Requirement:
Aruba Controller should be running minimum AOS: 8.x or above
Solution:There are two types of License category
1. Sharable Licenses( AP, ACR, PEF, RF Protect, xSec, VMC, MM, WebCC)
2. Controller Specific License(PEFV)
Starting from 8.x all the Sharable License are installed on the Mobility Master(MM) and it acts as the License Server. The controller Specific License are installed on the respective Managed Device(MD).
From AOS: 8.x the feature MM remotely adding an MD’s box(Controller Specific) license to MD introduced when MD’s console access is blocked from configuration.
Controller Specific License:
The licenses which are applied only to the controller on which it is installed. It is not sharable through the centralized licensing feature. One of the Controller Specific License is PEFV
PEFV:
The Policy Enforcement Firewall for VPN users( PEFV ) license allows a network administrator to apply firewall policies to clients using a VPN to connect to the controller. This license is mandatory for the Aruba VIA VPN client, but optional for all other VPN clients. The PEFV license is purchased as a single license that enables the functionality up to the full user capacity of the controller.
Configuration:From Mobility Master
Syntax:
(Mobility Master) [mynode] #license remote ip-addr <MD ip address> add <License Key>
Example:
(Mobility Master) [mynode] #license remote ip-addr 10.16.10.33 add dZISoMMz-lZsTr0DR-5bTBubyp-mDhDm7hQ-ZLibcbqp-xc7mOZJG-C4Qt/UgJ-DKts3b6H-AJmbd5PL-+5g
Note: Please reload the respective managed device(MD) for the license to take effect after the installation of the License.
VerificationVerification From Mobility Master
(Mobility Master) [mynode] #show license remote ip-addr 10.16.10.33 verbose
License Table
-------------
Key Installed Expires(Grace period expiry) Flags Service Type
--- --------- ---------------------------- ----- ------------
dZISoMMz-lZsTr0DR-5bTBubyp-mDhDm7hQ-ZLibcbqp-xc7mOZJG-C4Qt/UgJ-DKts3b6H-AJmbd5PL-+5g 2017-01-12 22:57:10 Never ER Policy Enforcement Firewall for VPN users
D0KR0EBZ-I6nTQccx-QCWRwdgy-l48GnMkW-gOe83R5H-pQs1xPYN-dJ2NQgXX-RwMUfvJq-nctEU4j7-ZKY 2016-02-18 01:45:54 Never E X86 VM SKU Activate
License Entries: 2
Flags: A - auto-generated; E - enabled; S - Subscription; R - reboot/activation key required to activate; D - Not enabled on Local Controller
Note: Time under 'Installed' for Subscription licenses is the license generation time.
(Mobility Master) [mynode] #
After the reload of the respective Managed Device post License installation:
Verification for the respective Managed Device:
(MD-VMC-5) #show license
License Table
-------------
Key Installed Expires(Grace period expiry) Flags Service Type
--- --------- ---------------------------- ----- ------------
dZISoMMz-lZsTr0DR-5bTBubyp-mDhDm7hQ-ZLibcbqp-xc7mOZJG-C4Qt/UgJ-DKts3b6H-AJmbd5PL-+5g 2017-01-12 22:57:10 Never E Policy Enforcement Firewall for VPN users
D0KR0EBZ-I6nTQccx-QCWRwdgy-l48GnMkW-gOe83R5H-pQs1xPYN-dJ2NQgXX-RwMUfvJq-nctEU4j7-ZKY 2016-02-18 01:45:54 Never E X86 VM SKU Activate
License Entries: 2
Flags: A - auto-generated; E - enabled; S - Subscription; R - reboot/activation key required to activate; D - Not enabled on Local Controller
Note: Time under 'Installed' for Subscription licenses is the license generation time.
(MD-VMC-5) #