Network engineer at a financial services firm with 1,001-5,000 employees
Real User
Enables us to define our policies and authenticate users based on them, eliminating threats
Pros and Cons
  • "It integrates with the rest of our platform, like our firewall, and helps us a lot. It also does a good job establishing trust for every access request."
  • "With the recent release of the solution, we had a bunch of bugs and we had to delay our deployment. Other than that, the solution is good."

What is our primary use case?

We use it for network device administration and for user access.

How has it helped my organization?

It has really helped us when it comes to security. It has eliminated trust from our network architecture because, with the solution in place, you tell us who you are and, based on who you are, we give you access. The solution provides us with a platform to define our policies. Users get into our system based on those policies. That eliminates threats. If you are not who you say you are, it will block you completely from our network.

What is most valuable?

It integrates with the rest of our platform, like our firewall, and helps us a lot. It also does a good job establishing trust for every access request.

What needs improvement?

With the recent release of the solution, we had a bunch of bugs and we had to delay our deployment. Other than that, the solution is good.

Buyer's Guide
Cisco ISE (Identity Services Engine)
May 2024
Learn what your peers think about Cisco ISE (Identity Services Engine). Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,170 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Cisco ISE (Identity Services Engine) for 10 years.

What do I think about the stability of the solution?

Cisco ISE has come a long way when it comes to stability. It's getting better.

What do I think about the scalability of the solution?

It's very scalable. We have it deployed in two data centers, and we're managing about 10,000 endpoints.

How are customer service and support?

TAC is very responsive whenever we call them.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Currently we have two solutions that do the same kinds of things. For our wireless infrastructure, we use Aruba, but for our wired access, we use ISE.

What was our ROI?

The ROI we have seen is because Cisco gives us what they promised us. They deliver. Our requirements are being met and that results in getting value for what we pay.

What's my experience with pricing, setup cost, and licensing?

Since we have a complete Cisco portfolio, including an Enterprise Agreement, it's not simple for me to compare what we're paying with the prices of other platforms.

Which other solutions did I evaluate?

We evaluated other companies and what they each do differently and looked at what was the better fit for our requirements.

Cisco TAC is really good. Whenever we have issues, we know they are there and that they will help us out with troubleshooting. The support of the other companies we looked at is not that great.

When I compare it with Aruba ClearPass and other solutions out there, I prefer Cisco. Cisco is number-one for user access, managing devices, and for network devices.

We don't leverage Cisco ISE for application access. We have another solution for that.

What other advice do I have?

Get some hands-on familiarity with it first. Do a PoC and get people who really know the solution to help you out during phase one before you deploy it.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager at Shanta Mining
Real User
Lacks properly knowledgeable support, but has stability
Pros and Cons
  • "So far, we have had no issues with the stability."
  • "The solution lacks properly knowledgeable support, especially internationally, and this is why I am exploring other applications."

What is our primary use case?

I am not certain if I am using the latest version. It is the one which is made for TV. 

We use the solution to access control. Prior to any device being authenticated on the network, a person must login to the solution's site for authentication purposes. 

What is most valuable?

While the solution has a host of features, we only use the one involving access control. 

We are looking into further uses for it. My aim is to deploy it across all three of our sites and not just one. 

What needs improvement?

There is much room for improvement, especially after having perused the documentation on the solution's website. 

The solution lacks properly knowledgeable support, especially internationally, and this is why I am exploring other applications. 

I would need time to expand my knowledge of the solution and consult with the Cisco engineers before I could point to other pain points. 

For how long have I used the solution?

I have been using Cisco ISE (Identity Services Engine) since 2015. 

What do I think about the stability of the solution?

So far, we have had no issues with the stability. 

How are customer service and technical support?

There should be more knowledgeable support, particularly in the international sphere. 

I have no doubt that we will get there. They contacted me yesterday, which makes it likely that by weeks-end we should be able to build a structure and do many things with the solution. This would allow me to know where I am standing, explore further and even examine the possibility of implementing some of Cisco's other features. 

Which solution did I use previously and why did I switch?

We did not use other solutions prior to the current one and will likely not explore others in the future. The current one should be fine. 

How was the initial setup?

The installation was straightforward, although it will likely involve a more complex implementation in the future.

As the previous installation was not complex, it did not take long. 

What's my experience with pricing, setup cost, and licensing?

I believe I have paid around $1,000 in licensing fees. The license is annual. 

Which other solutions did I evaluate?

We did not really explore other options prior to using the solution. We considered Fortigate, but found it to not be very straightforward, which is why we decided to go with the current solution. 

What other advice do I have?

While we have focused on the access control aspects of the solution, the documentation demonstrates that it has many more features, so I would like to explore it further. 

We are customers of Cisco. 

At the moment, we have around 250 users making use of the solution. 

I rate Cisco ISE (Identity Services Engine) as a five out of ten. This is because I wish to explore further any additional features that can add value to our organization, especially on the IT security side. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Edwin Dzangare - PeerSpot reviewer
Edwin DzangareNetwork Engineer at compulink Systems
User

Cisco Identity Service Engine l will give it an 8 out of 10 rate. It's stable and easily integrates with other network devices such as switches, routers and its central device management TACACS. The major challenge is in the new license model. Base, Plus and Apex licenses have been migrated to Essentials, Advantage and Premier. The new Cisco ISE licensing model Essentials, Advantage, and Premier licenses are term-based which limits end-user to fully utilize all the device features and functionality.  

Buyer's Guide
Cisco ISE (Identity Services Engine)
May 2024
Learn what your peers think about Cisco ISE (Identity Services Engine). Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,170 professionals have used our research since 2012.
Associate Director of Network Tower at Happiest Minds Technologies
Real User
Top 20
Superior support, effective NAC, but difficult to configure
Pros and Cons
  • "The most valuable features are the NAC and the bundles that are available with Cisco ISE, such as Cisco ACS being integrated."
  • "The solution configuration is complicated for setting the infrastructure. They have improved over the years but there is still a lot of room to improve. When comparing the simplicity to other vendors, such as Fortinet and Aruba they are behind."

What is our primary use case?

My clients are small to enterprise-size companies using this networking solution. One of my clients is a leading pharmaceutical manufacturing company, providing genetic medicine. The network they have has approximately 5,000 device inventory. Additionally, I have a couple of clients in the banking industry in the USA that has quite a large networking infrastructure using this solution.

What is most valuable?

The most valuable features are the NAC and the bundles that are available with Cisco ISE, such as Cisco ACS being integrated.

What needs improvement?

The solution infrastructure configuration is complicated to set up. They have improved over the years but there is still a lot of room to improve. When comparing the simplicity to other vendors, such as Fortinet and Aruba they are behind.

For how long have I used the solution?

I have been using this solution for approximately three years.

What do I think about the stability of the solution?

The solution is stable.

How are customer service and technical support?

Cisco's support system is very good and they are well known for it.

Which solution did I use previously and why did I switch?

I am also using FortiNAC and it is similar to Cisco ISE. However, Cisco is spread across the globe with bigger clients, large enterprises. FortiNAC is not as mature, but they are still working their way up in the market

What's my experience with pricing, setup cost, and licensing?

The price of the solution is price fair for the features you receive.

Which other solutions did I evaluate?

I have evaluated other solutions from Aruba and Fortinet.

What other advice do I have?

I rate Cisco ISE (Identity Services Engine) a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Vusa Ndlovu - PeerSpot reviewer
Security Solution Architect at Nexio South Africa
Real User
Top 5
Allows you to automate the collection of information
Pros and Cons
  • "I like the automation of the collection of information."
  • "One of the issues that we used to have was with profiling because we're working with a service provider that uses a lot of bring your own devices."

What is our primary use case?

We're using version 3.1, which is very stable. There have been a lot of improvements.

What is most valuable?

I like the automation of the collection of information.

What needs improvement?

We have only been deploying this version for three months. We haven’t had any issues, but we'll see how it goes. One of the issues that we used to have was with profiling because we're working with a service provider that uses a lot of bring your own devices. We haven't had any issues since we started using version 3.1.

For how long have I used the solution?

I have been using this solution for over 12 years.

What do I think about the stability of the solution?

There are no stability issues with version 3.1.

What do I think about the scalability of the solution?

It's stable. We deployed with a client in petroleum with about 200 users worldwide, and it was stable.

How was the initial setup?

Setup wasn't easy, especially if you haven’t worked with it intensively. VM is a little bit easier. If you don't deploy ISE with correct policies, it will be difficult.

If you deploy it with the correct policies, it's a wonderful product. You don't need to attach anything like your firewalls or creating rules.

What's my experience with pricing, setup cost, and licensing?

ISE has always been expensive compared to other products in terms of what it does on a user level. I haven't had a client who didn't say that ISE wasn't expensive. I’ve had an issue where I was just selling four boxes, and it was four million. It was a high-end box, and the client didn't take it. They end up going with VM.

What other advice do I have?

I would rate this solution 9 out of 10.

It's one of the more difficult products to deploy.

You can learn a lot about ISE from their training videos. I would suggest watching the videos before deploying the solution. They have created good videos for ISE, from version 1.3.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Senior Software Engineer with 501-1,000 employees
Reseller
Top 10
A one-stop solution to streamline security policy management
Pros and Cons
  • "They have recently made a lot of improvements. My clients don't have much to complain about."
  • "It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version."

What is our primary use case?

We use ISE for security group tagging in terms of guests and visitors who access the network to make sure that they actually go through this to control their privilege access to ensure they don't actually access the internal network, etc. 

Our clients use ISE as a form of security policy management so that users and devices between the wired, wireless, and VPN connections to the corporate network, can be managed accordingly.

Take a house for example. Sometimes you need to access a room via a certain keyhole, so you use a key that is unique to that door. With ISE, you can segment this process in terms of policy management based on the security tag. You actually grant the user access based on the tagging.

That's the IT trend — saving a lot on operating costs to manage the different users and access methods.

Within our company, we have roughly 200 employees using this solution.

What is most valuable?

My clients are always talking about the segregation capabilities. Segmentation refers to how you can actually segregate employee and non-employee client access. 

What needs improvement?

They have recently made a lot of improvements. My clients don't have much to complain about — it's a one-stop-shop.

It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version. 

What do I think about the stability of the solution?

It's stable but there's a limitation of up to 200,000 users. If you have a big number of users, then you have to customize the installation process. 

What do I think about the scalability of the solution?

It's only scalable up to 20,000 users. 

How are customer service and technical support?

I would say Cisco's support has been getting worse. I think they outsource a lot of skillsets.

How was the initial setup?

The initial setup is pretty straightforward. They actually provide a lot of help to IT administrators which makes setting it up rather easy.

The whole setup takes about three days because you need to basically configure the network, test the configuration, and then you need to cut over to production. 

What was our ROI?

Our customers definitely see a return on their investment with this solution.

What's my experience with pricing, setup cost, and licensing?

I think licensing costs roughly $2,000 a year. ISE is more expensive than Network Access Control.

What other advice do I have?

If you wish to use ISE, you must have a deep understanding of IT. If you don't, setting it up properly will be very complex.

Overall, on a scale from one to ten, I would give this solution a rating of nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Solution Architect Telecom at a manufacturing company with 10,001+ employees
Real User
Okay technical support but hard to scale and not very stable
Pros and Cons
  • "Technical support is okay."
  • "The solution is not so user-friendly."

What is our primary use case?

We primarily use the solution for user authentication and wireless segmentation of users for actual radius purposes.

What is most valuable?

The actual radius is the most valuable aspect of the solution. We need to have a centric solution either on MarTech X and for the wireless user authentication. We were mainly on Cisco and we continue to use them. However, this is the time period for a refresh as the five-year lifespan is completed. We may look for other options.

Technical support is okay.

What needs improvement?

The solution is not so user-friendly. It's very difficult to navigate through different manuals. The documentation should be simplified so that it is easier to understand.

It would take time for a beginner to understand and familiarize themselves with the solution. There's a bit of a learning curve.

Cisco ISE is not very stable. They could work on that aspect. 

We'd like the pricing to be better.

The product is not easily scalable.

Currently, if you want to do something with authentication, you need to have an additional document agent, however, these are short on all Microsoft endpoints. We then need to come up with some alternate options so that I don't have to modify any native applications on it. By default, Windows should be able to support and onboard the devices. Right now I need to have a Cisco AnyConnect as an agent to be deployed for authentication.

For how long have I used the solution?

I've been using the solution for over five years at this point. It's been a while.

What do I think about the stability of the solution?

The stability of the solution needs to be improved. It's not ideal. It's lacking overall. If we have five or six items activated, the box shakes and we're scared to touch anything. When we do have to reconfigure things, it's a nightmare as it can go down and it can take us a day or two to sort things out.

What do I think about the scalability of the solution?

In terms of scalability, it needs to be reactivated, which means that I need to add more nodes. It's got its own design limitations. We had only a two-node deployment in it. We need to add more hardware and we need to reduce so many things. It's not an easy option to scale this hardware. Scaling, in general, is very difficult.

We have roughly 9,000 users on this product currently.

How are customer service and technical support?

Technical support is fine. However, we may need to depend on support to resolve some of our many issues. We need to spend an enormous amount of time with them and to explain so much stuff. It would be easier if we could troubleshoot the issue ourselves or if the solution was more reliable.

Which solution did I use previously and why did I switch?

I don't know about other alternative products. I don't have any experience with other alternative products. I've only ever used Cisco ISE.

How was the initial setup?

The solution's initial setup can be a bit complex as there are so many features that are available. It all depends, however, upon which one you want to activate. In our case, we have five or six activated and the box always shakes. It's not stable. So my colleagues are always afraid to touch the box. If it is working well and good, you don't touch it, and we don't reconfigure it. In cases where we encounter any issues, it's a nightmare and we need to spend a minimum of twenty-four to forty-eight hours to recover everything.

What's my experience with pricing, setup cost, and licensing?

We pay a fee based on a subscription model.

The pricing could always be better.

Which other solutions did I evaluate?

I've been looking at evaluating Aruba's Clearpass as a potential replacement option for this solution. I haven't gotten too far into my research, however. I'm looking for a solution that's scalable and easy to use.

What other advice do I have?

My advice to Cisco would be to simplify as much as possible so that a normal IT guy can understand the CCD and set it up. If they can simplify the manuals, navigation, and documentation, it would be nice. It will always be difficult for a beginner, however, to, rearrange or design the network.

I would rate the solution five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
ChrisWanyoike - PeerSpot reviewer
Network Infrastructure Specialist at Central-Bank-Kenya
Real User
Top 5Leaderboard
Good posturing, good integration, and excellent technical support
Pros and Cons
  • "At the moment, ISE seems to integrate very well with a number of other technologies."
  • "This product doesn't work in isolation."

What is our primary use case?

Mainly the use case of the solution is for ensuring that the corporate staff gets access to their authorized systems. 

Another use case is for contractors to get access to the authorized systems. Those are the ones that hope to assist in the maintenance or for authorized admissions to the network.

We do also use it for remote access, for example, VPN's and also for wired and wireless access to the network.

What is most valuable?

The posturing is the solution's most important aspect. When a user connects his or her machine to the network, the first is for ISE to check whether that machine is authorized, check that that machine is compliant with respect to antiviruses, whether it complies with respect to Windows updates, et cetera. If not, a feature is on auto-remediation, so that the proper antivirus and Windows updates can be pushed to the machine.

At the moment, ISE seems to integrate very well with a number of other technologies. It integrates well with Microsoft and integrates well with other wireless systems.

What needs improvement?

In terms of the improvements I need, they've already, according to my research, done those improvements with their new versions. The features have already improved on their newer version, and that's why we need to update to that new version.

What is required is that Cisco needs to be doing health checks and following up with the customer to ensure that their Cisco partners have done the deployment right. That's something that has really helped us.

Whenever a partner comes and does any deployment, we would, later on, engage Cisco for a health check, so that Cisco could assist with their products. They would check whether it has been deployed following the best practices - or they would just alert us on which features that we have paid for and we are not taking advantage of that. 

Cisco needs to continue with that health check. That engagement with their customers to reconfirm everything is like a quality assurance that the Cisco partners have given the right stuff to their customers.

This product doesn't work in isolation. For example, when we talk of posturing the Microsoft updates, the system that does automatic updates for Microsoft needs to work in an ideal fashion. The antivirus needs to work. OF course, the antivirus is not Cisco. Those products need to work as they should so that integration of the ISE product will work as well. When all factors are held constant, Cisco works well. 

For how long have I used the solution?

We have been using the solution for six years now.

What do I think about the stability of the solution?

We have been using it, especially during alternative working arrangements (due to the COVID-19). Using it, it's been stable. We have not had any issues. The only reason we are looking to upgrade is we didn't know the benefits that the newer version offered. When we checked with Cisco, they advised us that we were missing a few items that actually gaps caused by the partner's setup which we realized we missed during the health check.

We haven't had bugs or glitches. It doesn't crash or freeze. It's good.

What do I think about the scalability of the solution?

Everyone in our company is using Cisco. In terms of users, we have about 1,500, however, in terms of endpoints we have, that would be closer to about 3,000 to 4,000 endpoints, including wireless gadgets, switches, laptops, phones, and all that. We use it on a daily basis.

Scalability probably might be an issue. Before we bought ISE, we did sizing for each. We looked at the number of users in the organization, 1,500,  and then we used a factor to look at the uppermost band. We decided we would have to go for 4,000 licenses or 4,500 licenses. We multiplied by three. Based on that, we went for a certain hardware model.

This time, the hardware model we are going for supports up to or has the capability to support up to 10,000 users or endpoints. When we go for that, we will have used even less than 50% of what their hardware is capable of. Above 10,000, there's another hardware model that we're generally expected to go for. 

Basically, when you get the right model, when you do the right scaling, it will be very scalable. However, from the onset, you need to write hardware for USI.

The solution is more meant for enterprise-level organizations. It's not really for small companies, however, that has more to do with the pricing.

How are customer service and technical support?

We're dealt with technical support in the past. Their support is excellent, except for Umbrella. There is a technology called Cisco Umbrella, and they're a bit slow, however, the technical support in general, depending on the severity of the issue, is very prompt. I would say we are quite satisfied with their level of service.

Which solution did I use previously and why did I switch?

I've only ever used Cisco. I used to use NAC, however, they changed to ISE. I've never used any other product.

How was the initial setup?

We had a partner set up the solution, and we're not sure if they set it up correctly. The partners come straight to us, and do the deployment. Cisco only is there to be the third eye to come and check that the deployment has been done okay.

You have to make sure that other items connected to ISE are correctly implemented and updated as well (such as the antivirus), otherwise, it won't work as you need it to. There's a lot of configuration that needs to be done at the outset.

I'm not sure how long the deployment takes, as I wasn't at the company when it was set up. However, it's my understanding that it shouldn't take too long so long as everything surrounding it is correctly aligned.

Any maintenance that needs to be done is handled by a third party. That includes patching, et cetera. We have an SLA with a Cisco recognized partner.

What about the implementation team?

We worked with a partner that assisted with the setup.

Afterward, Cisco will also come in to do a "health check" to make sure the setup is correct and they can direct users to features they should use or are not using.

What's my experience with pricing, setup cost, and licensing?

Cisco does not sell directly. They have authorized partners you need to buy through.

I don't deal directly with the licensing and therefore do not have any idea what the pricing of the product is. It's not part of my responsibilities.

It is my understanding, however, that it would be expensive for smaller organizations. Startups may not be able to afford these products.

We don't really worry about pricing, as cheap might be expensive in the long run if you don't get a product that is right for your organization, or is more likely to break down over time.

Which other solutions did I evaluate?

We are in the process of doing a refresh and I have compared other technologies to see how they stack up. I've looked at Fortinet, for example.

I wouldn't say we are switching from Cisco. What we are doing is we were exploring other technologies that offer similar functions. Sometimes it's good to look outside as you might think you have the best and yet you don't. We are just looking for other solutions to get to know what they offer. If we feel that there is something unique that is on offer somewhere else, then we would want to check that in Cisco and see, where is this offered in Cisco's product? 

We haven't concluded that we are switching. In any case, from what I have seen so far, it is likely we won't switch. 

What other advice do I have?

We're just a customer. We buy their products for our security and our connectivity.

We're not using the latest version. We're actually using a few versions. We have ISE, which is version 2.3. We're supposed to up to version 2.7, and that requires a refresh of the hardware.

That's why we are saying, "Should we try to look for a different solution?" That's why I have been looking for comparisons. We haven't dedicated a lot of time to that yet. From my assessments so far, however, ISE still wins the show and it's likely that the partner that was doing the deployment originally on behalf of Cisco probably missed out on a number of things. It's really about the engineers who are doing the deployment. You need to make sure you have some good ones.

I would recommend this solution to others, especially mature organizations as the smaller organizations may not be able to afford this. 

On a scale from one to ten, I would rate the product at an eight

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network & Security Architect at Canac IT
Real User
Easy implementation, simple to add policies, and very stable
Pros and Cons
  • "The implementation is very simple."
  • "The web interface needs improvement. The new web interface that they have is not as easy to manage and we find it to be very slow."

What is most valuable?

The .1x authentication schema is the most valuable aspect of the solution. It makes it possible to have multiple policies and it can still adapt to us. We can authenticate and calculate our trajectory and so on. The policy is very easy to put in place. It's got to be easy due to the fact that we have more than 200,000 devices.

The implementation is very simple.

What needs improvement?

The web interface needs improvement. The new web interface that they have is not as easy to manage and we find it to be very slow.

The solution might require two authentications. They should make a new authentication to authenticate both the device and the users. Right now, we are authenticating the PC, the workstation, but not as a user. A good addition would be to authenticate the user separately to get more information.

For how long have I used the solution?

I've been using the solution for five years.

What do I think about the stability of the solution?

The solution is stable. I haven't witnessed bugs or glitches. It doesn't freeze or crash. It's reliable.

What do I think about the scalability of the solution?

The solution is quite scalable.

We started with two clients and we've since scaled up to 20 clients.

Which solution did I use previously and why did I switch?

Cisco ISE was the first full solution we've used.

How was the initial setup?

The initial setup wasn't complex for us. We found the process of implementing the solution very straightforward.

For our organization, in terms of deployment, the first implementation took one month, and for the global implementation took six months.

For maintenance, a company needs one or two people to handle it, one of which should be full-time.

What's my experience with pricing, setup cost, and licensing?

The pricing is okay. It's reasonable for functionality, however, if you're going to implement it as a full-stack with Cisco Connect, and a work station, and so on, it's very high.

What other advice do I have?

I'd advise other companies to really take care in regards to the network devices that they want to authenticate. 

For most of the cases, the biggest rooms are the easiest to manage, however, the smallest ones require specific implementation in all devices. It is very tricky due to the fact that you are obliged to put in place the rules that are not so secure and that's why it's very important to know what devices are connected on the network.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cisco ISE (Identity Services Engine) Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Cisco ISE (Identity Services Engine) Report and get advice and tips from experienced pros sharing their opinions.