Supervisor IT Security at a government with 1,001-5,000 employees
Real User
Easy to use and has good support but is complex to set up
Pros and Cons
  • "Easy to use and provides good support"
  • "An area that could be improved is the agent. The challenge now is that agent and most of the computers have changed. They could think about agent-less deployment."

What is our primary use case?

We primarily use the solution for network admission control.

How has it helped my organization?

Previously, what used to happen is that we use to have anyone - any user, a staff member or a non-staff member, consultant contractors, etc. able to connect to our line without authentication, which I think posed a security risk. We felt that whoever connected to our network should be authenticated. We should know the person. We should have visibility to see who was connecting to our network so that we can detect anomalies. Now, we have different profiles, of different users and staff and for contractors or others. So, depending on the profile, there's control on the access that you can get.

What needs improvement?

An area that could be improved is the agent. The challenge now is that agent and most of the computers have changed. They could think about agent-less deployment. Also, I've not explored MDM but if it should be integrated. 

For how long have I used the solution?

I have been using the solution for 5 years.
Buyer's Guide
Cisco ISE (Identity Services Engine)
May 2024
Learn what your peers think about Cisco ISE (Identity Services Engine). Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,292 professionals have used our research since 2012.

What do I think about the scalability of the solution?

In terms of scalability, I think it's scalable. Quite scalable and very intricate. Easy to use and provides good support. 

How are customer service and support?

We've had many issues with technical support but from the local vendor, we do get a lot of support which is good. The fact that we also did some training helped. We normally don't have so much trouble when we rescale. We see that we can fix it and then if there are issues, with the vendors and their help, we can rescale it.

How was the initial setup?

Initially, the setup is a bit complex but that depends on the vendor. Maybe because of the complexities around it. Sometimes I think it's about how the best project team really does it.

What about the implementation team?

The person who was put in place to implement it couldn't. So we got another vendor who was good and was a lot more experienced. It's a very new feature so we're hopeful here in Uganda. My country only has about maybe 2 or 3 clients. Those are the ones I know about, our team being one of them.

What other advice do I have?

The deployment strategy was faster than the pilot. We had to see how it works and then we had to, in a transparent manner, see how it works. Deployment took about six months. But the rollout is on-going because we keep opening branches all the time, so we just keep adding them into the solution. For deployment, we used the front liner support but for documentation, we had professional staff. For deployment and maintenance, we have a small team of maybe about five to ten. 

I would give the solution 5.5 out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Information Security System Specialist at everis New Company Erifson
Real User
Enables us to distribute internet access to guests and has a good profiling feature
Pros and Cons
  • "It is scalable because we use a network load balancer at the front of the PSN. It can be extended as we want to multiply. It's scalable to our environment. We have around 8,000 users and we are planning to expand it."
  • "They should improve the upgrades. It's not easy to upgrade the solution."

What is our primary use case?

We use it to aid the tools that we make and to sponsor and get flow.

How has it helped my organization?

We distribute internet access to guests. It's the product to our environment.

What is most valuable?

The profiling option is the most valuable feature. 

What needs improvement?

They should improve the upgrades. It's not easy to upgrade the solution. 

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

It's stable. 

What do I think about the scalability of the solution?

It is scalable because we use a network load balancer at the front of the PSN. It can be extended as we want to multiply. It's scalable to our environment. We have around 8,000 users and we are planning to expand it. 

How are customer service and technical support?

I opened some tickets with them and I had no problems. They are engineers from India and the U.S and they perform well.

How was the initial setup?

The initial setup was complex. The deployment took around one year. 

What about the implementation team?

We used an integrator for the deployment. They didn't know a lot about the solution so we had to learn about it ourselves and helped them.

What was our ROI?

We have seen ROI from this solution. 

What's my experience with pricing, setup cost, and licensing?

We use a virtual machine so in terms of pricing, we can extend it as much as we need. The licensing; we had to renew twice and in my opinion, it's good.

Which other solutions did I evaluate?

We also looked at ForeScout but we preferred Cisco ISE. 

What other advice do I have?

I would rate this solution a ten out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco ISE (Identity Services Engine)
May 2024
Learn what your peers think about Cisco ISE (Identity Services Engine). Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
770,292 professionals have used our research since 2012.
PeerSpot user
Security Senior Network Engineer with 1,001-5,000 employees
Real User
We use it for implementing wireless 802.1X with Active Directory and guest portal, but we're waiting for TACACS integration to completely replace the Cisco ACS line of products.

What is most valuable?

  • I'ts compatibility with 802.1X
  • Posture
  • Profiling
  • Guest Portal

How has it helped my organization?

As an integrator, I can tell that this product is mostly used for implementing wireless 802.1X with Active Directory and guest portals. It can be integrated with Active Directory and an external SMS gateway, can be used to track user authentications with Cisco WLC, can be therefore used to completely implement BYOD (considering the tight integration with leading MDM vendors). The product can be bought as a physical appliance as well a virtual appliance.

What needs improvement?

We are waiting for TACACS integration to completely replace the Cisco ACS line of products.

For how long have I used the solution?

I've used it for about four years.

What do I think about the stability of the solution?

Being a product relatively young the product seems incredibly stable and not prone to system outages.

What do I think about the scalability of the solution?

Having a Cisco consolidated experience with this type of products, the product encounters very little of no scalability problem.

How are customer service and technical support?

Cisco has implemented a special ATC partner program to help partners and customers to have a smooth deployment. As far as I know there is also a dedicated TAC area for this product, Cisco commitment on the ISE line of product is really at a top level. I can say this with an high degree of certainty being a Cisco Gold Partner.

Which solution did I use previously and why did I switch?

We use this product because we mainly sell this as a premier class NAC solution, compared to other similar products.

How was the initial setup?

The initial setup is very straightforwardly done by following the product’s document guides.

What about the implementation team?

I work for a vendor/system integrator.

What other advice do I have?

The main advice is to seek for an accredited ATC system integrator with a large ISE portfolio.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a Gold Partner and an authorized ISE system integrator.
PeerSpot user
Real User
All devices have multifactor authentication in collaboration with IT which secures access to all our devices
Pros and Cons
  • "For device administration, all devices have multifactor authentication in collaboration with IT, so it secures access to all of our devices. For guest and wireless access, it's a matter of a lowly manager who we give access to the portal and he can assign access to the guests, so it's a very simple process now. It keeps the IT focusing on their work, and gives the business people the right access."
  • "The compliance and posture don't always work. They should make it more stable. With each upgrade, we lose some functionality. We have to wait for another upgrade."

What is our primary use case?

My primary use case of this solution is for access control for authentication and for the authorization of wireless users.

How has it helped my organization?

For device administration, all devices have multifactor authentication in collaboration with IT, so it secures access to all of our devices. For guest and wireless access, it's a matter of a lowly manager who we give access to the portal and he can assign access to the guests, so it's a very simple process now. It keeps IT focusing on their work, and gives the business people the right access. 

Also, with BYOD mobile users can work easier and in a more secure way. For the places in public access we're securing our network socket, so now not everybody can plug in and log into our network due to this feature. It's making it more secure for headquarters.

What is most valuable?

  • BYOD service
  • The guest and secure wireless access
  • Compliance and posture
  • Wireless administration

What needs improvement?

The compliance and posture don't always work. They should make it more stable. With each upgrade, we lose some functionality. We have to wait for another upgrade.

I would like to see them develop some type of device management, like an iPad feature, just to be able to give security access to certain devices for management. Mainly for the suppliers and the third parties.

Another feature I would like to see would be for them to create the ability to integrate with other products from the start. We always search for products that integrate with us and so it would ease the management and then everybody would be entered. 

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

It's 99% stable. 

What do I think about the scalability of the solution?

It's scalable. We have more than 500 users. We are planning to use more features and to integrate it with other branches that we have. It's a way to have a global solution across all branches.

How is customer service and technical support?

Technical support is okay. Sometimes it takes a long time for them to respond. We'll usually end up solving our own issues. The response time should be shorter. 

How was the initial setup?

The initial setup was complex. It took time to have a stable environment but once it stabilized, it was great. Although, we had six to seven months of an unstable system. 

What about the implementation team?

We deployed through a reseller, they were good. We require two staff members for maintenance.

What was our ROI?

Our ROI is good enough. It's simplifying things for IT and for the business, so it's good for both sides. It solves a lot of issues that without the product would be costly to our organization so we see ROI in that sense. 

What's my experience with pricing, setup cost, and licensing?

Licensing is very complicated and it changes a lot. I know recently it changed since we acquired the solution. It had a different licensing scheme that has changed. 

The cost is high compared to other solutions. Even so, it is better than what's on the market. The licensing model is complicated and the cost is a little bit high.

What other advice do I have?

It's a great product but you should be careful to plan before deploying. Do thorough planning as not to do the same error that we did. We didn't do enough planning before deploying so it took us a long time to have a thorough plan. 

I would rate this solution a nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Network Administrator at a media company with 1,001-5,000 employees
Real User
Useful portal, helpful support, and priced well
Pros and Cons
  • "The WiFi portal in Cisco ISE is very useful for WiFi customers."
  • "In an upcoming release, it would be nice to have NAC already standard in the solution."

What is our primary use case?

We use Cisco ISE for authentication for VPN and network management.

What is most valuable?

The WiFi portal in Cisco ISE is very useful for WiFi customers.

What needs improvement?

In an upcoming release, it would be nice to have NAC already standard in the solution.

For how long have I used the solution?

I have used Cisco ISE within the past 12 months.

What do I think about the stability of the solution?

Cisco ISE has been stable.

What do I think about the scalability of the solution?

I have found Cisco ISE to be scalable.

We have two of the Cisco ISE devices installed.

How are customer service and support?

The technical support has been good.

What about the implementation team?

The solution does not require a maintenance or support team.

What's my experience with pricing, setup cost, and licensing?

There is a license to use this solution and the price is reasonable.

What other advice do I have?

When someone is implementing this solution the difficulty depends on where they started. We started with zero and there was a very large learning curve. However, once they understand how it works, it's straightforward. There is a sharp learning curve to start working with it.

I rate Cisco ISE an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Network & Security Engineer at a engineering company with 201-500 employees
Real User
Excessive lagging, expensive, complicated installation, but has good features and support
Pros and Cons
  • "The RADIUS Server holds the most value."
  • "I would like to see the product simplified more, especially with the configuration."

What is most valuable?

The RADIUS Server holds the most value.

The TACACS feature in ISE is good.

We also use the Posture feature to control the environment.

The product features are quite good.

What needs improvement?

One of the main issues in  Cisco ISE (Identity Services Engine) is that it lags excessively.

Sometimes Cisco ISE (Identity Services Engine) just doesn't work properly, due to misconfiguration.

I would like to see the product simplified more, especially with the configuration.

For how long have I used the solution?

I have been working with Cisco ISE (Identity Services Engine) for approximately two years.

We are using version 2.7 Patch 2.

What do I think about the scalability of the solution?

Cisco ISE (Identity Services Engine) is easy to scale.

I have approximately 450 Apex end-based licenses.

Currently, we don't have plans to expand.

How are customer service and support?

Technical support as always is one of the best.

How was the initial setup?

The initial setup was a bit complex. It took us three to four weeks to complete the setup and get it up and running. We had help from the reseller.

It was deployed by a vendor.

What about the implementation team?

It was installed by a vendor.

What's my experience with pricing, setup cost, and licensing?

It's a bit expensive, especially the licensed product.

The hardware is purchased one time. 

The support license is reasonable, but when compared to other products, such as ClearPass or Fortinet, the base license for users is much lower in other products. In general, Cisco is more expensive.

I would like to see one license based on one user. We do not need to use multiple licenses in order to have multiple features in the product.

One of the issues in ISE is that if you need more features you have to have multiple licenses per user. One user can have three or four licenses. 

It would be beneficial to have a single license that included all of the features.

Which other solutions did I evaluate?

We are currently trying to deploy Fortinet network access control. The support from Fortinet is disappointing.

We are in the testing phases, but there is a good possibility that we will go with Fortinet.

We have not used it yet. We will try the POCs this week coming.

What other advice do I have?

I would suggest having an experienced engineer implement the product. If there is an error when implementing, you will experience many issues, especially lagging.

If it was well implemented I would rate it a nine out of ten, because it's good.

Cisco ISE (Identity Services Engine) is used in large enterprise companies. In our company and with our implementation, I would rate  Cisco ISE (Identity Services Engine) a four out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Technology Manager at Advanced Integrated Systems
Real User
A stable and scalable network administration solution with a valuable guest access feature
Pros and Cons
  • "I like the guest access feature, which has been important for us."
  • "Segmentation can be improved."

What is our primary use case?

The primary use case is to have network access control and automation to integrate with the enterprise network. It also helps provide a method to make segmentations between users and enable access control.

How has it helped my organization?

Cisco ISE has provided more mobility for the organization while controlling access no matter how the users connect to the network.

What is most valuable?

I like the guest access feature, which has been important for us. The BYOD feature is also good. 

What needs improvement?

Segmentation can be improved. They can also improve security policies for each group of users, and automation can also be better. The software interface could be better. They should make it easier for users to find features.

For how long have I used the solution?

I have been working with Cisco ISE for more than three years, but in general, I have more than 20 years of experience working with Cisco.

What do I think about the stability of the solution?

Cisco ISE is a stable solution.

What do I think about the scalability of the solution?

Cisco ISE is very scalable.

How are customer service and technical support?

Cisco technical support is very good.

How was the initial setup?

The initial setup is complex, and you can't easily find the features you want.

What about the implementation team?

If we're talking about a medium enterprise and there is a greenfield, it can take between one or two weeks.

What's my experience with pricing, setup cost, and licensing?

I think the price is okay.

What other advice do I have?

I advise new users to go through the admin guides for implementation and follow the script very carefully.

On a scale from one to ten, I would give Cisco ISE an eight.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Technology Manager at Advanced Integrated Systems
Reseller
Good integration, visibility, and automation
Pros and Cons
  • "The most valuable feature is the integration with StealthWatch and DNA as one fabric."
  • "The ISE software needs to be improved so that it is easier to administer."

What is our primary use case?

We are a system integrator and Cisco ISE is one of the products that we sell and implement at our customers side. I have built ISE's POC and provided training to our customers.

I also used real rent lab which was including; Active Directory integration, network access and core switches, access points, wireless access controller, and end points. (some end points have cisco client - anyconnect, and have not), and Web Server for creating wireless authentication portal solution end to end

The AAA features were awesome and have important attributes, and also the security groups (SGTs) concept to enforce policies for each group of users, regardless they coming via wired or wireless network devices. also i see the guest authentication is very rich and easy tom implement 

How has it helped my organization?

Cisco ISE offer one central point to create different policies for different group of users and enforce policies to each entity regardless it connected to network through wired or wireless network devices. it provide in this way more mobility and wireless-wired converged network. Also it integrates very well with network devices to control ports configurations services authentication and authorization. ISE also integrate with DNA center and stealthwatch to enable customer have SDN (Software defined Network) Fabric. 

What is most valuable?

Combines authentication,authorization,accounting(AAA),posture,and profilerinto one appliance

Provides for comprehensive guest access management for Cisco ISE administrators.

Enforces endpoint compliance by providing comprehensive client provisioning measures and assessing the device posture for all endpoints that access the network,including 802.1X Environments

EmploysadvancedenforcementcapabilitiesincludingTrustsecthroughthe use of SecurityGroup Tags(SGTs) and Security Group Access Control Lists (SGACLs)• Supports scalability to support a number of deployment scenarios from small office to large enterprise environments

What needs improvement?

The ISE software needs to be improved  in role to be easier to administer. SOftware enhancement required to have easier way to find the featured required to implement and also need enhancement of features sorting. Completing processes can be complex when try to implement some solutions. also steps are complex and the troubleshooting as well. As an example, if you intend to make AAA policy and enforce it on a group of users, you will find the software very confusing................................

For how long have I used the solution?

I have been using Cisco ISE for three months.

Which solution did I use previously and why did I switch?

We did not use another similar solution prior to this one.

How was the initial setup?

The initial setup was fine.

What's my experience with pricing, setup cost, and licensing?

The price for Cisco ISE is high.

Which other solutions did I evaluate?

We did not evaluate other options before adopting this solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: My Company is Cisco Reseller
PeerSpot user
Buyer's Guide
Download our free Cisco ISE (Identity Services Engine) Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Cisco ISE (Identity Services Engine) Report and get advice and tips from experienced pros sharing their opinions.