SlideShare a Scribd company logo
Updated: About Cisco ISR G2 SEC and HSEC Licensing FAQ
We discussed the main difference between SEC-K9 license and HSEC-
k9 license. What are the Cisco ISR G2 SEC and HSEC License used for?
The SEC-K9 license enables standard encryption (VPN payload and secure
voice) on the ISR G2 platforms. The SEC-K9 license is designed to comply
with both local and U.S. export requirements for global distribution to all
countries. This license enforces a curtailment on the maximum number of
encrypted tunnels and the maximum encrypted throughput on the ISR G2
platforms.
The HSEC-K9 license removes the curtailment enforced by the U.S.
government export restrictions on the encrypted tunnel count and encrypted
throughput. HSEC-K9 is available only on the Cisco 2921, Cisco 2951,
Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. With the HSEC-
K9 license, the ISR G2 router can go over the curtailment limit of 225 tunnels
maximum for IP Security (IPsec) and encrypted throughput of 85 -Mbps
unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of
170 Mbps.
The Cisco 1941, 2901, and 2911 already have maximum encryption capacities
within export limits.
Now, in this article, we will discuss the in the context of the security licensing
and export restrictions, a tunnel is a construct established between two
routers (peers) to transport insecure payloads using data-encryption
techniques.
Firstly you can read some general Qs about the security licensing and export
restrictions.
The SEC-K9 license limits the number of concurrent encrypted sessions and
maximum encrypted throughput per device. This limit helps ensure that the
ISR G2 complies with U. S. government export restrictions regardless of the
final destination country.
The SEC-K9 permanent licenses apply to the Cisco 1900, 2900, and 3900
ISR G2 platforms; these licenses limit all encrypted tunnel counts to 225
tunnels maximum for IP Security (IPsec), Secure Sockets Layer VPN (SSL
VPN), a secure time-division multiplexing (TDM) gateway, and secure Cisco
Unified Border Element (CUBE) and 1000 tunnels for Transport Layer Security
(TLS) sessions.
The SEC-K9 license limits encrypted throughput to less than or equal to 85-
Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional
total of 170 Mbps. This requirement applies for the Cisco 1900, 2900, and
3900 ISR G2 platforms.
All threat defense and VPN features that are supported on the Cisco ISR G2
routers are functionally available for configuration with the SEC-K9. The
image that includes this license is the universal -k9 image. For example, the
Cisco IOS release version is c3900-universalk9-mz.SPA.150-1.M1.
Q. Does the router require a reload after installing the SEC-K9 or the
HSEC-K9 license?
A. Reload is needed only for technology package licenses such as datak9,
uck9, and securityk9/securityk9_npe. Installing the SEC-K9 or the HSEC-K9
license does not require a reload. Also, moving from a temporary license to a
permanent license does not require a reload.
Q. Why do I need to purchase the SEC-K9 license as a spare?
A. If you purchase a Cisco ISR G2 chassis and later decide to turn on security
features, you must buy a SEC-K9 license. The administrator must download
the license to the router and follow the license installation instructions that
come with the license to be able to use the security features on the router.
Q. What information do I need to order either the SEC-K9 or the
HSEC-K9 license as a spare for my ISR G2 router?
A. To order the licenses as spares, you need the output of the following
command-line interface (CLI) command: show license udi, shown at the
end of this section. You must enter the product ID (PID) and the serial
number into the tool to complete the order. This information makes the
license unique for a particular router, and the license is not transferrable
between routers.
The command output follows:
3925-perf#sh license udi
Device# PID SN UDI
-----------------------------------------------------------------------------
*0 C3900-SPE100/K9 FOC133037J9 C3900-SPE100/K9:FOC133037J9
For more information about software license activation on the ISR G2
platforms, please
visit:http://www.cisco.com/en/US/docs/routers/access/sw_activation/SA_on_I
SR.html.
Q. What features does the npe-k9 image support?
A. The SECNPE image supports Cisco IOS Firewall, Integrated Protection
Services (IPS), and URL Filtering (basically all the threat-defense functions).
Standard encryption features are not supported on the ISR G2 platforms with
this image.
…
More Examples of installing a HSEC license from users and the rules for
ordering you can read the full FAQ information here
http://www.cisco.com/c/en/us/products/collateral/routers/3900-series-
integrated-services-routers-isr/q-and-a-c67-606268.html
More Related
Cisco SEC-K9 License vs. HSEC-K9 License
Cisco Licenses on Cisco ISR G2
Cisco Licenses on Cisco ISR G2
General Features of Cisco ASA Licensing
How to Activate a Cisco License?
Cisco 800 Series Licensing Options

More Related Content

PPT
Icnd210 s07l01
PPT
Icnd210 s02l04
PPT
Icnd210 s07l02
PPT
Icnd210 s01l01
PPT
Icnd210 s04l01
PPT
CCNA Icnd110 s04l10
PPT
Icnd210 s02l02
PPT
Icnd210 s07l03
Icnd210 s07l01
Icnd210 s02l04
Icnd210 s07l02
Icnd210 s01l01
Icnd210 s04l01
CCNA Icnd110 s04l10
Icnd210 s02l02
Icnd210 s07l03

What's hot (20)

PPT
CCNA Icnd110 s06l02
PPT
Icnd210 s02l03
PPT
Icnd210 s04l02
PPT
Icnd210 s02l01
PPT
Eigrp authentication
PPT
Icnd210 s08l04
PPT
Icnd210 s06l01
PPT
Icnd210 s08l03
PPT
CCNA Icnd110 s05l01
PPT
Icnd210 s08l05
PDF
520scg basic
PPT
CCNA Icnd110 s06l01
PPT
Icnd210 s06l02
PPT
Icnd210 s03l02
PPT
CCNA Icnd110 s04l07
PPT
Icnd210 s05l02
PPTX
CCNA 2 Routing and Switching v5.0 Chapter 9
PPT
CCNA Icnd110 s02l04
PPT
Icnd210 s08l01
PPT
CCNA Icnd110 s04l08
CCNA Icnd110 s06l02
Icnd210 s02l03
Icnd210 s04l02
Icnd210 s02l01
Eigrp authentication
Icnd210 s08l04
Icnd210 s06l01
Icnd210 s08l03
CCNA Icnd110 s05l01
Icnd210 s08l05
520scg basic
CCNA Icnd110 s06l01
Icnd210 s06l02
Icnd210 s03l02
CCNA Icnd110 s04l07
Icnd210 s05l02
CCNA 2 Routing and Switching v5.0 Chapter 9
CCNA Icnd110 s02l04
Icnd210 s08l01
CCNA Icnd110 s04l08
Ad

Viewers also liked (14)

DOCX
Ip phone boot up process
PDF
Cisco trouble shooting
DOCX
Definitely, cisco mobility express solution eases your wi fi deployments solu...
PDF
Cisco identity services engine (ise) ordering steps & guide
DOCX
Huawei s5700 ei in network--sample deployments
DOCX
How to recover password on the cisco catalyst fixed configuration layer 2&lay...
DOCX
Implementation of cisco wireless lan controller (multiple wla ns)
DOCX
Line cards that are available for cisco catalyst 4500 series switches
DOCX
Limited time 'countdown deals' on cisco items
DOCX
A new featured product cisco ie4010 series switches
DOCX
The new isr 4221, the new cisco dna ready platform
DOCX
Sample deployments the ar3200 series
DOCX
The latest isr 4000 model comparison
DOCX
Cisco one advanced security
Ip phone boot up process
Cisco trouble shooting
Definitely, cisco mobility express solution eases your wi fi deployments solu...
Cisco identity services engine (ise) ordering steps & guide
Huawei s5700 ei in network--sample deployments
How to recover password on the cisco catalyst fixed configuration layer 2&lay...
Implementation of cisco wireless lan controller (multiple wla ns)
Line cards that are available for cisco catalyst 4500 series switches
Limited time 'countdown deals' on cisco items
A new featured product cisco ie4010 series switches
The new isr 4221, the new cisco dna ready platform
Sample deployments the ar3200 series
The latest isr 4000 model comparison
Cisco one advanced security
Ad

Similar to Updated about cisco isr g2 sec and hsec licensing faq (9)

PDF
cisco-sl-4330-sec-k9-datasheet.pdf
DOCX
Cisco isr 900 series highlights, platform specs, licenses, transition guide
PDF
ROUTER Cisco 1921- HOJA TECNICA DE FABRICA
PDF
cisco-c881-k9-datasheet.pdf
PDF
cisco-l-sl-44-app-k9=-datasheet.pdf
PDF
C1111-8P Datasheet
PDF
Cisco 900 Series Integrated Services Routers Datasheet
DOCX
Cisco 1921 review why take it into top list while selecting cisco routers
PDF
BRKARC-2881.pdf
cisco-sl-4330-sec-k9-datasheet.pdf
Cisco isr 900 series highlights, platform specs, licenses, transition guide
ROUTER Cisco 1921- HOJA TECNICA DE FABRICA
cisco-c881-k9-datasheet.pdf
cisco-l-sl-44-app-k9=-datasheet.pdf
C1111-8P Datasheet
Cisco 900 Series Integrated Services Routers Datasheet
Cisco 1921 review why take it into top list while selecting cisco routers
BRKARC-2881.pdf

More from IT Tech (20)

DOCX
Cisco ip phone key expansion module setup
DOCX
Cisco catalyst 9200 series platform spec, licenses, transition guide
DOCX
Hpe pro liant gen9 to gen10 server transition guide
DOCX
The new cisco isr 4461 faq
DOCX
New nexus 400 gigabit ethernet (400 g) switches
DOCX
Tested cisco isr 1100 delivers the richest set of wi-fi features
DOCX
Aruba campus and branch switching solution
DOCX
Cisco transceiver module for compatible catalyst switches
DOCX
Cisco ios on cisco catalyst switches
DOCX
Cisco's wireless solutions deployment modes
DOCX
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
DOCX
Four reasons to consider the all in-one isr 1000
DOCX
The difference between yellow and white labeled ports on a nexus 2300 series fex
DOCX
Cisco transceiver modules for compatible cisco switches series
DOCX
Guide to the new cisco firepower 2100 series
DOCX
892 f sfp configuration example
DOCX
Cisco nexus 7000 and nexus 7700
DOCX
Cisco firepower ngips series migration options
DOCX
Eol transceiver to replacement model
DOCX
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco ip phone key expansion module setup
Cisco catalyst 9200 series platform spec, licenses, transition guide
Hpe pro liant gen9 to gen10 server transition guide
The new cisco isr 4461 faq
New nexus 400 gigabit ethernet (400 g) switches
Tested cisco isr 1100 delivers the richest set of wi-fi features
Aruba campus and branch switching solution
Cisco transceiver module for compatible catalyst switches
Cisco ios on cisco catalyst switches
Cisco's wireless solutions deployment modes
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
Four reasons to consider the all in-one isr 1000
The difference between yellow and white labeled ports on a nexus 2300 series fex
Cisco transceiver modules for compatible cisco switches series
Guide to the new cisco firepower 2100 series
892 f sfp configuration example
Cisco nexus 7000 and nexus 7700
Cisco firepower ngips series migration options
Eol transceiver to replacement model
Cisco firepower 2100 series, as a ngfw or a ngips

Recently uploaded (20)

PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PDF
Sims 4 Historia para lo sims 4 para jugar
PDF
Cloud-Scale Log Monitoring _ Datadog.pdf
PPTX
SAP Ariba Sourcing PPT for learning material
PPTX
international classification of diseases ICD-10 review PPT.pptx
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PDF
The Internet -By the Numbers, Sri Lanka Edition
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PPTX
artificial intelligence overview of it and more
PPTX
Introduction to Information and Communication Technology
PPTX
Introuction about WHO-FIC in ICD-10.pptx
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
Decoding a Decade: 10 Years of Applied CTI Discipline
Job_Card_System_Styled_lorem_ipsum_.pptx
Sims 4 Historia para lo sims 4 para jugar
Cloud-Scale Log Monitoring _ Datadog.pdf
SAP Ariba Sourcing PPT for learning material
international classification of diseases ICD-10 review PPT.pptx
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
Power Point - Lesson 3_2.pptx grad school presentation
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
The Internet -By the Numbers, Sri Lanka Edition
Introuction about ICD -10 and ICD-11 PPT.pptx
PptxGenJS_Demo_Chart_20250317130215833.pptx
artificial intelligence overview of it and more
Introduction to Information and Communication Technology
Introuction about WHO-FIC in ICD-10.pptx
The New Creative Director: How AI Tools for Social Media Content Creation Are...
RPKI Status Update, presented by Makito Lay at IDNOG 10
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰

Updated about cisco isr g2 sec and hsec licensing faq

  • 1. Updated: About Cisco ISR G2 SEC and HSEC Licensing FAQ We discussed the main difference between SEC-K9 license and HSEC- k9 license. What are the Cisco ISR G2 SEC and HSEC License used for? The SEC-K9 license enables standard encryption (VPN payload and secure voice) on the ISR G2 platforms. The SEC-K9 license is designed to comply with both local and U.S. export requirements for global distribution to all countries. This license enforces a curtailment on the maximum number of encrypted tunnels and the maximum encrypted throughput on the ISR G2 platforms. The HSEC-K9 license removes the curtailment enforced by the U.S. government export restrictions on the encrypted tunnel count and encrypted throughput. HSEC-K9 is available only on the Cisco 2921, Cisco 2951, Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. With the HSEC- K9 license, the ISR G2 router can go over the curtailment limit of 225 tunnels maximum for IP Security (IPsec) and encrypted throughput of 85 -Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of 170 Mbps. The Cisco 1941, 2901, and 2911 already have maximum encryption capacities within export limits. Now, in this article, we will discuss the in the context of the security licensing and export restrictions, a tunnel is a construct established between two routers (peers) to transport insecure payloads using data-encryption techniques. Firstly you can read some general Qs about the security licensing and export restrictions.
  • 2. The SEC-K9 license limits the number of concurrent encrypted sessions and maximum encrypted throughput per device. This limit helps ensure that the ISR G2 complies with U. S. government export restrictions regardless of the final destination country. The SEC-K9 permanent licenses apply to the Cisco 1900, 2900, and 3900 ISR G2 platforms; these licenses limit all encrypted tunnel counts to 225 tunnels maximum for IP Security (IPsec), Secure Sockets Layer VPN (SSL VPN), a secure time-division multiplexing (TDM) gateway, and secure Cisco Unified Border Element (CUBE) and 1000 tunnels for Transport Layer Security (TLS) sessions. The SEC-K9 license limits encrypted throughput to less than or equal to 85- Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of 170 Mbps. This requirement applies for the Cisco 1900, 2900, and 3900 ISR G2 platforms. All threat defense and VPN features that are supported on the Cisco ISR G2 routers are functionally available for configuration with the SEC-K9. The
  • 3. image that includes this license is the universal -k9 image. For example, the Cisco IOS release version is c3900-universalk9-mz.SPA.150-1.M1. Q. Does the router require a reload after installing the SEC-K9 or the HSEC-K9 license? A. Reload is needed only for technology package licenses such as datak9, uck9, and securityk9/securityk9_npe. Installing the SEC-K9 or the HSEC-K9 license does not require a reload. Also, moving from a temporary license to a permanent license does not require a reload. Q. Why do I need to purchase the SEC-K9 license as a spare? A. If you purchase a Cisco ISR G2 chassis and later decide to turn on security features, you must buy a SEC-K9 license. The administrator must download the license to the router and follow the license installation instructions that come with the license to be able to use the security features on the router. Q. What information do I need to order either the SEC-K9 or the HSEC-K9 license as a spare for my ISR G2 router? A. To order the licenses as spares, you need the output of the following command-line interface (CLI) command: show license udi, shown at the end of this section. You must enter the product ID (PID) and the serial number into the tool to complete the order. This information makes the license unique for a particular router, and the license is not transferrable between routers. The command output follows: 3925-perf#sh license udi Device# PID SN UDI ----------------------------------------------------------------------------- *0 C3900-SPE100/K9 FOC133037J9 C3900-SPE100/K9:FOC133037J9 For more information about software license activation on the ISR G2 platforms, please visit:http://www.cisco.com/en/US/docs/routers/access/sw_activation/SA_on_I SR.html.
  • 4. Q. What features does the npe-k9 image support? A. The SECNPE image supports Cisco IOS Firewall, Integrated Protection Services (IPS), and URL Filtering (basically all the threat-defense functions). Standard encryption features are not supported on the ISR G2 platforms with this image. … More Examples of installing a HSEC license from users and the rules for ordering you can read the full FAQ information here http://www.cisco.com/c/en/us/products/collateral/routers/3900-series- integrated-services-routers-isr/q-and-a-c67-606268.html More Related Cisco SEC-K9 License vs. HSEC-K9 License Cisco Licenses on Cisco ISR G2 Cisco Licenses on Cisco ISR G2 General Features of Cisco ASA Licensing How to Activate a Cisco License? Cisco 800 Series Licensing Options