Cisco ISE (Identity Services Engine) Room for Improvement

BP
Lead Network Engineer at a educational organization with 1,001-5,000 employees

There is room for improvement in its ability to allow end users to self-enroll their devices. Instead, you should be able to assign that permission by AD group, which is currently not available.

View full review »
Bill Masci - PeerSpot reviewer
Senior Network Admin at Iridium

A lot of people tell you the hardware requirements for ISE are pretty substantial. If you're running a virtual environment, you're going to be dedicating quite a bit of resources to an ISE VM. That is something that could be worked on.

The upgrade process is not very simple. It's pretty time-consuming. If you follow it step by step you're probably going to have a good time, but there are still a lot of things that could be a lot more user-friendly from an administrator's perspective. [They could be] easing a lot of the issues that people have. Instead of just saying the best practice is to migrate to new nodes [what would be helpful] would be to make that upgrade process easier.

The UI is a lot nicer in 3.0. It's pretty slow, but for the most part, it's easy to find what you're looking for, especially things like RADIUS live logs, TACACS live logs. From a troubleshooting perspective, it's really nice finding stuff. For setting up policies, from that perspective, it could be a little bit better looking.

View full review »
Rohit-Joshi - PeerSpot reviewer
Head of IT Infrastructure at a tech vendor with 10,001+ employees

Cisco ISE integration with Cisco ACI is something that can be done in a less complex way. And the simplification in that area may help us do better. 

View full review »
Buyer's Guide
Cisco ISE (Identity Services Engine)
April 2024
Learn what your peers think about Cisco ISE (Identity Services Engine). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
Brad Lossing - PeerSpot reviewer
Manager Network Operations at RAND Corporation

They should improve the documentation. There tends to be a lot of old text, or the new things aren't always up to what's been released on the code, and sometimes the documentation is inconsistent.

Last week, we were doing a dot1x troubleshooting, and I was showing people how to look for it, and all the documentation came up for version 1.0. I wondered why version 3.0 is not the top choice since it is already out, and we've been on Version 2.0 for five years. The solution should try adjusting their tags because sometimes it's difficult to find things.

View full review »
Vergin Mansour - PeerSpot reviewer
Network Engineer at a manufacturing company with 10,001+ employees

The one main thing that it can improve on is the GUI. As the newest addition to the team, I struggle a little bit to get around it just because it has so many features. This is an amazing thing but the downside of it is that it's not as friendly to figure out which feature does what and how to get to it. 

You have to go through a lot of menus to figure out what you need. Although it's fantastic, it's full of different options that are endless, it does get a bit hectic for new users to get comfortable with it. It's taking me a while to figure out all the features and options.

View full review »
Solomon Okonta - PeerSpot reviewer
Network Architect at Great Canadian Gaming Corp

The policies could be adjusted to make them more easily implementable.

View full review »
Wayne Cross - PeerSpot reviewer
Director of Cyber Security at Borden Ladner Gervais LLP

The interface is a little bit complex. It doesn't really have an executive dashboard. I'm the director of cybersecurity infrastructure operations for the entire firm, and I'm a very technical person, so I go in, and I can move around and try to figure everything out.

However, the interface is very complex, and there are tons and tons and tons of options. It's quite complex to get into and take a look at. As a result, most of the time, just my networking team would be in there. It's so complex that sometimes I will find something one week, and by next week I can't find it again.

It's too deeply layered. They have to redo the whole interface and have something that's executive based, and another one that's technically based. Even the help desk team and my security team use some of its components, however, they don't go anywhere often, as there are so many options in there. They have to make the interface a little bit more use user-friendly.

View full review »
MI
Technical account manager at a tech services company with 201-500 employees

I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it.

The deployment is complex. I get that it's very configurable, but there is the challenge of how to get to certain things. You go to different places to get the same things done. There needs to be improvement to the GUI.

View full review »
JS
Network Analyst at a mining and metals company with 10,001+ employees

It would be helpful for us to know what needs to be deployed, configured, and what changes we need to make to our devices when we don't receive the specific login which is an indication of a lack of connection or incorrect configuration.

View full review »
Aaron-Brown - PeerSpot reviewer
Network Engineer at Universal Health Services, Inc.

ISE is a little clunky. The front-end feels like it is from the 1980s.

The usability, as far as programmability goes, needs to be improved.

View full review »
SL
Network Engineer at a financial services firm with 10,001+ employees

The web UI should be made similar to the one in DNAC. The left pane must have the menu title followed by the submenu. Since I have moved to version 3.1, I have to go back to the old version to figure out my way. They haven't improved the left pane of the UI. The left pane is supposed to have the menu title in order.

View full review »
SM
IT Security manager at a energy/utilities company with 201-500 employees

It perfectly does everything we have been looking for it to do. I have not discovered any feature sets or items that are lacking. It's a much more functional product than the old Cisco ACS that it replaced. 

That being said, during deployment, they shipped us the Cisco ISE with the 3.1 operating system, which was incompatible with the license that we had purchased, which would only allow us to go up to version 2.9. Because of this, we actually had to do a factory reset and a reload to the operating system — to an older version of the operating system. This required a very extensive process. We had to take out the Cisco ISE and put it into a factory reset mode to get it to roll back to the old operating system. If we were doing an upgrade, this would have been very simple, but as we were doing a downgrade, it was extremely complex and very labor-intensive. I was crawling through the server room, through wires, to plug things in, to get it to connect in the way that it needed to be connected with an external device in order to actually get it to roll back.

I don't like that the licensing structure doesn't allow us to have the 3.1 operating system — it forces us to use version 2.9. If you don't want to pay a monthly or a yearly subscription fee, either that device should have come automatically with the 2.9 version operating system, or it should have been much easier to actually roll it back. Additionally, support should have realized that our license requires us to have the 2.9 operating system instead of the 3.1 operating system, which would have saved us a lot of time. 

It would be nice if it could be configured easily by default. If you're configuring a Cisco device, you pretty much need the support of a CCNA-level technician to be able to do it. It would be nice if there was a default or a more simple way to do it. It's not really a requirement to use the device because you can purchase the premium support or you could get a CCNA in-house to do it. Just having that ability to say, "Hey, we want to set this up" without too many complications or without having to bring in support would be nice. 

View full review »
Brad Davenport - PeerSpot reviewer
VP of Technical Architecture at Logicalis

I think in any technology infrastructure, you're going to have environments where improvements could occur. I think some areas where ISE could be better are perhaps in the number of integrations that they offer from a virtual standpoint, as well as having a better and more comprehensive pathway for the customer to go from a physical environment to a virtual one. Many of our clients today are hybrid. They have a physical footprint in a data center somewhere, as well as a public cloud instance for things. Today there really isn't an elegant pathway for a client that wants to go 100 percent cloud, and that's an improvement I think that could be along the way.

View full review »
Darren Hill - PeerSpot reviewer
Technical Consultant at a computer software company with 1,001-5,000 employees

I don't really know how to improve it, I think it's a great product. If I compare Cisco with something like ClearPass, for example, ISE is a lot more intuitive in terms of all the workflows and the work centers. They give you all the building blocks you need to be able to configure it. It's quite useful and quite easy to manage. 

If I was going to improve anything, it would be the ease of migration. It's really difficult at the moment if you're looking to upgrade ISE 2.1 and you want to go to ISE 3.1 or 3.2, that whole upgrade path and, particularly, the licensing is quite a minefield to sort out. If I wanted anything to be easier, it would be this.

View full review »
Adarge Ekholt - PeerSpot reviewer
Network Engineer at a university with 1,001-5,000 employees

The primary issue is the slowness of the application and the web interface. We have multiple admin nodes and app nodes. So when I need to get some information about a particular user, the GUI would take ten to fifteen seconds in loading when we need to know right away. 

View full review »
Laurence Mcbride - PeerSpot reviewer
Senior Business Systems Analyst at a financial services firm with 201-500 employees

A main issue is that the upgrade process, over time, is extraordinarily fragile. Repeatedly, over the past several years, when we've tried to upgrade our Cisco ISE implementation, the upgrade has broken it. Ultimately, we have then had to rebuild it because we need it. There are so many updates and, often, you can't go to a particular update unless you've done all of the updates leading up to it, although I don't think that was our issue.

If they could improve the upgrade process, that would make me sleep a lot better. It's almost like we need to have it pre-qualified before applying an update because our whole world hangs off of it. It is a "center of the known universe" implementation for us.

It is also an incredibly "nerdy" tool, one that is not really well documented for your everyday network and security engineers. It takes a village of specialists to keep something like this running. Cisco is definitely making some improvements in the user interface. It's a little more understandable and approachable. Even for the nerdiest of nerds, having what I call a "kissable baby face" makes it more usable. Cisco knows this and, from version 3 and up, they've been trying to improve the usability and it's getting better. It could use some work.

Not everything is a smart Windows or Mac OS device. We have Windows 10-based user laptops, almost exclusively, and there are some printers and phones and the like that are capable of either a certificate or other 802.1X conversation with Cisco ISE. From an engineering perspective, we just went "way-simple." We do MAC address bypass or MAB tables, which is administratively challenging.

Finally, I believe we've stretched it beyond its capabilities in attempting to make it a multi-client solution, more like a service provider implementation. It's really not architected for that yet. I think that's on the roadmap. This is what I refer to as a monolithic implementation. It is capable of servicing multiple Active Directories and saying, "I recognize this address range equals client X, and this address range equals client Y," and it can interrogate the appropriate Active Directory. But the way that we've implemented that, honestly, is a hack job. It's fully supported, but it's just not multi-client architected. If I had one message for Cisco, it would be: Please make this thing multi-client, or at least more affordable to do separate implementations that somehow get closer together. That's ultimately what multi-client is.

All our various clients are collectively involved with one another. Each of the five owners owns an equal share of the company and all profit and loss flows to each of the owners equitably. It's not that we don't have procurement relationships with one another. However, our regulator continues to believe that separating things is better. That way, if one of you gets taken down, the others aren't affected. Anytime that you have a product that is a type of monolithic implementation, it potentially could affect all of us.

View full review »
TA
Network Analyst at a healthcare company with 10,001+ employees

As software, in general, ISE is actually a fantastic product. I just think that, overall, it's just the software control, the bugs, and the fixes. We do tend to run into a lot of issues with ISE when it comes to bugs. I would like to see a lot more testing prior to the rollout of some of these software updates.

View full review »
FA
Network Engineer at Lawrence Livermore National Laboratory

Adding new devices was a little cumbersome. I haven't done it that many times, but I remember that adding new devices to the authentication piece of it was a little cumbersome. The way I was shown to do it, I thought it was odd because we had to go into the active device, copy the file down, export it, make some changes to it, and then reimport it as opposed to being able to click it and having a template to fill out. It was a little more cumbersome than I thought.

View full review »
Ashley Mead - PeerSpot reviewer
Sr Network Consultant at CAE Technology Services Limited

I don't see as many customers as I should adopting the onboarding feature. I think Cisco should make that process a lot easier and less intrusive on the end users' devices.

View full review »
AB
Network Architect at a tech vendor with 10,001+ employees

Cisco ISE has numerous features that are impractical, and I won't utilize them since they require payment.

View full review »
Roy Pinheiro - PeerSpot reviewer
IT Manager at a financial services firm with 1,001-5,000 employees

I believe that Cisco can improve the way its policies are built because they're a little complex. If the operation teams do not have not a very good understanding of the solutions, they can break something because it's not so easy to view their policies through their eyes.

View full review »
Jeffry Pereira - PeerSpot reviewer
Network Technical Lead at a energy/utilities company with 10,001+ employees

The templates could be better. When you have to do certs, especially with X.500 certs, it isn't very intuitive.

View full review »
CN
Network Operations Supervisor at McCoy's Building Supply

When it comes to improvements with ISE, even though we've been using it, there's still a lot to learn because it's such a robust product. I think that Cisco could do something to counteract the stigma that ISE is cumbersome and hard to use.

There was a big pushback against us implementing this product because as VPs and executives start to talk, they want to talk about everything they've heard, and they had it in their minds that things are the way they are. To proceed with implementing ISE, we had to push against that.

The UI is not as intuitive as some other products, even products inside of Cisco's wheelhouse. To an extent, some of it feels like it's legacy and could be improved upon.

View full review »
JN
Sr Wireless Network Engineer at a manufacturing company with 10,001+ employees

The opinion of my coworkers, and it's mine as well, is that the user interface could use some tender loving care. It seems counterintuitive sometimes. If you go to the logs, it's hard to figure out which one you need to look at. My ISE admin probably has different ideas, but for us, that's the main complaint.

View full review »
Gustavo Pena - PeerSpot reviewer
Services Director at XByte SRL

Profiling is a really good feature. However, it sometimes is a challenge for customers when there are issues with the remediation part. I would add a built-in remediation solution. That would be a very nice feature.

View full review »
EV
Senior Network Engineer at a tech consulting company with 11-50 employees

Cisco ISE's real-time data analytics for database logging could be improved. Earlier, you didn't have direct read access to the database. You'd have to rely on logs through some other sources like Splunk and be able to put everything that you want together. Being able to review logs in real-time, customized to your filtering, adds a lot of context and visibility.

View full review »
JC
Network Engineer II at a healthcare company with 10,001+ employees

Sometimes, there are instances when Cisco ISE simply fails to function without any apparent reason, and regardless of the investigation we undertake, the logs indicate that everything is functioning properly, making it somewhat inexplicable. However, after a while, it spontaneously begins functioning again. Therefore, I believe it is not a widespread problem, but when it does occur, it can be quite frustrating.

The support specifically for Cisco ISE has room for improvement.

View full review »
GV
Sr. Architect at a pharma/biotech company with 10,001+ employees

Cisco could improve the GUIs on their hardware.

View full review »
Adam Boldin - PeerSpot reviewer
Network Architect at Tarrant Regional Water District

I'd like to see the logging be a bit more robust in terms of what it has baked in. If I want to do any in-depth searching, I have to export all the logs to an external platform like Elastic or LogRhythm and then parse through them myself. It would be nice if I could find what I want, when I want it, on the platform itself.

View full review »
Romildo Junior - PeerSpot reviewer
IT Business Manager at Telefónica

I'm not working in the IT team. I'm working the sales team. While there are a lot of features that we could improve in our organization, I can't speak to the exact changes that should be made.

We'd like to be able to integrate the product with our solutions. Sometimes we face some infrastructure where there are multiple vendors and sometimes the ISE is not the best tool to manage multiple vendor infrastructure. 

The price here in Brazil is very expensive. 

Configurations can be a bit complicated. 

Sometimes we have problems integrating logs into SIEM solutions. We have to deliver some logs to a SIEM secret platform, and sometimes it does not work well. It would be better if we had better integration or a better way to deliver the logging SIEM platforms.

View full review »
CT
Network Engineer at a comms service provider with 10,001+ employees

The knocks I have against the product are the number of bugs that we encounter, constantly, and the amount of upgrading that we have to do.

View full review »
Batu Akalin - PeerSpot reviewer
Corporate Information Technology Security Manager at AG ANADOLU HOLDİNG A.S.

This solution does not provide us with enough visibility into our network. We would like to see additional information that it does not show. In general, the reporting is not very useful.

ISE needs to have better integration with third-party products.

A basic profiling engine would make a good addition because device profiling is very important.

This product requires the use of agents and ideally, I would like an agentless version. I think that they should get rid of them because they are hard to manage and deploy. Also, they are not useful.

The interface is not very user-friendly and it is not simple to use.

View full review »
WG
Senior Network Engineer at a financial services firm with 10,001+ employees

It is a good product for what it does. I don't have a similar experience with other solutions.

The solution cannot be deployed on the cloud yet, and that is one of the things I would like to test. Also, I want to have a couple of VMs integrated with the solution.

View full review »
Mehran Reza - PeerSpot reviewer
Engineering Lead at Canadian Broadcasting Corporation

Troubleshooting and multi-ISE can be challenging with the solution.

View full review »
Josh Calhoun - PeerSpot reviewer
IT Systems Engineer at Pierce County Information Technology

Cisco ISE can become quite complex, especially with policy sets, the entire authentication process, and everything involved. I would appreciate a more comprehensive visual depiction of the steps from the beginning to the end.

View full review »
EM
Network Engineer at a hospitality company with 10,001+ employees

Automation [is an area for improvement]. It seems like everywhere I look, automation is super important. Automation and integrations. That's the area it could be improved, as we get more and more away from a lot of human involvement and [into] machine learning and just trusting that these systems could automatically help us.

View full review »
Elshaday Gelaye - PeerSpot reviewer
Lead Technical Architec at Commercial Bank of Ethiopia

Some of ISE's features need to be more agile. For example, we couldn't integrate our data because Cisco needs your data to be in its own format.

View full review »
Ahmed_Shalaby - PeerSpot reviewer
Senior Cyber Security Engineer at Beta Information Technology

We face many bugs. The vendor is trying to improve it by releasing new patches and hotfixes.

View full review »
SM
Cyber systems Engineer at a manufacturing company with 10,001+ employees

They should improve their licensing. Licensing is always trouble with Cisco, and Cisco Identity Services Engine is no different. The way the product is licensed could be improved.

View full review »
WK
Senior Systems Engineer at Austro Control

Cisco ISE requires a lot of time-consuming administration.

View full review »
VikasKumar13 - PeerSpot reviewer
Associate consultant at HCL Technologies

There is room for improvement in CLI. Most things are done through the GUI, and there aren't many commands or troubleshooting options available compared to other Cisco products like switches and routers. We have more visibility on the CLI for those devices, but the GUI seems limited. Moreover, sometimes, GUI seems very pathetic. 

View full review »
SS
Network Manager at a healthcare company with 10,001+ employees

Some of the reporting could be improved.

View full review »
AS
Data Engineer at a healthcare company with 5,001-10,000 employees

It could be less monolithic. It's one huge application, and it does everything under the sun, so it's hard to deal with and upgrade and manage.

View full review »
SamBrown - PeerSpot reviewer
Network Engineer at a energy/utilities company with 1,001-5,000 employees

There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that. Cisco DNA Center may do it, but it would be better if that was integrated into Cisco ISE.

In terms of securing our infrastructure from end to end so we can detect and remediate threats, it's a little bit difficult in terms of visibility, but, generally, we would just go through the logs and see if there's a problem or not.

View full review »
AA
Senior Network Architect at Commercial Metals Company

I would like to see integration with other vendors, and the RADIUS integration needs to be improved a little bit.

Other than that, all the features that we're using look good.

View full review »
WM
Network Engineer at a insurance company with 5,001-10,000 employees

I don't like the fact that we can see the logs only for 24 hours. Maybe that happens because of the way we set it up.

View full review »
PB
Network Security Engineer at Vienna Insurance Group Kooperativa

[When it comes to securing access to your applications we are] not [using it] so much. I'll have another session with a TAC engineer on Friday, and I will have to discuss some basic concepts of securing the application with ISE. I find it very challenging to do some micro segmentation with it. I'm staying on top of it and doing it macro, but I want to go micro, and it's something I need to discuss more with an engineer.

Also, the menus could have been much simpler. There are many redundant things. That's a problem with all Cisco solutions. There are too many menus and redundant things on all of them. This is a problem in ISE. This could be much simpler.

View full review »
BS
Senior Systems Administrator at a manufacturing company with 10,001+ employees

It does a good job of establishing trust for every access request. We have had a little bit of a challenge with profiling, but we are probably about 80% there.

View full review »
JB
Network Services Engineer at a government with 51-200 employees

We would definitely like to see a little bit of an improvement in the web GUI navigation. Some of the things are a little bit hidden in the drop-down menu. If we could get a way to get to those quicker, it'd be much more useful.

View full review »
DM
Network Manager at a government with 201-500 employees

One of the problems we have had is that there are many features on Cisco ISE that we are not utilizing. In the real world, it requires multiple parties to come together, just like the AD or OU. Therefore, it won't be solely the responsibility of the network or security personnel to ensure that the solution works as intended and utilizes all the features. It necessitates collaboration among various stakeholders. If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components. This would be beneficial for my organization.

View full review »
PG
Principal Consultant at a computer software company with 1,001-5,000 employees

Sometimes some of Cisco ISE's graphical interfaces could be a little bit smoother. However, with the different versions, the product is getting better and better.

View full review »
MA
Senior Network Officer at a financial services firm with 1,001-5,000 employees

Cisco ISE's performance could be better, faster, and more robust. Sometimes it takes some time to move through the tabs and configure something.

View full review »
BB
ITS 1 at a government with 10,001+ employees

I would definitely improve the deployment and maybe a little bit of the support. Our first exposure to ISE had a lot of issues. However, I have noticed as we have been implementing patches and upgrades that it has gotten a lot better.

View full review »
SC
Infrastructure and Cybersecurity Manager at George Washington's Mount Vernon

Because we have a large database and 4,000 network devices, the solution can lag a bit when you're running updates or different things because of the fact that it's so big and it is such a resource hog. But the biggest problem we've encountered is that it finds errors or people are rejected or not authenticated without a clear explanation as to why. A second issue is that we're currently on 2.4 and Cisco's gold standard now is 2.7. They are a little slow with that.

I'd really like the solution to dive down a little deeper when something's not profiling. As it stands now, you have to go through and search what hasn't profiled. Microsoft, for example, gives you a direction to look at and will even be specific sometimes and tell you there is a password error, or the password hasn't been updated, or it's not meeting the policy and that's why it won't let it through. Those are very helpful because you know exactly what's required to solve a problem. 

Cisco is getting better with it, but they fail in some areas because of a network connectivity issue, or it's not getting DCAP quick enough and it fails. Those things would be more helpful to understand when it's going through, so you are able to triage it a little better. I mean, it does point you in a direction, but sometimes you have to dig a lot deeper to find the right direction and figure out what kept it from profiling. One big issue we've discovered is that people are not rebooting their machines or powering them off at night. We're trying to ensure that is done by sticking messages on screens.

View full review »
Md Manirul Islam - PeerSpot reviewer
Assistant general manager at Beximcocomputers

The tracking mechanism in Cisco ISE is relatively costly, especially its vendor-specific protocol. It would be beneficial if it could support open source or other devices with a similar checking mechanism, but unfortunately, it remains proprietary.

View full review »
OB
IT Architect at a tech services company with 501-1,000 employees

I'm frustrated by the resource consumption and how many resources it needs to run. It takes a lot of RAM. It takes a lot of space and a lot of IO power. It's frustrating to do upgrades because it takes a long time. Things are at a much smaller scale where we are than in the US. We even have smaller virtualization farms, so it takes a considerable amount of power and resources.

View full review »
HV
Network engineer at Bimbo Bakeries USA

On the network services devices, when you click on filter, the filter comes up. However, when I search and want to click on something it defaults back to the main page. I keep having an issue with that, and I'm not doing anything wrong.

View full review »
Sait Kilinc - PeerSpot reviewer
Manager of IT at a financial services firm with 10,001+ employees

The user interface could be more user-friendly.

View full review »
Jeff Burdette - PeerSpot reviewer
Cyber Security Administrator at a aerospace/defense firm with 11-50 employees

There are always some things that I would request.

View full review »
JB
Network Engineer at a financial services firm with 201-500 employees

Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior.

View full review »
CH
Principal consulting architect at a tech vendor with 10,001+ employees

When I work with customers to do my knowledge transfer, they're really overwhelmed with the navigation of the product and the number of things you can do with it. From a user interface standpoint, Cisco could focus on making certain tasks a bit more guided and easier for customers to walk through. That is, a user-friendly interface and streamlined workflows would be great.

View full review »
LP
Network engineer at a financial services firm with 1,001-5,000 employees

With the recent release of the solution, we had a bunch of bugs and we had to delay our deployment. Other than that, the solution is good.

View full review »
DH
IT Manager at Shanta Mining

There is much room for improvement, especially after having perused the documentation on the solution's website. 

The solution lacks properly knowledgeable support, especially internationally, and this is why I am exploring other applications. 

I would need time to expand my knowledge of the solution and consult with the Cisco engineers before I could point to other pain points. 

View full review »
CP
Associate Director of Network Tower at Happiest Minds Technologies

The solution infrastructure configuration is complicated to set up. They have improved over the years but there is still a lot of room to improve. When comparing the simplicity to other vendors, such as Fortinet and Aruba they are behind.

View full review »
MA
Associate Consultant at a computer software company with 201-500 employees

An issue with the product is it tends to have a lot of bugs whenever they release a new release.

We've always found ourselves battling out one bug or another. I think, overall they need to form a quality assurance standpoint. ISE has always had this issue with bugs. Even if you go to a Cisco website and you type all the bug releases for ISE, you'll find a lot of bugs. Because the product is kind of intrusive, right? It's in the network. Whenever you have a bug, if something doesn't work, that always creates a lot of noise. I would say that the biggest issue we're having is with all the product bugs.

Also, the graphical user interface is very heavy. By heavy, I mean it's quite fancy. It's equipped with a lot of features and animations that sometimes slow down the user interface.

It's a technical product — I don't think a lot of engineers really need fancy GUIs. We pretty much look for functionality, but I think Cisco, for some reason, is putting an emphasis on its GUIs looking better. We always look for functionality over fancy features.

We've had issues with different browsers, and sometimes it's really slow. From a functionality standpoint, we would rather the GUI was light and faster to navigate.

ISE has a very good logging capability but because their GUI is so slow, we feel it's not as flexible or user-friendly as we would like it to be, especially when it comes to monitoring and logging. At the end of the day, we're implementing ISE for security. And that means visibility.

Of course, you can export the data into other products to get that visibility, but we would like to have a better type of monitoring, maybe better dashboards, and better analytics capabilities within the product.

Analytics is one thing that's really lacking. Even if you're to extract a report, it just takes a lot of time. So, again, that comes down to product design, but that's definitely an area for improvement. I think it does the job well, but they can definitely improve on the monitoring and analytics side.

View full review »
Vusa Ndlovu - PeerSpot reviewer
Security Solution Architect at Nexio South Africa

We have only been deploying this version for three months. We haven’t had any issues, but we'll see how it goes. One of the issues that we used to have was with profiling because we're working with a service provider that uses a lot of bring your own devices. We haven't had any issues since we started using version 3.1.

View full review »
BN
Senior Software Engineer with 501-1,000 employees

They have recently made a lot of improvements. My clients don't have much to complain about — it's a one-stop-shop.

It should be virtualized because many people have begun migrating to the cloud. They should offer a hybrid version. 

View full review »
AV
Solution Architect Telecom at a manufacturing company with 10,001+ employees

The solution is not so user-friendly. It's very difficult to navigate through different manuals. The documentation should be simplified so that it is easier to understand.

It would take time for a beginner to understand and familiarize themselves with the solution. There's a bit of a learning curve.

Cisco ISE is not very stable. They could work on that aspect. 

We'd like the pricing to be better.

The product is not easily scalable.

Currently, if you want to do something with authentication, you need to have an additional document agent, however, these are short on all Microsoft endpoints. We then need to come up with some alternate options so that I don't have to modify any native applications on it. By default, Windows should be able to support and onboard the devices. Right now I need to have a Cisco AnyConnect as an agent to be deployed for authentication.

View full review »
ChrisWanyoike - PeerSpot reviewer
Network Infrastructure Specialist at Central-Bank-Kenya

In terms of the improvements I need, they've already, according to my research, done those improvements with their new versions. The features have already improved on their newer version, and that's why we need to update to that new version.

What is required is that Cisco needs to be doing health checks and following up with the customer to ensure that their Cisco partners have done the deployment right. That's something that has really helped us.

Whenever a partner comes and does any deployment, we would, later on, engage Cisco for a health check, so that Cisco could assist with their products. They would check whether it has been deployed following the best practices - or they would just alert us on which features that we have paid for and we are not taking advantage of that. 

Cisco needs to continue with that health check. That engagement with their customers to reconfirm everything is like a quality assurance that the Cisco partners have given the right stuff to their customers.

This product doesn't work in isolation. For example, when we talk of posturing the Microsoft updates, the system that does automatic updates for Microsoft needs to work in an ideal fashion. The antivirus needs to work. OF course, the antivirus is not Cisco. Those products need to work as they should so that integration of the ISE product will work as well. When all factors are held constant, Cisco works well. 

View full review »
LC
Network & Security Architect at Canac IT

The web interface needs improvement. The new web interface that they have is not as easy to manage and we find it to be very slow.

The solution might require two authentications. They should make a new authentication to authenticate both the device and the users. Right now, we are authenticating the PC, the workstation, but not as a user. A good addition would be to authenticate the user separately to get more information.

View full review »
RO
Manager of Systems Architecture at a computer software company with 51-200 employees

The upgrades could be better. Every time we try to do an upgrade, we have problems. It's a pain.

View full review »
MB
Accounting Executive at a tech services company with 11-50 employees

As far as what could be improved, to continually be thinking about ransomware, cyber attacks, and all those kinds of things. They always have to be innovating. Always have to be improving. I can't give you anything specific because these cyber guys are always coming up with new ways to get in. You just really have to be aware of what's going on.

In the next release, I would want to see this kind of solution in the cloud as opposed to on prem because when enhancements are made to the software, if it's in the cloud, it's overnight. I mean you're not going to have to respin the servers that the license sits on, it's all microservices kinds of things in the cloud. That would be my recommendation. If I'm a customer, that's what I'm looking at - for cloud based software subscriptions.

View full review »
BN
Senior Software Engineer with 501-1,000 employees

This solution has enhanced features that make it difficult to use. To make it easier, it should be made without PxGrid.

It should be able to work with third-party routers and switches. We want to work in an environment where there are multi-vendors that require PxGrid.

Their software-defined access is not easy to implement. You have to have a good understanding of how to implement it. It would be helpful if they could make it easier for the customer to adopt.

Third-party integration is important, as well as the continuous adaptation feature, which is the AIOps. It would be helpful to include the AIOps.

View full review »
SN
Sr Manager Infrastructure at a financial services firm with 5,001-10,000 employees

The intuitiveness of the user interface could be improved. They could also make the deployment process more user-friendly.

View full review »
NH
IT Manager at cmc

The interface could be more user-friendly and the ability to apply rules to MAC addresses, for example, if I wanted to allow a certain MAC address access at a particular time I cannot make this adjustment.

In an upcoming release, they could improve by providing rule-based bandwidth consumption, bring your own device (BYOD) need to be more mature, and the reports could be more user-friendly.

View full review »
MN
Network Architect at a tech vendor with 10,001+ employees

It could be more intuitive in terms of how to configure the policies.

View full review »
WH
Network Manager at a university with 501-1,000 employees

Cisco ISE has almost all the features we are looking for now, but sometimes the configuration, such as the conditions, is a little difficult to understand and not so easy to navigate.

View full review »
Chinthaka Kannangara - PeerSpot reviewer
Network System Engineer at VSIS

The licensing documentation needs to be better. We found some old documents describing the license names, like the Base license and Apex license. Cisco used both names. We have found that they changed the Advantage license and Premier License. If someone misunderstands that, they might end up with a hassle. I don't know if it's possible or not for Cisco to remove the older documents from the official website.

View full review »
RM
Sr Consultant at a tech services company with 10,001+ employees

Cisco ISE could be simplified somewhat. I would also prefer certificate-based authentication over confirmation-based authentication for all the processes. It's possible for us to do a workaround, but the process needs to be simplified. 

View full review »
TB
Senior Enterprise Network Administrator

The UI and UX could be more seamless and easier to use.

View full review »
JM
Network Specialist

The area where things could be improved is education. It's complicated to deploy initially because you have to know what you're getting into. That's true with any customer. I don't know them so I have to learn about them. I have to figure it out, but there are very limited windows to do that. If a customer's going to hire you, you are the professional. You should know this already. You should come in with a base knowledge of what you need to do and, after that, grow with the customer. More education is how it can be improved.

View full review »
FC
Director of Engineering at a tech services company with 51-200 employees

Documentation is probably the worst part of the software.

View full review »
MN
Chief ICT Specialist at a government with 10,001+ employees

The admin interface is really slow. It's horrible.

View full review »
SI
Security Solutions Architect at GTS

I would like for the next release to be easier to implement and to limit its dependencies around ISE, Windows, the network as a whole, etc.

View full review »
JC
Project Manager at Projectnet

There should be better documentation on the implementation of the solution. I learned how to implement it from watching videos. I felt the documentation was too complicated and I also learn better from watching videos.

In my experience, there needs to be better documentation for firewall integration as well, we had some trouble early on.

View full review »
TP
Technical Systems Analyst at NJC

I'd like to see an easier way to upgrade to larger versions, as well as more best practices that are easier to locate on their support page.

View full review »
Gerald Jimenez - PeerSpot reviewer
IT Operations Supervisor at Aboitiz Equity Ventures, Inc.

There are still some bugs in ISE that need to be worked out.

View full review »
RF
Cyber Security at a manufacturing company with 10,001+ employees

As I treat the system basically as a user would, and am not overly technical, I can't say what features, if any, the solution is missing.

I'm working from China currently and the only real issue is that, within the country, there's some concern around Cisco and its ability to offer the solution for the long term. As the United States has banned the Huawei version in their country, we feel there may be retaliation in ours and Cisco will get banned as a countermeasure from the government. The future of Cisco in China is in question. Our local partners are worried about the situation.

View full review »
Joni Saputro - PeerSpot reviewer
System Engineer at Packet System Indonesia

You have to restart the system to change the DNS or NTP server.

View full review »
ME
Smart Information and Communication Technology Engineering student at INPT

Although the solution is easy to implement it's not so easy to understand. You need to be able to figure out the protocols, the nodes, and the personals of the nodes in order to implement correctly and make good use of it. Because it's a Cisco product, if you're not in a Cisco environment, it's difficult to integrate with anything else, so the big concern is its interoperability with other technologies and other vendors. 

View full review »
LR
Director of Security and Computer Risks at Eclipse Telecomunicaciones S.A. de C.V.

The price could be better. I would like to see more integration with third-party solutions in the next release. This is because many of my clients don't have Cisco.

View full review »
FA
Networks Lead Engineer at a mining and metals company with 1,001-5,000 employees

They need to simplify the processes and management more, as well as the platform. Their user experience is a bit complicated, and it's not easy to manage. They need to do something to enhance the management console and make it more simple and easier to use.

I need to see stronger integration with Cisco SDN. Instead of treating it as a separate appliance, it should be a built-in feature in the SDN solution. This is one of the things that will reduce the complexity of Cisco's architecture. Instead of having multiple appliances, and getting lost in-between, and not knowing where is the problem is, everything can just be in one place. It will be better to move this feature or this technology as a built-in technology in the SDN solutions, similar to DNA and ACI.

The pricing and licensing structure are not ideal for customers.

View full review »
Brook Debebe Hailu - PeerSpot reviewer
Chief Technology Officer at Mehbub General Trading PLC

In an upcoming release, the solution needs to be more agentless and more independent. Additionally, there could be improved integration with other next-generation solutions, such as Palo Alto, Fortinet, or Check Point.

View full review »
FS
Deputy Head of IT at a legal firm with 501-1,000 employees

It is too complex. It should be easy to use. We are not such a big team. We only have three engineers to work with this, and we don't use all of the functionality of the product. Its range of functionality is too wide for us, and this is the reason why we are thinking of switching to a more simple product. We have shortlisted a Microsoft solution. We have a big footprint for Microsoft products, especially in security. As a global strategy, we try to leverage to the maximum what is possible around Microsoft.

View full review »
it_user808431 - PeerSpot reviewer
Solutions Manager at EOH

So far we have had no complaints from customers. No major complaints in terms of ISE. They do complain obviously if the ISE service stops working. Normally that happens if there's a server flaw or some problem at the data center somewhere. 

There can more integration between the wireless controller management and ISE. Consolidation or integration of the controller and ISE dashboards would be great. It's not that bad but would make for simplified support if it could be combined into one dashboard.

View full review »
DG
Sr.Manager at a energy/utilities company with 10,001+ employees

The solution could be more secure.

View full review »
SS
Deputy Manager at Convergent Wireless Communications

The initial setup could be simplified.

The support could be faster and the pricing could be reduced.

View full review »
Can Aksaya - PeerSpot reviewer
Network Solutions Architect at turcom

Compatibility with other vendors is what needs to be improved in Cisco ISE (Identity Services Engine). We should be able to use it with other vendors, for all specifications. There should be integration with different vendors, e.g. Cisco ISE (Identity Services Engine) working with AccuPoint networks.

View full review »
MK
Co-Founder & Director at VSAM Technologies

I have not come across any missing features. 

It would be ideal if Cisco could provide some short training videos or documentation to customers to help them understand how to use the product. 

View full review »
MA
Supervisor IT Security at a government with 1,001-5,000 employees

An area that could be improved is the agent. The challenge now is that agent and most of the computers have changed. They could think about agent-less deployment. Also, I've not explored MDM but if it should be integrated. 

View full review »
RF
Information Security System Specialist at everis New Company Erifson

They should improve the upgrades. It's not easy to upgrade the solution. 

View full review »
it_user302130 - PeerSpot reviewer
Security Senior Network Engineer with 1,001-5,000 employees

We are waiting for TACACS integration to completely replace the Cisco ACS line of products.

View full review »
JF
Works

The compliance and posture don't always work. They should make it more stable. With each upgrade, we lose some functionality. We have to wait for another upgrade.

I would like to see them develop some type of device management, like an iPad feature, just to be able to give security access to certain devices for management. Mainly for the suppliers and the third parties.

Another feature I would like to see would be for them to create the ability to integrate with other products from the start. We always search for products that integrate with us and so it would ease the management and then everybody would be entered. 

View full review »
RD
Senior Network Administrator at a media company with 1,001-5,000 employees

In an upcoming release, it would be nice to have NAC already standard in the solution.

View full review »
OZ
Network & Security Engineer at a engineering company with 201-500 employees

One of the main issues in  Cisco ISE (Identity Services Engine) is that it lags excessively.

Sometimes Cisco ISE (Identity Services Engine) just doesn't work properly, due to misconfiguration.

I would like to see the product simplified more, especially with the configuration.

View full review »
HA
Technology Manager at Advanced Integrated Systems

Segmentation can be improved. They can also improve security policies for each group of users, and automation can also be better. The software interface could be better. They should make it easier for users to find features.

View full review »
HA
Technology Manager at Advanced Integrated Systems

The ISE software needs to be improved  in role to be easier to administer. SOftware enhancement required to have easier way to find the featured required to implement and also need enhancement of features sorting. Completing processes can be complex when try to implement some solutions. also steps are complex and the troubleshooting as well. As an example, if you intend to make AAA policy and enforce it on a group of users, you will find the software very confusing................................

View full review »
Ntwrkengine0887 - PeerSpot reviewer
Senior Network Engineer at a comms service provider with 1,001-5,000 employees

Cisco ISE is complex. The deployment and design of networks with it is so complex. If it could change it would be better. 

It needs a better solution for reduced complexity.

I think to add more people to four-thousand users is going to be hard. Cisco needs to make it easier to add more people.

View full review »
it_user146331 - PeerSpot reviewer
Senior Network Operations Specialist at a government with 1,001-5,000 employees

Cisco ISE has improved performances on Access Switches and closely monitored the daily suspicious or rogue activities within the organization.  

View full review »
PP
Owner at a tech services company with 11-50 employees

Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things. Whenever we choose a product, it's very difficult because we have to meet the requirements of each feature. There is no standard feature, so the best system that we bought may not fit the solution. 

We have to look at every feature that the customer uses. If you compare it with other products like Aruba, it's not the same. With Cisco, I have to read all about the features on this version and the licensing required for the product. In Aruba, that thing is covered when you get one license because it covers almost everything. It could also be more scalable.

View full review »
EA
Principal ICT Assistant at a educational organization with 1,001-5,000 employees

I would like the product to include support for OSVS version three.

View full review »
SK
Security Engineer at a energy/utilities company with 201-500 employees

Since we have started, we struggled a lot to implement this solution into our network, and we opened a case a couple of times. Up until this point, nothing else needs to be improved with this product.

View full review »
it_user216399 - PeerSpot reviewer
Senior Network Engineer with 1,001-5,000 employees

It is quite complex when it comes to troubleshooting.

View full review »
DG
Technical Solutions Architect at a wholesaler/distributor with 201-500 employees

The user interface could be improved to make it more user-friendly.

View full review »
AH
Network Administrator at a government with 51-200 employees

It has many complications from the administration perspective, it's not easy to learn. Not like other solutions that are very friendly and easy to go through. It needs to be more user-friendly. We'll see the same name on more than one tab so we need to realize why that name is there or why only the main tab is not like the other. I cannot believe that Cisco is the best case of security integration however it is easier to implement.

They are good at integration, I do not expect more from them in that regard. They could think about developing VXLAN. They have LDN switches, we need to get into contextual switches, not catalyst switches. Normal switches. I wish they could explore developing more VXLAN options.

View full review »
it_user375078 - PeerSpot reviewer
Senior Network Engineer/Mobility Specialist at CCSI - Contemporary Computer Services, Inc.

The learning curve is steep and the initial setup is complex.

View full review »
it_user375078 - PeerSpot reviewer
Senior Network Engineer/Mobility Specialist at CCSI - Contemporary Computer Services, Inc.

The product has improved with its evolution. The initial setup, though, is extremely complex.

View full review »
MB
Senior Solutions Manager at a computer software company with 1,001-5,000 employees

It is a good product, but in order to use all of the functions of the product, you must have a good understanding of the product. You must know how to use and manage it. It is a little bit complicated to configure and manage. It must be simplified to make it easy to manage for end users. In the initial stage, we found ISE complicated for end users. It was not easy to manage it or to write authentication and authorization protocol. They must improve its management and make it easy for end users. 

The monitoring and reporting capabilities can be improved because end users want to quickly see what is happening in their network. There were some restrictions in working with other vendors. It should also have a better and easy integration with other vendors. 

View full review »
JL
Unified Networks at a program development consultancy with 11-50 employees

There should be an easier way to do the upgrades. Customers were having issues going from one version to the next. There are a lot of steps to get to the next version from the previous version which ends up being a bit of the headache with the upgrade. 

View full review »
BE
Network Security Engineer at Data Consult

I would like for them to improve the reporting. 

View full review »
CR
Cyber Transport Specialist at a government with 10,001+ employees

Whenever we see the authentication logs, we can't see what device we're logging into. It shows us the main server, but we don't see details like, "It's in building 200," or that kind of thing. We can't see the IP address. We can see who logged in, but we can't see the IP address of the device.

I'm sure that's available. We just haven't figured out how to properly deploy it.

View full review »
SZ
Team Lead Network Infrastructure at a tech services company with 1-10 employees

The solution isn't as dynamic as it could be. There are some limitations, specifically around switches. 

Deploying to a machine, as opposed to a dedicated appliance, can be a bit difficult. 

The network solutions need to be improved by Cisco.

View full review »
PA
IT Specialist at Armstrong flooring, inc.

The stability of this solution needs to be improved.

It should not be necessary to go to each individual set of alarms and acknowledge them in order for them to go away. There should be a single button that can be pressed to dismiss all of the alarms at once.

View full review »
AA
Network Engineer at a financial services firm with 1,001-5,000 employees

The software is a little bit complicated to understand in the beginning, meaning the implementation. It needs proper documentation so that we can understand the options more easily.

View full review »
it_user683622 - PeerSpot reviewer
Presales Systems Engineer at a tech services company with 501-1,000 employees

There are issues with respect to the posture assessment function. It's been observed that customers are not receiving total access to the network because the assessment agent is glitchy and malfunctions from time-to-time. I would like to see refining of the compliance assessment and adding more detailed compliance of endpoints on the user end.

We have also had to deal with some cache update issues in conjunction with Cisco's tech support team. Unfortunately, they had trouble providing suitable solutions within specific and desirable time frames.

The next release should offer more inter-operability, increased cross-integration functionality. 

View full review »
it_user690516 - PeerSpot reviewer
Manager - IT Security & Process Compliance at a tech services company with 1,001-5,000 employees

Support and integration for the active devices needs to be worked on. Their features mainly work well with Mac devices. If we use an HP the Mac functionalities may no longer be able to deliver.

View full review »
it_user866460 - PeerSpot reviewer
Architect of Security and Networking solutions (Presales and after sales) at a comms service provider with 1,001-5,000 employees

In a future release, I would like to see network access control. That is something that customers seem to be looking for.

View full review »
AR
VP of IT at a tech services company with 51-200 employees

The user interface can be improved.

View full review »
it_user816279 - PeerSpot reviewer
Research Engineer with 1-10 employees
  • The Cisco wireless controller needs to add more than one physical port.
  • The Guest Network verification needs to add a QR code option.
View full review »
Buyer's Guide
Cisco ISE (Identity Services Engine)
April 2024
Learn what your peers think about Cisco ISE (Identity Services Engine). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.