No more typing reviews! Try our Samantha, our new voice AI agent.
Infrastructure and Cybersecurity Manager at George Washington's Mount Vernon
Real User
Jul 29, 2020
We've experienced first-hand the reliable protection provided against malware and ransomware
Pros and Cons
  • "The solution cuts down on the repercussions of getting malware or ransomware."
  • "Now that we have it in, I feel it's pretty much a game changer on locking down our network so that we're not penetrated from inside or outside because everything going through the VPN has to meet a certain standard."
  • "The solution can lag somewhat as we have a large database."
  • "Because we have a large database and 4,000 network devices, the solution can lag a bit when you're running updates or different things because of the fact that it's so big and it is such a resource hog."

What is our primary use case?

We have two servers and they're both VMs. Every network system is issued a certificate and each device coming onto the network has to be on the domain with an active AD user logging into it. It needs an up-to-date AMP, which is our Cisco malware and virus scan product and it also needs to have the most current Microsoft security updates and the three layers that we're using: The core VPN, the Network Access Manager and the ISE profiler. When it goes through all those different things on every port on the switch, there are commands for it to be able to go through an ACL so it knows what users are there, what server, and what devices have been put onto the domain. It can verify all that.

The user can then proceed on to the network. We've set it so that regular users are VLAN'd off and can only see the data network through ISE and are blocked from seeing the rest of the network. Depending on the department needs or other factors, we have cameras for security which are on a different VLAN, and they can see those. We also have something for O&M where the AC guy can see the AC equipment, and we can prevent all the VLAN's from being viewed by everybody.

We are customers of Cisco and I'm the infrastructure and Cyber security manager.

What is most valuable?

The solution cuts down on the repercussions of getting malware or ransomware which happened to us four years ago. We regularly took very aggressive snapshots and we were able to recover in an hour and 20 minutes without any loss of data.

What needs improvement?

Because we have a large database and 4,000 network devices, the solution can lag a bit when you're running updates or different things because of the fact that it's so big and it is such a resource hog. But the biggest problem we've encountered is that it finds errors or people are rejected or not authenticated without a clear explanation as to why. A second issue is that we're currently on 2.4 and Cisco's gold standard now is 2.7. They are a little slow with that.

I'd really like the solution to dive down a little deeper when something's not profiling. As it stands now, you have to go through and search what hasn't profiled. Microsoft, for example, gives you a direction to look at and will even be specific sometimes and tell you there is a password error, or the password hasn't been updated, or it's not meeting the policy and that's why it won't let it through. Those are very helpful because you know exactly what's required to solve a problem. 

Cisco is getting better with it, but they fail in some areas because of a network connectivity issue, or it's not getting DCAP quick enough and it fails. Those things would be more helpful to understand when it's going through, so you are able to triage it a little better. I mean, it does point you in a direction, but sometimes you have to dig a lot deeper to find the right direction and figure out what kept it from profiling. One big issue we've discovered is that people are not rebooting their machines or powering them off at night. We're trying to ensure that is done by sticking messages on screens.

For how long have I used the solution?

I've been using this solution for the past two years. 

Buyer's Guide
Cisco Identity Services Engine (ISE)
May 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,311 professionals have used our research since 2012.

What do I think about the stability of the solution?

ISE is pretty stable. If it does have an issue then you need to call TAC and work through the bug in it. They are very responsive and very quick to help us eliminate the issue and also come up with a plan, such as how to move forward with additional issues or different things that are coming down the pipe with Cisco ISE. When you're talking to them, you feel like they are a partner and not just a disconnected entity.

How are customer service and support?

The technical support is excellent, I would rate them very highly.

How was the initial setup?

The initial setup is very complex. You have to go in and manually add in all the network devices, as far as all the switches, access points are concerned. You have to go port by port and add in codes and conditions and you have to go switch by switch and add in codes and conditions. You start out with a monitor mode and then go to an impact mode and then you go towards total lockdown. Implementation took us about 18 months. We rolled it out in short bursts because we have a very small IT team and we had a consultant company come in and work with us on installing it. A lot of it was knowledge transfer from them to us.

Our consultant was Cycorp, their main focus is network security. They are a sister Cisco partner, and we had one of their CCIE's come out and help implement everything. The gentleman at the top of the CCIE, was a former Cisco employee and a beta tester for ISE. Now that we have it in, I feel it's pretty much a game changer on locking down our network so that we're not penetrated from inside or outside because everything going through the VPN has to meet a certain standard.

What's my experience with pricing, setup cost, and licensing?

We did a five year deal and it was very reasonable. I think for the Avast virus scan, I think we were paying $95 a machine for five years, which nobody else could touch. And that includes all updates, technical support, etc. From the ISE side, I'm not really sure what it costs because it was all encompassed in equipment we were buying and the ISE and the AMP and the open DNS. I know that it was not more expensive than any of the things we had looked at with HP or BMC or other places. It was much more cost effective.

Which other solutions did I evaluate?

We have looked at other products but we are a Cisco shop so having a Cisco product rides very easy on all our switches, our access points, and our Cisco servers. I believe it's the same for other companies such as HP. It's also a priority for them that the solution works better with HP switches. Given that we weren't going to change our switches, we really needed to focus on something that was going to work well with our environment.

What other advice do I have?

The important thing is to have a good game plan going into it. Prep is key for everything going on with ISE. The more stuff you have prepped and the more understanding that you have upfront of how it goes through and how it behaves, the better off you are.

I would rate this solution a nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Batu Akalin - PeerSpot reviewer
Corporate Information Technology Security Manager at AG ANADOLU HOLDİNG A.S.
Real User
Jun 27, 2020
Integrates well with other Cisco products, but they need to provide better network visibility and also release an agentless version
Pros and Cons
  • "The features that do work, work well, and we use it on a daily basis."
  • "This is a stable product and the features that do work, work well, and we use it on a daily basis."
  • "The interface is not very user-friendly and it is not simple to use."
  • "The initial setup is not simple. I don't consider our deployment to be complete because we were unsuccessful at trying to use the majority of the features."

What is our primary use case?

We use Cisco ISE for 802.1 network authentication.

What is most valuable?

ISE integrates well with other Cisco products.

What needs improvement?

This solution does not provide us with enough visibility into our network. We would like to see additional information that it does not show. In general, the reporting is not very useful.

ISE needs to have better integration with third-party products.

A basic profiling engine would make a good addition because device profiling is very important.

This product requires the use of agents and ideally, I would like an agentless version. I think that they should get rid of them because they are hard to manage and deploy. Also, they are not useful.

The interface is not very user-friendly and it is not simple to use.

For how long have I used the solution?

I have been using the Cisco Identity Services Engine for six years.

What do I think about the stability of the solution?

This is a stable product. The features that do work, work well, and we use it on a daily basis.

What do I think about the scalability of the solution?

I would say that this product is scalable because we are using it in our central headquarters, in addition to several branch offices.

How are customer service and technical support?

We do not pay for Cisco SMARTnet, so we did not contact technical support.

Which solution did I use previously and why did I switch?

Prior to using ISE, we were using a solution by Trustwave. It is a different product because it uses Name Poisoning methods. It was an interesting solution but we changed because the price of support is too high. We opted to instead purchase a new product.

How was the initial setup?

The initial setup is not simple. I don't consider our deployment to be complete because we were unsuccessful at trying to use the majority of the features. The fact that we can't solve these problems is why we are searching for another solution.

What about the implementation team?

We had assistance from a consultant for the deployment.

Internally, we have a team of five administrators who manage this product.

What's my experience with pricing, setup cost, and licensing?

The SMARTnet technical support is available at an additional cost.

Which other solutions did I evaluate?

I am currently doing research on Fortinet FortiNAC because I find that Cisco ISE is not a very powerful tool.

What other advice do I have?

My advice for anybody who is considering Cisco ISE is to first run a proof of concept to see that all of the features work well. In my opinion, you have to see all of the features.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Identity Services Engine (ISE)
May 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,311 professionals have used our research since 2012.
Joni Saputro - PeerSpot reviewer
System Engineer at Packet System Indonesia
Real User
Top 10
Dec 4, 2023
A cost-effective and stable solution to secure the endpoints

What is our primary use case?

We use the solution to secure the endpoint. Before the user connects to the network, it can be investigated whether to connect.

What is most valuable?

Cisco ISE has a powerful posturing tool with security requirements. This data can be integrated with the device identity and threat intelligence surface, enabling you to create granular policies based on a device's identity. Just like we made policies based on Samsung or Lenovo, you can now do the same based on its compliance posture.

What needs improvement?

You have to restart the system to change the DNS or NTP server.

For how long have I used the solution?

I have been using Cisco ISE as a system integrator for three years.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

The solution’s scalability is good. We cater the solution to medium-sized businesses.

I rate the solution’s scalability an eight out of ten.

How was the initial setup?

The initial setup is easy. One engineer can deploy it in three hours.

What's my experience with pricing, setup cost, and licensing?

The product has moderate pricing and comes with a subscription model.

What other advice do I have?

We must check the compatibility with the other device before using Cisco ISE. Fortinet or Palo Alto provides integration to another device.

The solution has medium maintenance.

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Smart Information and Communication Technology Engineering student at INPT
Real User
Aug 14, 2022
Provides significant benefits including enhancing compliance and security
Pros and Cons
  • "It provides client provisions and profiling as well as guest access."
  • "The product has many useful features, enhances compliance and security posture, and provides client provisions and profiling as well as guest access, features not available in other solutions."
  • "Difficult to figure out the protocols and nodes in order to implement correctly."
  • "Because it's a Cisco product, if you're not in a Cisco environment, it's difficult to integrate with anything else, so the big concern is its interoperability with other technologies and other vendors."

What is our primary use case?

I'm an engineering student, studying smart information and communication technology.

What is most valuable?

The product has many useful features. It enhances compliance and security posture. It provides client provisions and profiling as well as guest access, features not available in other solutions. The product can be customized. 

What needs improvement?

Although the solution is easy to implement it's not so easy to understand. You need to be able to figure out the protocols, the nodes, and the personals of the nodes in order to implement correctly and make good use of it. Because it's a Cisco product, if you're not in a Cisco environment, it's difficult to integrate with anything else, so the big concern is its interoperability with other technologies and other vendors. 

For how long have I used the solution?

I've been using this solution for two months. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

ISE is extensible. It can be deployed for small and large organizations, and can even be distributed and centralized. 

How are customer service and support?

We haven't used the customer support but if I do need some assistance my supervisor and the manager I'm working with can help. 

What other advice do I have?

I've looked at other network access control solutions and ISE is among the leading technologies. I recommend it but suggest taking a close look at the technology before implementing it. Try to really understand it, because if you miss anything and don't configure correctly, it's going to be awful and you'll lose the benefits that the solution provides. Even if you only need one or two of the features that the solution provides, I would recommend using it. 

I rate this solution nine out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1792131 - PeerSpot reviewer
Chief ICT Specialist at a government with 10,001+ employees
Real User
Jun 21, 2022
Helps us to better recognize our endpoints and know whether they are allowed to access our network
Pros and Cons
  • "The integration with Active Directory is the most valuable feature for us."
  • "We can better recognize our endpoints and we know whether they are allowed to access our network."
  • "The admin interface is really slow. It's horrible."
  • "The admin interface is really slow. It's horrible."

What is our primary use case?

We use it for SDA infrastructure. We have a challenge in recognizing different kinds of devices and that's what we are using ISE for in the SDA fabric.

How has it helped my organization?

We can better recognize our endpoints and we know whether they are allowed to access our network. That's really important for us.

It has also eliminated some rogue devices from accessing our network.

What is most valuable?

The integration with Active Directory is the most valuable feature for us.

What needs improvement?

The admin interface is really slow. It's horrible.

For how long have I used the solution?

I have been using Cisco ISE (Identity Services Engine) for five years.

What do I think about the stability of the solution?

It's really stable.

What do I think about the scalability of the solution?

It's scalable, but we need to upgrade some of our hardware to support more users.

Our SDA fabric has about 1,500 users that we are authenticating. We have plans to use it throughout the City of Helsinki, which has about 38,000 personnel whom we will need to authenticate in the future.

How are customer service and support?

I haven't used the tech support.

Which solution did I use previously and why did I switch?

We also currently have Microsoft RADIUS, but we are planning to move away from it and use ISE as our only authentication solution.

What other advice do I have?

Other than the slow admin interface, it's an excellent product.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1024695 - PeerSpot reviewer
Owner at a tech services company with 11-50 employees
Real User
Jan 11, 2022
A network administration product that is easy to use, but migration could be better
Pros and Cons
  • "I like that Cisco ISE is easy to use."
  • "I like that Cisco ISE is easy to use."
  • "Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things. Whenever we choose a product, it's very difficult because we have to meet the requirements of each feature. There is no standard feature, so the best system that we bought may not fit the solution. We have to look at every feature that the customer uses. If you compare it with other products like Aruba, it's not the same. With Cisco, I have to read all about the features on this version and the licensing required for the product. In Aruba, that thing is covered when you get one license because it covers almost everything. It could also be more scalable."
  • "Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things."

What is our primary use case?

We use Cisco ISE to develop products for other people. We don't really use it in our system. We just buy it and implement it when our customers require ISE.

What is most valuable?

I like that Cisco ISE is easy to use.

What needs improvement?

Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things. Whenever we choose a product, it's very difficult because we have to meet the requirements of each feature. There is no standard feature, so the best system that we bought may not fit the solution. 

We have to look at every feature that the customer uses. If you compare it with other products like Aruba, it's not the same. With Cisco, I have to read all about the features on this version and the licensing required for the product. In Aruba, that thing is covered when you get one license because it covers almost everything. It could also be more scalable.

For how long have I used the solution?

We have been using Cisco ISE for 20 to 30 years.

What do I think about the scalability of the solution?

It could be more scalable. It's easy to scale initially, but it will become very difficult at a certain point. In the beginning, it's in the previous environment, and it's pretty easy. But after we integrate it, we need to do a couple more to scale the product, which is more difficult.

We have less than 300 people using it worldwide. We deal with an airline company, so people who come to use it aren't many, but it's available to everyone from everywhere around the world.

How are customer service and support?

We deal with a local Cisco partner for technical support. I haven't dealt with Cisco directly in Bangkok. 

How was the initial setup?

I think Cisco takes around six months to complete the migration from the old one to the new one. This is because we have compliance and a lot of other things here.

What about the implementation team?

Our in-house team implements this solution. It takes about three people to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

It costs around 50,000 baht in the first year, but I'm unsure about the second year.

What other advice do I have?

On a scale from one to ten, I would give Cisco ISE a seven.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1108698 - PeerSpot reviewer
Senior Network Administrator at a media company with 1,001-5,000 employees
Real User
Jan 10, 2022
Useful portal, helpful support, and priced well
Pros and Cons
  • "The WiFi portal in Cisco ISE is very useful for WiFi customers."
  • "The WiFi portal in Cisco ISE is very useful for WiFi customers."
  • "In an upcoming release, it would be nice to have NAC already standard in the solution."
  • "In an upcoming release, it would be nice to have NAC already standard in the solution."

What is our primary use case?

We use Cisco ISE for authentication for VPN and network management.

What is most valuable?

The WiFi portal in Cisco ISE is very useful for WiFi customers.

What needs improvement?

In an upcoming release, it would be nice to have NAC already standard in the solution.

For how long have I used the solution?

I have used Cisco ISE within the past 12 months.

What do I think about the stability of the solution?

Cisco ISE has been stable.

What do I think about the scalability of the solution?

I have found Cisco ISE to be scalable.

We have two of the Cisco ISE devices installed.

How are customer service and support?

The technical support has been good.

What about the implementation team?

The solution does not require a maintenance or support team.

What's my experience with pricing, setup cost, and licensing?

There is a license to use this solution and the price is reasonable.

What other advice do I have?

When someone is implementing this solution the difficulty depends on where they started. We started with zero and there was a very large learning curve. However, once they understand how it works, it's straightforward. There is a sharp learning curve to start working with it.

I rate Cisco ISE an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Emmanuel Appiah Boateng - PeerSpot reviewer
Network and Security Engineer at a educational organization with 1,001-5,000 employees
Real User
Top 5
Jan 5, 2022
Allows us to use our public ID properly
Pros and Cons
  • "The most valuable feature is the ASDM - the user interface makes it very easy to configure the firewall."
  • "I would recommend this solution as it is very easy to set up and has a very easy user interface."
  • "I would like the product to include support for OSVS version three."
  • "I would like the product to include support for OSVS version three."

What is our primary use case?

My primary use case is network address translation and layer 4 filtering.

How has it helped my organization?

Without this product, we wouldn't be able to use our public ID the way we need to.

What is most valuable?

The most valuable feature is the ASDM - the user interface makes it very easy to configure the firewall.

What needs improvement?

I would like the product to include support for OSVS version three.

For how long have I used the solution?

I've been using this solution for about five years.

What do I think about the stability of the solution?

This is a stable product.

What do I think about the scalability of the solution?

The scalability is good - currently, we don't have an internet bandwidth greater than 10GB, so it's efficient for us.

How was the initial setup?

The initial setup was straightforward, and deployment was done in one night.

What about the implementation team?

I implemented using an in-house team.

What was our ROI?

This product has helped us protect our infrastructure.

Which other solutions did I evaluate?

I considered some open source solutions, but those are usually difficult to set up.

What other advice do I have?

I would recommend this solution as it is very easy to set up and has a very easy user interface. I would rate this solution as eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2026
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.