Licensing description
General description
The NAICE network access control system is distributed under a commercial license. This means that access to the system functionality requires purchasing and activating a license.
Licensing may be performed using one of the following models:
Using the Eltex License Manager server (ELM), which provides licensing for software and hardware products of Eltex. This model requires periodic communication with the license server. It may use:
the Eltex license server (hereinafter referred to as Online ELM). No additional software installation is required. The centralized license server is available at
https://elm.eltex-co.ru:8099, and network access to this address must be ensured. Connection to the ELM license server via an HTTP proxy is supported (HTTPS proxy is not supported);an ELM server deployed within the customer’s infrastructure (hereinafter referred to as Offline ELM).
In both cases, the ELM server address is specified in the system settings (for details, see v1.2_5.1. System settings) and must be accessible at the time of license activation. Operation with the ELM server via an HTTP proxy is supported (with login/password authentication or without authentication).
File-based licensing (hereinafter referred to as PLR — Persistent License Reservation) — a licensing model tied to the physical parameters of the host on which NAICE is installed. If the host parameters are changed, re-activation is required. This model is also suitable for operation in isolated environments. For more information, see v1.2_2.1 File-based licensing (PLR).
After installation, NAICE operates in demonstration mode with limited functionality. The limitations of demonstration mode are described below.
Upon purchasing access to a specific licensing level, a product key file is generated, unique for each NAICE instance. To unlock the NAICE functionality corresponding to the purchased license, the file must be uploaded and activated on the Licensing page. For a PLR license, after uploading the product key file, the customer will receive a license activation file, which must be sent to Eltex via their sales manager. After processing, the license will be activated and provided to the customer.
After successful upload of the activation file, access to the product functionality corresponding to the license level will be granted.
License levels
The set of functional capabilities provided by a license is divided into levels. This allows access only to the functionality actually required, without increasing costs for features that are not needed.
In the current version, two licensing levels are implemented — BASIC and ADVANCED.
BASIC
At this level, upon license activation, access is granted to the basic NAICE functionality and its primary service — endpoint authorization. An endpoint, hereinafter, refers to a client device that connects to the network via an authenticator device and undergoes authentication and authorization. Examples of endpoints include a personal computer, laptop, smartphone, IP phone, IP camera, etc.
At this level, the licensed parameter is the number of successfully authorized unique endpoints. This parameter determines how many unique client devices can be authorized in the system simultaneously. The calculation is performed as follows:
- The counter of connected endpoints increases only when a unique endpoint connects, i.e., an endpoint that has not been successfully authorized by NAICE within the last 24 hours;
- To determine endpoint uniqueness, the RADIUS request must include the
Calling-Station-IdRADIUS attribute containing the MAC address of the client device; - If the specified attribute is missing, indirect identification is performed using the following attributes:
User-Name— the attribute must be present in the RADIUS request;NAS-IP-AddressorNAS-Identifier— at least one of these attributes must be present;NAS-Port— optional attribute;NAS-Port-Type— optional attribute.
- A device is considered active for exactly 24 hours from the moment of its last successful connection. If re-authorization occurs within this period, the 24-hour countdown is reset.
The value of this parameter is agreed upon at the time of license purchase and depends on the number of client devices in the network. The methodology for calculating this parameter is described below.
When the licensed daily limit for connected endpoints is reached, endpoints exceeding this limit will not be authorized. Devices authorized within the last 24 hours may still be successfully re-authorized.
ADVANCED
The ADVANCED license includes the BASIC functionality and activates the functionality required for configuring and operating portal-based authorization (Captive Portal). For licenses of this level, the number of guest endpoints is unlimited. Portal authorization is therefore available for any number of guest users and does not affect the connection limit of non-guest endpoints.
If NAICE is to be used only for Captive Portal, an ADVANCED license with a minimum of 100 endpoints must be purchased.
Additional options
NAICE-TACACS
This option enables the TACACS server functionality within NAICE. If the option is not purchased, the corresponding configuration settings are hidden in the system interface. The option is purchased in addition to the main license of any level, and this must be specified when purchasing the license. Purchasing the TACACS+ functionality separately without a main license is not permitted.
If NAICE is to be used only as a TACACS server, a BASIC license with the NAICE-TACACS option enabled and a minimum of 100 endpoints must be purchased.
When this option is purchased, there are no limitations on the number of network devices or the number of TACACS+ sessions.
Other license parameters
License validity period
Licenses of any level may be issued for a period of 1, 3, or 5 years.
A time-limited license may be renewed upon expiration.
When the license validity period expires, the licensed NAICE functionality will be blocked.
Number of NAICE nodes
For a clustered NAICE installation, a separate product key file must be obtained and activated for each NAICE node. In this case, an additional product key is issued with the license for activation on the standby node. The license itself is identical for all nodes.
Selecting an appropriate license
To select a license, it is first necessary to calculate the number of endpoints. The number of client devices can be determined by summing the number of users and the number of “auxiliary” devices.
If the above calculation method is not applicable, an alternative approach may be used:
- Upon request, an Eltex representative generates a short-term license (one or several months) with a deliberately higher device limit.
- The license is activated on the NAICE instance.
- During this period, authorization is ensured for all endpoints.
- The maximum number of endpoints simultaneously authorized within a 24-hour period is obtained from the system monitoring statistics.
- This number is considered the required quantity of unique endpoints in the network.
Demonstration mode
After installation, before a license has been uploaded to the system for the first time, NAICE operates in demonstration mode, which limits the number of:
- Network devices (authenticators) that can be added to the system: 15.
- Endpoints (client devices that have successfully completed 802.1X and MAB authentication): 15.
- Guest endpoints (client devices that have completed registration or authentication through the portal): 15.
After successful license activation, demonstration mode is disabled. Returning to demonstration mode without complete removal of NAICE is not possible.
Obtaining a license
License purchase
For inquiries regarding license purchase, please contact us at: foreign.sales@eltex-co.ru.
Demo license
A short-term license with extended limits is available for solution testing.
For inquiries regarding obtaining a demo license, please contact us at: foreign.sales@eltex-co.ru.
License activation
To activate a license, you must have the license key file received from your sales manager when purchasing the product.
The license activation process is described in detail in the NAICE built-in documentation in the section Licensing → Actions for license activation. Instructions on how to access the built-in documentation are provided in v1.2_4. Built-in documentation.
The PLR license activation process is also described in v1.2_2.1 File-based licensing (PLR).
License status monitoring
The current license status can be monitored on the dedicated Licensing page in the NAICE web interface. A description of the elements on this page is available in the built-in documentation under Licensing → License management and monitoring. Instructions on how to access the built-in documentation are provided in v1.2_4. Built-in documentation.
In addition, license status over a selected period of time can be monitored using Peeper monitoring system.
License degradation
An ELM license requires periodic communication with the ELM server to update its status and parameters. If an issue occurs during the next communication with the ELM server, the license degradation process begins.
- If ELM is unavailable during the next communication attempt, the countdown to license reset and feature blocking begins:
- if the server has already been contacted successfully, the grace period is 72 hours;
- if NAICE has never successfully contacted the ELM server since startup, the grace period is 3 hours.
The License activation error: Connection error and Feature access restriction events will be displayed in the Events section. The interface will indicate the probable cause of the error: The mandatory ELM server communication period for license verification has expired.
After the timeout expires, NAICE will switch to the No license state (License not installed). The functionality will be blocked.
- If the license has been blocked on the ELM server (for example, due to simultaneous use on different NAICE systems), the functionality is blocked immediately.
- In the License list section, the license status changes to Invalid.
- The License activation error, ElmLib: Request service is rejected because of license event is displayed in the Events section.
- The Feature access restriction event is displayed in the Events section.
- If the license was active and expired (the license expiration date has been reached), the functionality is blocked immediately. Warnings will start being displayed in the system interface 90 days before the expiration date. For details, see v1.2_4 Built-in documentation, under Licensing → Warnings.
Modifying license parameters
If it is necessary to modify license parameters (for example, to increase the number of successfully authorized unique endpoints per 24-hour period), contact your sales manager or send a request to foreign.sales@eltex-co.ru.
After approval, the parameters of the current license will be updated. The update of parameters in NAICE will occur automatically after a certain period of time. To accelerate the process, a manual update may be performed. The procedure for manual license parameter update is described in the built-in documentation under Licensing → License composition modification (see v1.2_4. Built-in documentation for instructions on accessing the built-in documentation).
In rare cases, it may be necessary to replace the current license with a new one. In this case, a new product key corresponding to the new license must be uploaded. The license replacement process is also described in the built-in documentation under Licensing → Full license replacement.
Technical support
If you have additional questions regarding licensing, please contact your sales manager or send a request to foreign.sales@eltex-co.ru.