Configuration Guide for Cisco NCS 1004, IOS XR Release 25.x.x

PDF

Configuration Guide for Cisco NCS 1004, IOS XR Release 25.x.x

Configure smart licensing

Want to summarize with AI?

Log in

Configure smart licensing on Cisco NCS 1004 by setting up the DNS server, CiscoTAC-1 Smart Call Home profile, an optional crypto trustpoint, and registering the device with a token.


Enable smart license management on your Cisco NCS 1004 by connecting the device to Cisco Smart Licensing services.

Smart licensing automates license activation and compliance, helping you centrally manage device licenses.

To configure smart licensing in Cisco NCS 1004, perform these tasks:

Procedure

1.

Configure the domain name server for the smart license server.

Example:

RP/0/RP0/CPU0:ios#configure 
Sat Dec 15 15:25:14.385 IST
RP/0/RP0/CPU0:ios(config)#domain name-server 198.51.100.247
2.

Setup the CiscoTAC-1 profile and destination address for Smart Call Home, using these commands:

call-home

service active

contact smart-licensing

profile CiscoTAC-1

active

destination address http {http|https}://{FQDN}/its/service/oddce/services/DDCEService

destination transport-method http

Note

The destination address must be the fully qualified domain name (FQDN) of the Cisco Smart Software Manager (tools.cisco.com) or your Smart Licensing satellite server. Configure the DNS server before setting up the call-home destination. The CiscoTAC-1 profile is the default for smart licensing and must not be deleted.

Example:

RP/0/RP0/CPU0:ios#configure 
Sat Dec 15 15:25:14.385 IST
RP/0/RP0/CPU0:ios(config)#domain name-server 198.51.100.247
RP/0/RP0/CPU0:ios(config)#call-home
 RP/0/RP0/CPU0:ios(config)#service active
 RP/0/RP0/CPU0:ios(config)#contact smart-licensing
 RP/0/RP0/CPU0:ios(config)#profile CiscoTAC-1
 RP/0/RP0/CPU0:ios(config)#active
 RP/0/RP0/CPU0:ios(config)#destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
 RP/0/RP0/CPU0:ios(config)#destination transport-method http

]
3.

Configure the crypto ca Trust point profile, if CRL distribution point is not defined in the Satellite server certificate or if the device is not able to reach the host mentioned in the CRL distribution point.

Example:

RP/0/RP0/CPU0:ios(config)#crypto ca trustpoint Trustpool crl optional
4.

Create and copy the registration token ID using Cisco Smart Software Manager.

For more details about creating a token, see Create a token.

5.

Use the license smart register idtoken token-ID in the privileged EXEC mode, to register the token ID in Cisco NCS 1004.

If registration fails due to communication issues, wait 24 hours for the device to retry or force the registration using the license smart register idtoken token-ID force command.

If the device is removed from inventory, redeployed, or returned to Cisco using Return Merchandise Authorization (RMA), cancel registration and remove entitlements, using the license smart deregister command to cancel the registration on your device. All smart licensing entitlements and certificates on the platform are removed.

ID certificates are renewed automatically after six months. In case, the renewal fails, the product instance goes into unidentified state. You can manually renew the ID certificate using the license smart renew id command.

Authorization periods are renewed by the Smart Licensing system every 30 days. As long as the license is in an 'Authorized' or 'Out-of-Compliance' (OOC), the authorization period is renewed. Use the license smart renew auth command to make an on-demand manual update of your registration. Thus, instead of waiting 30 days for the next registration renewal cycle, you can issue this command to instantly find out the status of your license.

After 90 days, the authorization period expires and the status of the associated licenses display "AUTH EXPIRED". Use the license smart renew auth command to retry the authorization period renewal. If the retry is successful, a new authorization period begins.

The Cisco NCS 1004 is registered with Cisco Smart Licensing, license entitlements are tracked automatically, and compliance is maintained.

Verify smart licensing configuration

This reference enables you to verify smart licensing configuration on Cisco NCS 1004 by listing the supported show commands, describing each license authorization status, and providing sample command outputs for confirmation.

After enabling smart licensing, you can use the show commands to verify the default smart licensing configuration. If any issue is detected, take corrective action before making further configurations.

  • show license all

  • show license trace all

  • show license status

  • show license summary

  • show license tech

  • show license udi

  • show license usage

  • show license platform detail

  • show license platform summary

  • show license platform trace

  • show license platform trace all

  • show tech-support smartlic

  • show call-home detail

  • show call-home trace all

  • show tech-support call-home

This table defines the available license authorization status in Cisco NCS 1004:

Table 1. License Authorization Status

License Authorization Status

Description

Unconfigured

Smart Software Licensing is not configured.

Unidentified

Smart Software Licensing is enabled but is not registered.

Registered

Device registration is completed and an ID certificate is received that is used for future communication with the Cisco licensing authority.

Authorized

Registration is completed with a valid Smart Account and license consumption has begun. This indicates compliance.

Out of Compliance

Consumption exceeds available licenses in the Smart Account.

Authorization Expired

The device is unable to communicate with the Cisco Smart Software Manager for an extended period. This state occurs after 90 days of expiry. The device attempts to contact the CSSM every hour to renew the authorization until the registration period expires.

Example 1: show license all

The following example shows the sample output of the show license all command.


RP/0/RP0/CPU0:SIT-5#show license all
Wed Sep 22 17:18:19.761 IST

Smart Licensing Status
======================

Smart Licensing is ENABLED

Registration:
  Status: REGISTERED
  Smart Account: BU Production Test
  Virtual Account: NCS1000
  Export-Controlled Functionality: ALLOWED
  Initial Registration: SUCCEEDED on Jun 21 2021 12:40:52 IST
  Last Renewal Attempt: None
  Next Renewal Attempt: Dec 18 2021 12:40:51 IST
  Registration Expires: Jun 21 2022 12:35:49 IST

License Authorization:
  Status: AUTHORIZED on Sep 09 2021 11:45:43 IST
  Last Communication Attempt: SUCCEEDED on Sep 09 2021 11:45:43 IST
  Next Communication Attempt: Oct 09 2021 11:45:42 IST
  Communication Deadline: Dec 08 2021 11:40:41 IST

Export Authorization Key:
  Features Authorized:
    <none>

Utility:
  Status: DISABLED

Data Privacy:
  Sending Hostname: yes
    Callhome hostname privacy: DISABLED
    Smart Licensing hostname privacy: DISABLED
  Version privacy: DISABLED

Transport:
  Type: Callhome

Miscellaneus:
  Custom Id: <empty>

License Usage
==============

NCS1K4 - Subsea - 1.2T Line Card (S_NCS1K4_SUBSEA):
  Description: NCS1K4 - Subsea - 1.2T Line Card
  Count: 3
  Version: 1.0
  Status: AUTHORIZED
  Export status: NOT RESTRICTED

NCS1K4 smart license - one QSFP28 client (S-NCS1K4-LIC-100G=):
  Description: NCS1K4 smart license - one QSFP28 client
  Count: 18
  Version: 1.0
  Status: AUTHORIZED
  Export status: NOT RESTRICTED

NCS1K4 smart license - one QSFP28 client with encryption (S-NCS1K4-LIC-100X=):
  Description: NCS1K4 smart license - one QSFP28 client with encryption
  Count: 2
  Version: 1.0
  Status: AUTHORIZED
  Export status: NOT RESTRICTED

NCS1K4 - Long Haul - 1.2T Line Card (S_NCS1K4_LONGHAUL):
  Description: NCS1K4 - Long Haul - 1.2T Line Card
  Count: 2
  Version: 1.0
  Status: AUTHORIZED
  Export status: NOT RESTRICTED

Product Information
===================
UDI: SN:CAT2249B009,UUID:default-sdr

Agent Version
=============
Smart Agent for Licensing: 4.13.32_rel/85

Reservation Info
================
License reservation: DISABLED

Example 2: show license platform detail

The following example shows the sample output of the show license platform detail command.


RP/0/RP0/CPU0:ios#show license platform detail
Mon Feb 11 15:59:55.422 IST
Current state:    REGISTERED

Collection: LAST: Mon Feb 11 2019 15:57:53 IST
            NEXT: Mon Feb 11 2019 16:57:53 IST
Reporting:  LAST: Mon Feb 11 2019 15:57:53 IST
            NEXT: Tue Feb 12 2019 15:57:53 IST

Parameters: Collection interval:          60 minute(s)
            Reporting  interval:        1440 minute(s)
            Throughput gauge:        1000000 Kbps

=================================================
Feature/Area 'system'
   Name:  System
   Status:   ACTIVE
   Flags: CONFIG

   [ 1] Name:  NCS1K4 smart license - one QSFP28 client
        Entitlement Tag: regid.2018-05.com.cisco.S-NCS1K4-LIC-100G=,1.0_03df009f-5ac5-48da-af50-4279ddea5e24
        Count: Last reported:    8
               Next report:      0
   [ 2] Name:  NCS1K4 smart license - one QSFP28 client with encryption
        Entitlement Tag: regid.2018-05.com.cisco.S-NCS1K4-LIC-100X=,1.0_3938b0c5-f635-4426-9f0f-936d930cea9e
        Count: Last reported:    8
               Next report:      0

Example 3: show license status

The following example shows the sample output of the show license status command.


RP/0/RP0/CPU0:ios#show license status
Mon Feb 11 16:02:24.499 IST

Smart Licensing is ENABLED
  Initial Registration: SUCCEEDED on Mon Feb 11 2019 15:51:10 IST
  Last Renewal Attempt: None
  Next Renewal Attempt: Sat Aug 10 2019 15:52:10 IST
  Registration Expires: Tue Feb 11 2020 15:46:59 IST

License Authorization:
  Status: AUTHORIZED on Mon Feb 11 2019 15:53:40 IST
  Last Communication Attempt: SUCCEEDED on Mon Feb 11 2019 15:53:40 IST
  Next Communication Attempt: Wed Mar 13 2019 15:53:39 IST
  Communication Deadline: Sun May 12 2019 15:47:29 IST

Example 4: show license usage

The following example shows the sample output of the show license usage command.

RP/0/RP0/CPU0:ios#show license usage
Mon Feb 11 15:59:29.817 IST

License Authorization:
  Status: AUTHORIZED on Mon Feb 11 2019 15:53:40 IST

NCS1K4 smart license - one QSFP28 client (S-NCS1K4-LIC-100G=):
  Description: NCS1K4 smart license - one QSFP28 client
  Count: 8
  Version: 1.0
  Status: AUTHORIZED

NCS1K4 smart license - one QSFP28 client with encryption (S-NCS1K4-LIC-100X=):
  Description: NCS1K4 smart license - one QSFP28 client with encryption
 Count: 8
  Version: 1.0
  Status: AUTHORIZED

Example 5: show license udi

The following example shows the sample output of the show license udi command.


RP/0/RP0/CPU0:ios#show license udiMon Feb 11 16:02:46.733 IST

Product Information
===================
UDI: SN:CAT2231B18Y,UUID:default-sdr

Criteria for license consumption of subsea networks

A subsea license is a trunk-based smart license model that

  • is consumed on Cisco NCS 1004 whenever specified subsea trunk-port configurations, bits-per-symbol values, or chromatic dispersion ranges exist in the running configuration,
  • supports tracking license status and software usage trends for subsea deployments, and
  • allows access to subsea-specific controls such as extended chromatic dispersion and advanced compensation settings.
Table 2. Feature History

Feature Name

Release Information

Feature Description

Licensing Feature Update Cisco IOS XR Release 7.3.2

Criteria for license consumption in Long Haul and Subsea networks are introduced. Long Haul (LH) and Subsea are two trunk-based license models that are implemented regardless of the line rate, in addition to the existing client-based licenses. These license models allow the user to easily track the status of licenses and software usage trends. The long-haul license is required to enable QPSK and 8QAM modes. The subsea license is required to enable BPSK and subsea specific controls such as extended chromatic dispersion, special non-linear compensation settings and so on.

Criteria for license consumption

The criteria for license consumption of subsea networks are as follows:

  • If any of the following trunk-port configurations appear in the running configuration, the subsea license is consumed:

    • Ios(config-optics)#filter-roll-off-factor <0-1>
    • Ios(config-optics)#rx-voa target-power <-190,+30>
    • Ios(config-optics)#rx-voa fixed-ratio <+100,+1700>
    • Ios(config-optics)#enh-colorless-mode <1-3>
    • Ios(config-optics)#enh-sop-tol-mode <1-3>
    • Ios(config-optics)#nleq-comp-mode <1-4>
    • Ios(config-optics)#cross-pol-gain-mode <1-15>
    • Ios(config-optics)#cross-pol-weight-mode <1-7>
    • Ios(config-optics)#cpr-win-mode <1-15>
    • Ios(config-optics)#cpr-ext-win-mode <1-15>
  • The license is consumed if the bps value is in the range of 1–2 bits per symbol or 1, excluding the boundary value of 2 in the following command:

    show controller optics <trunk-port>
  • The license is consumed if the cd-min value is less than -10000 or cd-max value is greater than 100000, excluding the boundary values in the output of the following command:

    show controller optics <trunk-port>

Example for license consumption

The following output of show license usage command shows the license usage count as one.

RP/0/RP0/CPU0:BH-SIT2#show license usage
Tue Aug  3 11:12:42.440 IST
License Authorization:
Status: AUTHORIZED on Aug 03 2021 11:10:12 IST
NCS1K4 - Subsea - 1.2T Line Card (S_NCS1K4_SUBSEA):
Description: NCS1K4 - Subsea - 1.2T Line Card
Count: 1
Version: 1.0
Status: AUTHORIZED
Export status: NOT RESTRICTED

Criteria for license consumption of long-haul networks

The long-haul smart license is consumed on Cisco NCS 1004 when the bits-per-symbol value reported by the trunk controller falls within the qualifying range, and the license remains consumed while the line card is up.

Long-haul license consumption criteria

The smart license is consumed if the bps value is in the range of 2 - 4 bits per symbol including the boundary values in the output of the following command:

show controller optics 0/1/0/1

Example:

show controller optics 0/1/0/1 Bits per symbol = 3.0000000000 bits/symbol

In the above example, the bits per symbol value is 3, so the license is consumed.

Note
  • The license is consumed even when the trunk port is in shutdown state.

  • The license is consumed only when the line card is up and running.

Example for license consumption

The following output of show license usage command shows the license usage count as two:

RP/0/RP0/CPU0:SIT-4#show license usage
Tue Aug 3 15:53:48.453 IST
License Authorization:
NCS1K4 - Long Haul - 1.2T Line Card (S_NCS1K4_LONGHAUL):
Description: NCS1K4 - Long Haul - 1.2T Line Card
Count: 2
Version: 1.0
Status: AUTHORIZED
Export status: NOT RESTRICTED

Register a smart license on Cisco NCS 1004

Enable smart license functionality on Cisco NCS 1004 and maintain licensing compliance via Cisco Smart Software Manager (CSSM).

Use this process to register a smart license for your Cisco NCS 1004 device, address synchronization issues between the device and CSSM, and perform license renewal and deregistration when needed.

Procedure

1.

Register the license using the license smart register idtoken <idtoken> command:

RP/0/RP0/CPU:ios#license smart register idtoken <idtoken>
2.

Access the Cisco Smart Software Manager portal, https://software.cisco.com/software/csws/ws/platform/home#module/SmartLicensing.

3.

Remove the existing product instance in CSSM:

  1. Click Inventory.

  2. Click Product Instances.

  3. Select the node instance.

  4. Click Actions, and then Remove.

4.

Renew the authorization period on the device.

RP/0/RP0/CPU0:ios#license smart renew auth
RP/0/RP0/CPU0:ios#show logging | i "Data and signature"
Thu May 27 09:57:02.237 UTC
RP/0/RP0/CPU0:May 27 09:54:57.783 UTC: smartlicserver[311]: 
LICENSE-SMART_LIC-3-AUTH_RENEW_FAILED : Authorization renewal with the Cisco Smart Software Manager (CSSM) : 
Error received from Smart Software Manager: Data and signature do not match  for udi PID:8812,SN:FOX2202WIVM 
Note

The error message in the output of the show logging command is expected and is due to loss of synchronization between the CSSM server and the device after removing the product instance directly from the CSSM server.

5.

Deregister the device from CSSM.

RP/0/RP0/CPU0:ios#license smart deregister
RP/0/RP0/CPU0:ios#show logging | i DEREG
Thu May 27 14:48:58.170 UTC
RP/0/RP0/CPU0:May 27 09:58:58.464 UTC: smartlicserver[311]: 
%LICENSE-SMART_LIC-3-AGENT_DEREG_FAILED : Smart Agent for Licensing DeRegistration with Cisco Smart Software Manager (CSSM) failed: 
Agent received a failure status in a response message. Please check the Agent log file for the detailed message. 
Note

The error message in the output of the show logging command is expected.

The Cisco NCS 1004 device is registered, synchronized, and deregistered as needed with CSSM. Expected error messages confirm the resolution of device and CSSM synchronization issues.