This solution provides access to the employees of the company.
IT Business Manager at Telefónica
Simple, works well, and has a lot of features
Pros and Cons
- "It's scalable."
- "We are very happy with the solution and we have no problem using Cisco ISE solutions."
- "The price here in Brazil is very expensive."
- "Sometimes we face some infrastructure where there are multiple vendors and sometimes the ISE is not the best tool to manage multiple vendor infrastructure."
What is our primary use case?
What is most valuable?
It works. It is simple. It works very well. We have a good strategic setup. We are very happy with the solution and we have no problem using Cisco ISE solutions.
The solution is stable.
It's scalable.
What needs improvement?
I'm not working in the IT team. I'm working the sales team. While there are a lot of features that we could improve in our organization, I can't speak to the exact changes that should be made.
We'd like to be able to integrate the product with our solutions. Sometimes we face some infrastructure where there are multiple vendors and sometimes the ISE is not the best tool to manage multiple vendor infrastructure.
The price here in Brazil is very expensive.
Configurations can be a bit complicated.
Sometimes we have problems integrating logs into SIEM solutions. We have to deliver some logs to a SIEM secret platform, and sometimes it does not work well. It would be better if we had better integration or a better way to deliver the logging SIEM platforms.
For how long have I used the solution?
I've been using the solution for five to six years.
Buyer's Guide
Cisco Identity Services Engine (ISE)
June 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability is good. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We have no problem with the management of our infrastructure when we need more accountability from the platform. Scalability was fine. There is no problem.
We have 6,000 people in Brazil using the solution.
How are customer service and support?
I consider technical support to be perfect. Anytime that I have problems with shifting solutions, they work well with me and I have no problems with working with them.
Which solution did I use previously and why did I switch?
I'm a reseller from Fortinet and Cisco solutions. I also have experience with Check Point.
How was the initial setup?
I can't speak to how the setup goes. I'm not working directly in deployment. What I've heard from my customers, for example, is that it is not difficult to set up, however, it may be to run all the features.
What I've heard is the first setup is very, very easy and to do some adjustments is very easy, however, when you want to go further in the configuration, that could be a bit easier.
What's my experience with pricing, setup cost, and licensing?
I can't speak to the exact pricing of the product.
What other advice do I have?
I work with various versions of the solution.
We're resellers.
Others should know it's a very good solution, very stable. There are a lot of features, and it is a secure solution. It's the first solution that we indicate to our customers and most of the time, the decision of the customer is to deploy a Cisco product.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
Technical account manager at a computer software company with 51-200 employees
Eliminates trust from a network and we know exactly what to open and what to trust
Pros and Cons
- "SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms."
- "ISE has eliminated trust from our network architecture."
- "I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it."
- "It's damn expensive and the licensing is terrible."
What is our primary use case?
We were looking for secure network access.
How has it helped my organization?
It's important that the solution considers all resources to be external because we are introducing new endpoints to the environment every day. We want to make sure that endpoints are secured. In addition, we want to see what that endpoint is doing in our environments.
ISE has eliminated trust from our network architecture. It has changed the methodology of how we look at security. Instead of having everything open, now we know exactly what to open and what to trust.
What is most valuable?
SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms.
What needs improvement?
I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it.
The deployment is complex. I get that it's very configurable, but there is the challenge of how to get to certain things. You go to different places to get the same things done. There needs to be improvement to the GUI.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for seven years.
What do I think about the stability of the solution?
It's now way more stable than 2.0 was.
What do I think about the scalability of the solution?
It's scalable, but we get back to the point that you have to deploy multiple nodes across the environment to get the bandwidth for larger environments.
How are customer service and support?
TAC is pretty good. They're solid. The product has been out there for a little bit so that side of things is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had ClearPass.
How was the initial setup?
It's pretty good when it comes to supporting an organization across a distributed network but it's not easy to implement. It requires a lot of expertise. It requires a full understanding of your environment and the traffic flow.
Our clients have it in multiple locations. At the same time, there are multiple SSIDs on the wireless side and each SSID has a different function for a different group of users. It's not like there is just one set of policies. It has to be multiple policies and sometimes the policies cross each other when moving from one campus to another campus.
Deployment requires a minimum of two solid engineers. One can focus on the network side and the other one can focus on the ISE side.
The way you establish trust is that you first have to "untrust" everything and then you set your points and your profiles and, based on that, you build your policy.
What's my experience with pricing, setup cost, and licensing?
It's damn expensive and the licensing is terrible. There are three different types of licenses: Essential, Advantage, and Premier, and each one of them has certain features. I work with the SLED accounts and it's not easy for customers to find the money. I'm trying to sell their product but, at the same time, to utilize the product fully they have to pay millions of dollars on the licensing alone. And it's software. It's not like I'm selling them hardware with hardware value. It's just software. The prices need to be brought down.
The majority of our clients are still using 2.7, while some have moved to 3.0 or 3.1. That's another issue with the licenses. If you have perpetual licenses on 2.7 and you upgrade to 3, you are forced to go with Essentials. That is one of the issues that I'm seeing with my clients now.
What other advice do I have?
Go for it. It's a great solution. It's very configurable and you can tie your environment together from a wireless or from a wired side. I love the solution.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Cisco Identity Services Engine (ISE)
June 2026
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
Senior Systems Administrator at a manufacturing company with 10,001+ employees
Establishes better layouts. Devices can move and we don't have to worry about where they need to go.
Pros and Cons
- "Since migrating towards doing wired ports over ISE with 802.1X and MAB authentication, our organization's security risk has been better, and we have been able to establish better layouts so devices can move and we don't have to worry about where they need to go."
- "It does a good job of establishing trust for every access request. We have had a little bit of a challenge with profiling, but we are probably about 80% there."
- "Scalability is good as far as adding another node. However, if you ever wanted to increase the node that you have, then you need to buy a bigger license. You also have to build a new VM for it because you can't just scale it."
What is our primary use case?
Right now, we are doing all wireless through ISE. We have also started migrating to wired.
We have about 20 sites. By having enough node regionalization, we have been able to have all our sites utilizing it.
It is deployed to multiple locations. We have one in Mexico, one in Kelso, two in Asia, and then two in the US.
How has it helped my organization?
It improved our standardization with all its policy sets being the same.
Since migrating towards doing wired ports over ISE with 802.1X and MAB authentication, our organization's security risk has been better. We have been able to establish better layouts, so devices can move and we don't have to worry about where they need to go.
What is most valuable?
The Guest Portal is a big feature for us.
What needs improvement?
It does a good job of establishing trust for every access request. We have had a little bit of a challenge with profiling, but we are probably about 80% there.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
The stability is fairly good. Since we went to the 2.6 version, it has been a lot better.
What do I think about the scalability of the solution?
Scalability is good as far as adding another node. However, if you ever wanted to increase the node that you have, then you need to buy a bigger license. You also have to build a new VM for it because you can't just scale it.
How are customer service and support?
I had one problem with the portal. I got support from TAC and it worked out really well. It was really good. I would rate the support as 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not previously use another solution.
We were looking to solve the challenge where people were moving devices that they were not supposed to.
How was the initial setup?
The initial deployment was straightforward and took a couple of months. It was actually a project for a customer, then the customer backed out. So, we spent a good year without using it for anything.
The initial deployment was for a customer in Asia, so we had to deploy it in our Asia data center. We then deployed it in our US data center to kind of match that configuration.
What about the implementation team?
We did use a consultant from Presidio for our first deployment project. Since then, we have been doing deployments ourselves.
Two people were needed for the deployment: the consultant and myself.
What was our ROI?
There is probably a return on investment as far as increased time for people not having to worry about devices moving around nor having to be contacted about moving them to the appropriate spot.
What's my experience with pricing, setup cost, and licensing?
Its licensing could be improved. It used to be perpetual, but now they are moving away from that.
What other advice do I have?
Make sure you understand where you want to deploy nodes and how far away they are from other locations since there is some latency involved.
We don't do any sort of application-based stuff right now. It is just purely assigning devices to what VLAN they are supposed to go to.
We are looking to upgrade to a newer version. Hopefully, by seeing some of the stuff at Cisco's event, I can find some more features that we could use.
I would rate the solution as eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Architect at Commercial Metals Company
Integration with Active Directory means we can find and authorize users based on their AD groups
Pros and Cons
- "The most valuable feature is 801.1x and another very good feature is the TACACS."
- "Without Cisco ISE, we couldn't authorize our users, contractors, and everyone else."
- "I would like to see integration with other vendors, and the RADIUS integration needs to be improved a little bit."
- "Technical support has been okay, but I wouldn't describe it as "very good." We have had some problems with technical support."
What is our primary use case?
We use it mostly for identity, authentication, and authorizations for wireless and wired. The challenges we were looking to address were mostly around the authorization and authentication of the users. We wanted to use the Identity Services Engine to make sure that the users accessing our network were authorized users, with the authentication happening before.
How has it helped my organization?
The integration with Active Directory, and finding and authorizing users based on their Active Directory groups, rather than just their identities, was a big change for us.
What is most valuable?
The most valuable feature is 801.1x and another very good feature is the TACACS.
In addition, it establishes trust for every access request. That's very valuable. We can't authorize users without it. The fact that it considers all resources to be external is very important. Without Cisco ISE, we couldn't authorize our users, contractors, and everyone else. It's our one source of truth for authentication and authorization.
It's also very good when it comes to supporting an organization across a distributed network. We like that.
What needs improvement?
I would like to see integration with other vendors, and the RADIUS integration needs to be improved a little bit.
Other than that, all the features that we're using look good.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for about six years.
What do I think about the stability of the solution?
It has been very stable. There's no problem with that, as we have redundancy in place.
What do I think about the scalability of the solution?
It can be scaled very quickly by adding more nodes to the solution. The scalability is very good.
We have it deployed in three data centers in Austin, Texas, Lewisville, Texas, and one in Poland. It's a distributed deployment and we have around 8,000 endpoints on it so far.
How are customer service and support?
Technical support has been okay, but I wouldn't describe it as "very good." We have had some problems with technical support. Sometimes it takes them too long to resolve a problem.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
The pricing is good. The last time we purchased four new appliances the price was doable for any organization of our size.
Which other solutions did I evaluate?
In my previous job, I used Aruba ClearPass. It's similar to ISE. They're both good.
What other advice do I have?
Design it well in the first place. If you design it well, you can scale it. Always read, line-by-line, the Cisco guide because that's where you'll find all the information about the design and the scalability. If you design it correctly in the first place, you will have a smooth ride.
We want to use it in a hybrid cloud deployment, but we currently use it 100 percent on-premises. As we move more into the cloud, we're trying to integrate that with Cisco ISE to make it our authentication and authorization source. We're not really into the cloud yet. We're just doing some dev. We're building a whole cloud strategy.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Administrator at a aerospace/defense firm with 11-50 employees
Helps us meet PCI compliance and improve our pen-testing scores
Pros and Cons
- "Profiling is one of the most valuable features. We have a lot of different devices between cameras, access points, and laptops that get plugged in."
- "Before, we had mid-range scores, but over the last couple of years, between implementing ISE and a few other technologies and SIEMs, we've gotten into the 90th percentile with our pen-testing scores."
- "There are always some things that I would request."
What is our primary use case?
We use it for identity services, profiling, and locking down devices.
We're an airport, so when anybody plugs in a device, it's obviously a really big security point for us.
How has it helped my organization?
We have a lot of different devices that get plugged in and we really don't have the manpower to address each one individually, as far as our network goes. Cisco ISE has really cut down a lot on the size of our ticket queues and the manpower. My boss is extremely happy about that.
The solution has also eliminated trust from our organization's network architecture and that has actually been positive because we have to meet PCI compliance. It is very important for us to be able to take cards. It has also helped to improve our pen-testing scores at the end of the year.
Resilience, in cyber security, is at the top of the list. It's one of the most valuable aspects and has been extremely important for us. Before, we had mid-range scores, but over the last couple of years, between implementing ISE and a few other technologies and SIEMs, we've gotten into the 90th percentile with our pen-testing scores. We were sitting at about 75 to 80, so this is a pretty huge jump for us.
What is most valuable?
Profiling is one of the most valuable features. We have a lot of different devices between cameras, access points, and laptops that get plugged in.
Establishing trust for every access request, no matter where it comes from, is extremely important for us, especially because we are an airport entity. We do have port security implemented throughout our airport, but on the more sensitive side of things, it's a little bit more hardcore regarding what we need to allow, per security zone.
What needs improvement?
There are always some things that I would request.
For how long have I used the solution?
I first started using Cisco ISE (Identity Services Engine) in about 2015, but we recently just spun it up here at my current job.
What do I think about the stability of the solution?
The stability of the solution is a 10 out of 10.
What do I think about the scalability of the solution?
The scalability is also a 10 out of 10.
How are customer service and support?
For this particular solution, the technical support has been pretty good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I've worked with ISE before, and it was actually my suggestion that we buy the license for it.
How was the initial setup?
The initial deployment was pretty straightforward only because I had done it before. I worked on it with a colleague and taught him everything about it, just in case I was incapacitated.
From the start, including getting to an agreement, budgeting, and scheduling, the deployment took about three months.
In terms of an implementation strategy, once we got the licensing, we just stood the nodes up. Then we did the features one-by-one, with proper RFCs done, just to see, in a break-fix manner, if each thing we implemented would break something.
What about the implementation team?
We used a consultant. The deployment required two people on our side. I was in charge of the initial rollout and implementation, and I'm in charge of managing it. However, if I'm not there, we have another network guy who does the day-to-day tasks and checks the logs to see if he needs to approve anything.
What was our ROI?
We have definitely seen return on investment. We have so many different security solutions in place, and ISE just works really seamlessly with them. I get to keep my job, so that's a pretty ROI from my point of view.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair for what it does. The only time I've really not been too crazy about the price is for Cisco Prime, which is a management solution for Cisco products.
Which other solutions did I evaluate?
We implemented a request for purchase and talked to a few different companies. One of the companies was Presidio. There was another company close by called Net Solutions. Three out of the five companies that we talked to were outsourcing the work to pretty much just bring in an ISE solution, so we just decided to do it in-house.
What other advice do I have?
If you are on the fence about it, and you don't have someone on your team who has worked with the product before, definitely reach out to a company or a certified Cisco entity to help with the rollout. It's pretty painful if you don't know what you're doing.
Resilience is never a bad idea and it's never too late to start working towards it or to begin the journey to Zero Trust. It's very important in this day and age.
I'm the only cyber security administrator that we have currently, so if we hadn't gotten this solution in place, I highly doubt that I would have been able to make it here to Cisco Live 2021, so it's excellent.
From 2015, when I first started using it, until now, there's not really a lot that I would ask be changed. They've been hard at it ever since I first started using it.
It's been incredible ever since we got it in place.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Services Director at XByte SRL
Improves security posture and reduces security gaps
Pros and Cons
- "They provide you multiple ways to achieve security, not only on-prem, but also when you have remote and guest workers. Especially post-pandemic, a lot of our customers have remote workers. So, it has been really helpful."
- "Profiling is a really good feature. However, it sometimes is a challenge for customers when there are issues with the remediation part. I would add a built-in remediation solution. That would be a very nice feature."
What is our primary use case?
We are working with packets and A011X. In some cases, we also do profiling.
We are using this solution because we wanted to improve security and reduce security gaps. This is mainly for our customers.
How has it helped my organization?
This solution improves security. There is a new law in the Dominican Republic, where I am from. The central bank has ordered the banks to improve their security through a law. ISE is one of the start points for those organizations to start improving their security.
The solution gives us a way to provide a professional security solution to our customers.
What is most valuable?
They provide you multiple ways to achieve security, not only on-prem, but also when you have remote and guest workers. Especially post-pandemic, a lot of our customers have remote workers. So, it has been really helpful.
Its resilience gives you a better security posture. Cybersecurity resilience is very important. Security is one of the main things in my country enforced by law.
What needs improvement?
Profiling is a really good feature. However, it sometimes is a challenge for customers when there are issues with the remediation part. I would add a built-in remediation solution. That would be a very nice feature.
For how long have I used the solution?
I have been using the solution for six to seven years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is very scalable. You can install several nodes in order to scale the solution.
How are customer service and support?
The technical support is really good. I would rate them as 10 out of 10. You need to know how to work with the tech support. If you don't know how to work with them, then it won't work.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have been working for 15 years with Cisco as a Cisco partner. We like the Cisco solutions.
How was the initial setup?
The deployment is complex. It takes four or five to deploy it.
What about the implementation team?
Deployment takes a skilled technician. The customer's help is always needed since we need to integrate Active Directory.
What was our ROI?
Our customers see ROI. They feel more confident about their operations. It gives them time to do other things in order to be more profitable.
What's my experience with pricing, setup cost, and licensing?
It has a fair price. It is better than it was before.
Which other solutions did I evaluate?
We have seen Aruba ClearPass, but it is not that common in the Dominican Republic.
What other advice do I have?
Organizational leaders should do constant analysis of their security posture, in order to be improving every day.
I would rate them as eight out of 10 because of the remediation feature.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller/Integrator
Director, Information Technology Solutions at a healthcare company with 5,001-10,000 employees
Comprehensive and allows you to control access to network resources granularly based on policies
Pros and Cons
- "Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies."
- "Cisco ISE is very complex and not very easy to deploy."
What is our primary use case?
We use the solution for network access control.
What is most valuable?
Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies.
What needs improvement?
Cisco ISE is very complex and not very easy to deploy. There are a lot of prerequisites for the tool.
For how long have I used the solution?
I have been using Cisco ISE (Identity Services Engine) for three years.
What do I think about the stability of the solution?
We did not face any issues with the solution’s stability.
What do I think about the scalability of the solution?
Cisco ISE is a very scalable solution.
How are customer service and support?
We are working with a partner for support and are very happy with them.
On a scale from one to ten, where one is bad and ten is good, I rate their support a seven or eight out of ten.
Which solution did I use previously and why did I switch?
Compared to Cisco ISE, Fortinet NAC is more consumer-friendly.
How was the initial setup?
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a four out of ten.
What about the implementation team?
The project lasted a few months, but the planning took several months. Cisco ISE itself means nothing. It has to have the network set up to ensure the network penetration is in place, and we're still working on that.
What was our ROI?
Security is about risk control and exposure avoidance. You can only calculate its return on investment based on how you avoid penalty fees. Cisco ISE improves our security stats.
What's my experience with pricing, setup cost, and licensing?
If you consider money only, Cisco ISE is not a cheap solution. Functionality-wise, however, it offers a very good price for the value you receive.
What other advice do I have?
The solution's compliance and policy enforcement capability has benefited our organization by simplifying work.
The solution operates in the background, and users generally don't interact with it. Cisco ISE is the security framework layer between network resources and end users using them. Users do not go into Cisco ISE to do anything.
It's like Active Directory for Identity. If you're an end user, you don't work in Active Directory, but you authenticate Active Directory to use resources on the network. The same applies to Cisco ISE, and users don't interact with it directly. They are affected by it to the extent to which they are accessing network resources.
Cisco ISE has a very comprehensive integration suite and we did not face a lot of challenges in integrating this solution with other security tools. If they know how to use it, I would recommend the solution to other organizations with similar security needs.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Manager at a government with 201-500 employees
Helps save us time and seamlessly integrates with our entire suite
Pros and Cons
- "The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval."
- "If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components."
What is our primary use case?
We use Cisco ISE for the authentication of wireless clients.
How has it helped my organization?
Cisco ISE has saved me a couple of hours per month in terms of not having to manually onboard clients. However, there are still some manual tasks that need to be uploaded to Cisco ISE.
What is most valuable?
The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval.
What needs improvement?
One of the problems we have had is that there are many features on Cisco ISE that we are not utilizing. In the real world, it requires multiple parties to come together, just like the AD or OU. Therefore, it won't be solely the responsibility of the network or security personnel to ensure that the solution works as intended and utilizes all the features. It necessitates collaboration among various stakeholders. If Cisco could grant more control, the features could be more focused on network and security administration, reducing the need for integration with other components. This would be beneficial for my organization.
For how long have I used the solution?
I have been using Cisco ISE for one and a half years.
What do I think about the stability of the solution?
Cisco ISE is extremely stable.
What do I think about the scalability of the solution?
As long as we have the funds to purchase the license, Cisco ISE is highly scalable.
How are customer service and support?
We have a contact person in Singapore whom we can reach at any time for support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward because we used an integrator.
What about the implementation team?
We used an integrator for the implementation.
What was our ROI?
The cost-benefit analysis primarily considers the time saved through manual labor.
What's my experience with pricing, setup cost, and licensing?
The recent changes in the licensing model have caused some issues with the team.
Which other solutions did I evaluate?
We have a rigorous procurement process and carefully evaluated other options before selecting Cisco ISE.
One of the other solutions we evaluated was the Aruba Wireless feed and its accompanying authentication, but we determined that Cisco ISE was superior and more beneficial.
What other advice do I have?
I would rate Cisco ISE with a nine out of ten based on its overall benefits. However, since I am unable to utilize all the features due to the need for coordination from numerous other teams, I would personally assign it a benefit score of only five out of ten.
We attempted role-based access with the Cisco ISE integration, but it didn't work out effectively because it is more of an upper-level issue regarding organization and role level. Multiple teams had to collaborate, and there was a need to configure the Active Directory and Organizational Unit groups. This also involved restructuring and similar tasks. As individuals moved between OU groups, someone had to consistently update the OU groups to ensure the success of the process.
We have made a significant investment in Cisco infrastructure; therefore, we have chosen Cisco ISE as a logical option for our authentication mechanism.
Cisco ISE has not directly assisted our organization in enhancing its cybersecurity resilience.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Officer at a financial services firm with 1,001-5,000 employees
An easy-to-use solution that integrates well with other external identity servers
Pros and Cons
- "Cisco ISE's integration with other external identity servers like Duende is very simple and easy."
- "Cisco ISE's performance could be better, faster, and more robust."
What is our primary use case?
I use Cisco ISE for VPN and authentication.
What is most valuable?
Cisco ISE is a good and easy-to-use solution. We had a smooth experience with it, and we didn't face any issues. We upgraded the solution two years ago, and that version also worked fine.
Cisco ISE's integration with other external identity servers like Duende is very simple and easy.
What needs improvement?
Cisco ISE's performance could be better, faster, and more robust. Sometimes it takes some time to move through the tabs and configure something.
For how long have I used the solution?
I have been using Cisco ISE for three and a half years.
What do I think about the stability of the solution?
Cisco ISE is a stable solution. We haven't faced any major issues with the product.
What do I think about the scalability of the solution?
Cisco ISE is a scalable solution. Our environment has a cluster distributed across three countries and seven nodes. It would be very easy to add another node or remote site.
How are customer service and support?
In some areas, Cisco ISE's technical support is good. However, we had an issue with integrating Cisco ISE with DNS. So we opened a case, which escalated, and we had it for almost two years. Cisco escalated our case after hearing about our integration problem, and the issue was solved eventually.
In normal support cases, like if you are facing a bug, you will have very quick input from Cisco ISE's technical support. It is easy to find the issues in some areas, but in some cases, you might have to go along a troubleshooting path to find the issue. I used to work for Cisco tech wireless team. In some deployments, you have a complicated environment and must understand and solve the issue. Sometimes, it might take a long time to solve or find an issue, while it would be easy in other cases. It depends on the complexity of the environment.
How would you rate customer service and support?
Positive
How was the initial setup?
Cisco ISE was already deployed when I joined my company, but I was present when it was upgraded. The upgrading process wasn't very easy, but we didn't face many issues. When we upgraded our Cisco ISE, it was running on the 2.3 version. We upgraded it to 2.7, and we had some issues at that time. We upgraded directly to 2.7 patch 2, and most problems were solved.
What other advice do I have?
My main focus is on the .1X access. We have another security team whose focus is on VPN access. I use Cisco ISE for TechX authentication and .1X authentication.
Cisco ISE saves us time. If you deploy any security features using Cisco ISE, you don't have other options not to automate it. Part of our Cisco ISE is integrated with the Cisco DNS center. The Cisco DNS center saves time in terms of configuration, integration, upgrading, and adding other switches to the fabric. You can deploy the features in Cisco ISE using manual techniques.
Cisco ISE was already deployed in my organization when I joined. However, I know that Cisco ISE replaced ACS.
I work in the banking industry. Our main concern is securing our network from either remote or on-site access. When you get physical access to the site and connect your device, you might risk the security of the network on purpose or unknowingly. Deploying Cisco ISE has helped improve the security of our organization.
Overall, I rate Cisco ISE a nine out of ten because I have a very good experience with the solution and hear the same from other vendors.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Data Engineer at a healthcare company with 5,001-10,000 employees
Does everything under the sun but is hard to upgrade and manage
Pros and Cons
- "It works as a good RADIUS server. It has lots of features. It works with all the proprietary Cisco AB pairs and features."
- "It could be less monolithic. It's one huge application, and it does everything under the sun, so it's hard to deal with and upgrade and manage."
What is our primary use case?
Right now we use Wireless.1X and TACACS for device management. It's in our wired network too, but only use it for MAC address bypass.
How has it helped my organization?
It has helped to consolidate tools and applications. Previously, we had Windows NPS in some places and then Cisco ACS in other places. Now, Cisco ISE is all I use. This consolidation hasn't had a whole lot of impact on our organization. It wasn't that big of a deal to begin with.
What is most valuable?
It works as a good RADIUS server. It has lots of features. It works with all the proprietary Cisco AB pairs and features.
What needs improvement?
It could be less monolithic. It's one huge application, and it does everything under the sun, so it's hard to deal with and upgrade and manage.
For how long have I used the solution?
I've been using Cisco ISE for three or four years.
What do I think about the stability of the solution?
Overall, it's pretty stable.
What do I think about the scalability of the solution?
It seems to be pretty good for what we're doing with it.
How are customer service and support?
Cisco TAC support is hit or miss. It depends on who you got. I'd rate them a six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We didn't have any network access control. For the wireless, we had ACS, and some places used NPS from Windows.
We chose Cisco ISE because we have a Cisco network. It seemed like the obvious choice.
How was the initial setup?
The initial setup was pretty easy, but trying to get all the switches to talk to ISE was pretty complex. It required a lot of configuration and learning, and we found a lot of bugs and issues along the way.
What about the implementation team?
Initially, we took the help of Presidio. They were good. They knew a lot about it and helped us a lot.
What other advice do I have?
In terms of detection and remediation of threats, it wouldn't detect anything. If we integrated it with other products, it could cut certain clients off from the network, but we haven't gotten that far yet.
It hasn't helped to free up our IT staff. It has probably consumed more time.
I don't have a lot of familiarity with other products, so I'd rate it a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
Cisco Secure Firewall
Cisco Umbrella
Aruba ClearPass
Cisco Secure Email
Cisco Secure Network Analytics
Forescout Platform
Fortinet FortiNAC
Cisco Secure Endpoint
ThreatLocker Zero Trust Platform
Cisco Secure Client (including AnyConnect)
Cisco Secure Workload
F5 BIG-IP Access Policy Manager (APM)
ExtremeCloud IQ
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Can Cisco ISE disallow authentication based on OS?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
- What are the requirements for integrating the Cisco Data Center and Cisco ISE?
- What is the biggest difference between Aruba ClearPass and Cisco ISE?
- Which is better - Aruba Clearpass or Cisco ISE?
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- How does Cisco ISE compare with Fortinet FortiNAC?
- What is your experience with 802.1X when using EnGenius WAP/switch with Cisco ISE 2.1?













