FTD Smart Licensing Types.
Note: If you onboarded an FTDv running Version 7.0 and smart-licensed the device during the onboarding process, you must manually re-select the tiered-performance smart license in the FDM UI.