crypto isakmp command error? CSR1000v image?


I am using image csr1000v-universalk9.03.12.00.S.154-2.S-std.ova

Cisco IOS XE Software, Version 03.12.00.S - Standard Support Release

Cisco IOS Software, CSR1000V Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.4(2)S, RELEASE SOFTWARE (fc2)


I just started trying to load the init for the CCIE R&S v5 Advanced Technology Labs - MPLS

VRF Lite  R4.txt 

and getting this error, 

R4(config)#crypto isakmp policy 10


% Invalid input detected at '^' marker.


There isn't "isakmp" option

R4(config)#crypto ?

  key  Long term key operations

  pki  Public Key components


Just wonder if I am using the right image for these labs?  or there is something other setup missing before I can get this to work?   I have seen people mentioned a few different images, like csr1000v-universalk9.03.11.01.S.154-1.S1-std-C1-M2560-N3-DS8, csr1000v-adventerprisek9.03.09.00a.S.153-2.S0a-C4-M4G-N3-D8 and this one csr1000v-universalk9.03.12.00.S.154-2.S-std


Thank you




  • Just found it I needed to activate primium license with license boot level premium, then it works

    R4(config)#do sh license detail 

    Index: 1        Feature: prem_eval                         Version: 1.0

            License Type: Evaluation

            License State: Active, In Use

                Evaluation total period: 8  weeks 4  days 

                Evaluation period left: 8  weeks 3  days 

                Period used: 2  minutes 20 seconds 

                Expiry date: Aug 06 2014 15:55:16

            License Count: Non-Counted

            License Priority: Low

            Store Index: 0

            Store Name: Built-In License Storage


    R4(config)#do show platform hardware throughput level

    The current throughput level is 50000 kb/s


    R4(config)#crypto ?                                  

      call         Configure Crypto Call Admission Control

      dynamic-map  Specify a dynamic crypto map template

      engine       Enter a crypto engine configurable menu

      gdoi         Configure GDOI policy

      identity     Enter a crypto identity list

      ikev2        Configure IKEv2 Options

      ipsec        Configure IPSEC policy

      isakmp       Configure ISAKMP policy

      key          Long term key operations

      keyring      Key ring commands

      logging      logging messages

      map          Enter a crypto map

      mib          Configure Crypto-related MIB Parameters

      pki          Public Key components

      ssl          Configure Crypto SSL Options

      vpn          Configure crypto vpn commands

      xauth        X-Auth parameters


    So the question is, so this is not going to work after 60 days right?

    guess i need to roll back my vmware snapshot then if it doesn't.


    could someone clarify that, please?



  • Hi lefthop,

    CSR can be used in production networks, obviously. After the trial period ends, the data plane traffic will be limited to a low throughput value (I think it's 5Mbps), this way preventing you to use the platform in real case scenarios.

    As for the CCIE lab preparation, I see no problem with this limitation, for testing scenarios you'll be just fine.

  • Great, thanks for the clarification.

    Take care.Post

  • So after the 60 days - does it retain the premium license features and just limits the throughput?




Sign In or Register to comment.