My primary use case of this solution is for access control for authentication and for the authorization of wireless users.
Works
All devices have multifactor authentication in collaboration with IT which secures access to all our devices
Pros and Cons
- "For device administration, all devices have multifactor authentication in collaboration with IT, so it secures access to all of our devices. For guest and wireless access, it's a matter of a lowly manager who we give access to the portal and he can assign access to the guests, so it's a very simple process now. It keeps the IT focusing on their work, and gives the business people the right access."
- "The compliance and posture don't always work. They should make it more stable. With each upgrade, we lose some functionality. We have to wait for another upgrade."
What is our primary use case?
How has it helped my organization?
For device administration, all devices have multifactor authentication in collaboration with IT, so it secures access to all of our devices. For guest and wireless access, it's a matter of a lowly manager who we give access to the portal and he can assign access to the guests, so it's a very simple process now. It keeps IT focusing on their work, and gives the business people the right access.
Also, with BYOD mobile users can work easier and in a more secure way. For the places in public access we're securing our network socket, so now not everybody can plug in and log into our network due to this feature. It's making it more secure for headquarters.
What is most valuable?
- BYOD service
- The guest and secure wireless access
- Compliance and posture
- Wireless administration
What needs improvement?
The compliance and posture don't always work. They should make it more stable. With each upgrade, we lose some functionality. We have to wait for another upgrade.
I would like to see them develop some type of device management, like an iPad feature, just to be able to give security access to certain devices for management. Mainly for the suppliers and the third parties.
Another feature I would like to see would be for them to create the ability to integrate with other products from the start. We always search for products that integrate with us and so it would ease the management and then everybody would be entered.
Buyer's Guide
Cisco Identity Services Engine (ISE)
June 2025

Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
It's 99% stable.
What do I think about the scalability of the solution?
It's scalable. We have more than 500 users. We are planning to use more features and to integrate it with other branches that we have. It's a way to have a global solution across all branches.
How are customer service and support?
Technical support is okay. Sometimes it takes a long time for them to respond. We'll usually end up solving our own issues. The response time should be shorter.
How was the initial setup?
The initial setup was complex. It took time to have a stable environment but once it stabilized, it was great. Although, we had six to seven months of an unstable system.
What about the implementation team?
We deployed through a reseller, they were good. We require two staff members for maintenance.
What was our ROI?
Our ROI is good enough. It's simplifying things for IT and for the business, so it's good for both sides. It solves a lot of issues that without the product would be costly to our organization so we see ROI in that sense.
What's my experience with pricing, setup cost, and licensing?
Licensing is very complicated and it changes a lot. I know recently it changed since we acquired the solution. It had a different licensing scheme that has changed.
The cost is high compared to other solutions. Even so, it is better than what's on the market. The licensing model is complicated and the cost is a little bit high.
What other advice do I have?
It's a great product but you should be careful to plan before deploying. Do thorough planning as not to do the same error that we did. We didn't do enough planning before deploying so it took us a long time to have a thorough plan.
I would rate this solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at Data Consult
The firewall can see traffic as unencrypted and we can then mitigate the enemy and any attack
What is our primary use case?
My primary use case of this solution is to protect the website from web attacks.
How has it helped my organization?
I use the F5 device on the DMZ zone of the firewall. A record will come to the virtual server on the F5. Then the F5 will upload the encrypted message to the server and decrypt this message. The firewall can see the traffic as unencrypted and we can mitigate the enemy and any attack from F5 and from the firewall.
What is most valuable?
The most valuable feature would be the protection.
What needs improvement?
I would like for them to improve the reporting.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
It is scalable.
How is customer service and technical support?
I would rate their technical support as an eight. They provide a quick solution and I trust working with them.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is not very expensive.
What other advice do I have?
This solution can be used to protect one's application. The server has many features to secure and diagnose.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Identity Services Engine (ISE)
June 2025

Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Architect of Security and Networking solutions (Presales and after sales) at a comms service provider with 1,001-5,000 employees
Provides Member Access Control and enables integration of Cisco hardware
Pros and Cons
- "Member Access Control and the ability to integrate all Cisco wireless, Cisco networking, switches, routers, and firewalls."
- "In a future release, I would like to see network access control. That is something that customers seem to be looking for."
What is our primary use case?
We are an ISP and we are working on providing ISP solutions for companies. For that reason, we are trying to deploy ISE or other technologies.
How has it helped my organization?
The benefit comes from the fact that all of our clients have Cisco products and we are looking for a tool that can integrate all the devices for a secure facility, monitoring, etc.
What is most valuable?
- MAC - Member Access Control
- Integrating all Cisco wireless, networking, switches, routers, firewalls for our customers.
What needs improvement?
In a future release, I would like to see network access control. That is something that customers seem to be looking for.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Research Engineer with 1-10 employees
Its wireless controller needs to add more than one physical port. However, it improves switch account management.
Pros and Cons
- "Improves switch account management."
- "The Cisco wireless controller needs to add more than one physical port."
- "The Guest Network verification needs to add a QR code option."
What is our primary use case?
- Wireless Control Solutions
- Physical Port Access Control
- Changing switch configuration records and account controls.
How has it helped my organization?
- Currently planning to establish a wireless network environment.
- Expected benefits.
- Improves switch account management.
- Physical Port Access Control.
What is most valuable?
- ISE Dynamic VLAN assignment
- ISE Radius and Tacacs+
- External identity sources LDAP, domain, or token.
What needs improvement?
- The Cisco wireless controller needs to add more than one physical port.
- The Guest Network verification needs to add a QR code option.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Engineer/Mobility Specialist at CCSI - Contemporary Computer Services, Inc.
It has a centralized and unified highly secure access control with ISE, which grew out of ACS.
Pros and Cons
- "Cisco ISE now competes with any other product in the space because of its centralized and unified highly secure access control with ISE."
- "The learning curve is steep and the initial setup is complex."
What is most valuable?
Cisco ISE now competes with any other product in the space because of its centralized and unified highly secure access control with ISE. ISE grew out of ACS and in the process has grown up.
What needs improvement?
The learning curve is steep and the initial setup is complex.
What do I think about the stability of the solution?
We've had no issues with stability.
What do I think about the scalability of the solution?
We've had no issues with scalability.
How are customer service and technical support?
Customer Service:
Customer service is good.
Technical Support:
Technical support is very good.
Which solution did I use previously and why did I switch?
Yes. I am a consultant, so I have used many competing products over the years.
How was the initial setup?
The initial setup is complex, but not if you fully vet the solution and leverage the functionality.
What about the implementation team?
I am the services firm that does this work and the SME for my organization.
What was our ROI?
It is hard to quantify ROI. It is more easily measured in increased mobility and security.
What's my experience with pricing, setup cost, and licensing?
There are three levels of pricing: basic, plus, and apex. Basic satisfied our needs.
Which other solutions did I evaluate?
Yes, we used ClearPass.
What other advice do I have?
Not all features are available with base license, plus license allows for profiling and provisioning
Disclosure: My company has a business relationship with this vendor other than being a customer. We resell Cisco.
Senior Network Engineer with 1,001-5,000 employees
It can handle Radius and TACACS+. It is quite complex when it comes to troubleshooting.
What is most valuable?
It can handle Radius and TACACS+.
How has it helped my organization?
Authorisation and Authentication Policy creation is easier. Access right limitation is pretty easy in ISE. Context exchange feature is present.
What needs improvement?
It is quite complex when it comes to troubleshooting.
For how long have I used the solution?
2 years
What was my experience with deployment of the solution?
Upgrade was quite a pain. It doesn't exactly go according to the document.
What do I think about the stability of the solution?
On TACACS side, we see some issues. The rest is all going well.
How are customer service and technical support?
Customer Service:
It's good.
Technical Support:Tech support is still lacking on TACACS troubleshooting on ISE.
Which solution did I use previously and why did I switch?
We were using ACS and IAS servers for radius and TACACS. ISE is one stop shop for everything with more to offer.
What about the implementation team?
Initially done with a Cisco consultant and started with Radius services. Expertise was excellent.
What's my experience with pricing, setup cost, and licensing?
Smartnet is not so cheap depending on the deployment.
What other advice do I have?
We have deployed this solution and we keep on exploring more and more. It can do wonders for authentication and limiting access with the network.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

it_user375078Senior Network Engineer/Mobility Specialist at CCSI - Contemporary Computer Services, Inc.
Real User
We may have borrowed ideas from other sources, but I do not think so. More based on years of experience with ACLs, firewall rule sets and working on the ISE flow and best practices. Also creating a flow chart of ISE flow is great. If you can create it prior to configuration it will guide you. And then create or adjust after implementation. Remember that if your flow chart is clumsy or difficult to organize chances are that your logic is also clumsy or even incorrect. With that said if you are new to ISE (and Dot1x, EAP and RADIUS) a poor flow chart may not reflect an incorrect implementation but a lack of understanding of the underlying principles. GOOD LUCK again!
Senior Network Engineer/Mobility Specialist at CCSI - Contemporary Computer Services, Inc.
Profile Sets help organize how AAA is handled by grouping, like traffic into separate subroutines.
What is most valuable?
Profile Sets help organize how AAA is handled by grouping, like traffic into separate subroutines.
How has it helped my organization?
We implement this for customers is various verticals. Most of the time oit is in Education. It really helps secure, classify and manage users including guest and BYOD users.
What needs improvement?
The product has improved with its evolution. The initial setup, though, is extremely complex.
For how long have I used the solution?
10 years. I have used this since it was Cisco ACS
What was my experience with deployment of the solution?
As the product matures I encounter less and less problems.
What do I think about the scalability of the solution?
The produt scales well.
How are customer service and technical support?
Excellent. TACis quite knowledgable.
Which solution did I use previously and why did I switch?
I have used Microsoft IAS/NPS, Funk, and Aruba ClearPass. ClearPass is the only product in the same league as Cisco ISE.
How was the initial setup?
ISE is extremely complex. With the functionality and flexibility it offers that is to be expected.
What about the implementation team?
I am the vendors's partner.
What's my experience with pricing, setup cost, and licensing?
Licensing and pricing is a complicated calculation, so it is best to really understand your customers' needs. Also team up with the right resources at Cisco for help.
Disclosure: My company has a business relationship with this vendor other than being a customer. We resell this product and the services associated with it. I have used several other RADIUS/security products from various vendors.
Senior Network Operations Specialist at a government with 1,001-5,000 employees
This technology is based upon utilizing other Cisco products such as IDS, IPS, ASA and Catalyst switches.
Valuable Features:
Cisco Identity Services Engine (ISE) version 1.3 has improved it's GUI margin and much easier to navigate than the previous versions.
This technology pride itself with Trust Sec and 802.1x feature. Trust Sec can be an advantage when an environment is nothing but a Cisco workshop.
This technology is based upon utilizing other Cisco products such as IDS, IPS, ASA and Catalyst switches. It provides the RADIUS feature for Active Directory so that 802.1x (EAP over LAN) is properly utilized for User Authentication.
It also does MAC Address Bypass (MAB) for MAC Address verification and authentication.
Cisco will integrate the TACACS+ feature into ISE version 2.0 and enterprises no longer need Cisco ACS for this reason.
Improvements to My Organization:
Many organizations and large enterprises are faced with the daunting task of keeping their security issues at bay. They also need to be in compliant with the Cyber Security's strict guidelines and orders.
While there are many cyber attacks from the outside of the edge routers, cyber attacks can also be implemented within the organization whether it is either intentional or unintentional. Cisco ISE can mitigate many attacks such as MAC spoofing, VLAN hopping, DHCP Starvation and ARP Snooping.
By implementing ISE, it can lighten the overhead of the Cisco Catalyst Switches by not implementing port security, Dynamic Arp Inspection, DHCP Snooping. This will also improve the switch's performance since the ISE server takes over the duty of posturing with its Policy Service Node persona.
Room for Improvement:
Cisco ISE has improved performances on Access Switches and closely monitored the daily suspicious or rogue activities within the organization.
Deployment Issues:
We've had no issues with deployment.
Stability Issues:
We've had no issues with stability.
Scalability Issues:
We've been able to scale it for our needs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
Cisco Secure Firewall
Cisco Umbrella
Aruba ClearPass
Fortinet FortiNAC
Forescout Platform
Cisco Secure Email
Cisco Secure Network Analytics
Cisco Secure Client (including AnyConnect)
Cisco Secure Endpoint
Cisco Secure Workload
F5 BIG-IP Access Policy Manager (APM)
ThreatLocker Zero Trust Endpoint Protection Platform
ExtremeCloud IQ
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Can Cisco ISE disallow authentication based on OS?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
- What are the requirements for integrating the Cisco Data Center and Cisco ISE?
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- Which is better - Aruba Clearpass or Cisco ISE?
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- How does Cisco ISE compare with Fortinet FortiNAC?
- What is your experience with 802.1X when using EnGenius WAP/switch with Cisco ISE 2.1?
It is a great product