Try our new research platform with insights from 80,000+ expert users
reviewer2212440 - PeerSpot reviewer
Network Engineer at a financial services firm with 201-500 employees
Real User
Helps to ensure that we're secure and no unauthorized devices are accessing the network
Pros and Cons
  • "TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
  • "Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior."

What is our primary use case?

We use it for Cisco device TACACS authentication and .1X security. 

How has it helped my organization?

We have a better state of mind that we're secure, and we don't have unauthorized devices accessing the network. In a financial institution, we want to keep everything as secure as possible. We don't want anything plugged in.

It has helped to consolidate tools. We had arpwatch monitoring, which we no longer have to use, and then TACACS is securing the network. We didn't have a tool before, so that added a layer of security for us.

It has improved our cybersecurity resilience. We have authentication logging for everything that's authenticated or denied. We use a Splunk forwarder. We get notifications if something is denied for authentication. 

What is most valuable?

TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network.

What needs improvement?

Its user interface could be better. It's not bad. They've just redesigned the whole user interface. It's not terribly difficult. The drop-down menus are easy to use. However, when you're looking for some things in the user interface, it takes a minute to find where you were prior.

Buyer's Guide
Cisco Identity Services Engine (ISE)
June 2025
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

For how long have I used the solution?

I've been using Cisco ISE for a year.

What do I think about the stability of the solution?

Its stability is great.

What do I think about the scalability of the solution?

Its scalability is also great. We have 350 users. 

How are customer service and support?

Their support is excellent. I've opened two support tickets so far, and they were able to remediate the issue within a few hours.

How was the initial setup?

It's fairly difficult. We have third-party support to assist with the setup.

Our setup is on-prem and virtual in Azure. 

What about the implementation team?

It was a third-party support, not a reseller.

What other advice do I have?

It's a very good tool for security. It's a lot of work to initially set up, but once it's set up, it's pretty easy to use.

It hasn't yet saved the time of our IT staff. It's still fairly new, so we haven't had much time to use the product fully. It has only been a year since we started using it, so it's still pretty new.

Overall, I'd rate Cisco ISE a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1905522 - PeerSpot reviewer
Client Manager at a tech vendor with 10,001+ employees
Real User
We can deep dive into each employees' usage according to our infrastructure needs
Pros and Cons
  • "There are a lot of integrations available with multiple vendors. This has made the solution easier to work with."
  • "If you have someone taking care of it, it can be quite easy to manage the solution. Otherwise, if you don't look after it and take care of it day-to-day, then it will become more complex to run."

What is our primary use case?

We have been authenticating our company's employees and certifying that they are in compliance. We have to certify our employees in regards to compliance, having all the necessary protections in our infrastructure for their endpoints, notebooks, laptops, and mobile phones.

We have implemented it across the entire company in every area and department at every single level of our organization.

So far, it has been on-premises. We are still working to expand it to integrate with multiple cloud providers, like AWS.

How has it helped my organization?

We have become more reliable because we do not have any vulnerabilities coming into our network, which is important since a lot of employees are using their own endpoints to connect to our infrastructure.

Every other time that we have a new employee, we need to make sure they have been using the latest version of the solution in order to connect to our infrastructure.

We have made our company more secure. As an IT guy, I have gained more importance to my company.

What is most valuable?

It is more about the features related to Apex. This is part of the solution where we can deep dive into each employees' usage according to our infrastructure needs.

There are a lot of integrations available with multiple vendors. This has made the solution easier to work with.

We use the management platform, which makes it easy for our IT to access and manage. 

For how long have I used the solution?

We have been working with it for about 10 years.

What do I think about the stability of the solution?

If you have someone taking care of it, it can be quite easy to manage the solution. Otherwise, if you don't look after it and take care of it day-to-day, then it will become more complex to run. However, if you have someone taking care of it, maintenance is not that difficult.

What do I think about the scalability of the solution?

The scalability is good and quite easy to do. If you have the licenses, then anything is possible.

We worked with customers. The last one that we worked with had 10,000 licenses, i.e., 10,000 endpoints. We started working with the corporate office, then we replicate to the distribution centers.

How are customer service and support?

As an IT integrator, it is quite easy to work with their technical support. We have the correct people to deploy it as well as receive good support from the Cisco Technical Assistance Center. I would rate the support as 10 out of 10.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have been using ISE for a while. We didn't have another solution beforehand.

How was the initial setup?

We had to do some labs beforehand, in order not to breach the environment. The deployment was not too complex.

When we work with customers, it takes four or five hours. We start with a specific environment, then we replicate to other areas.

What about the implementation team?

We are a reseller. My professional services implemented it, which includes a tech lead, engineer, senior engineer, and project manager to work with the solution.

It is an easy solution to implement with the correct partner.

What was our ROI?

It is difficult to measure security breaches, but since we have not been attacked so far, it has paid for itself over the years.

Which other solutions did I evaluate?

We worked with Fortinet to look at their solution, but ISE was more reliable and had more integration with our product vendors. Also, it had a more affordable cost.

When compared with other vendors, like Forescout, for what we need, ISE has been more usable and accessible.

What other advice do I have?

Learn about the solution, then evaluate what devices it would be implemented with. I would amalgamate the devices and their versions with a systems integrator or partner who already has experience and will try only to replicate it, not to reinvent the wheel.

Part of our journey is getting everybody connected to the infrastructure and trying to avoid any breaches. We don't want to be vulnerable.

I would rate the solution as 10 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
PeerSpot user
Buyer's Guide
Cisco Identity Services Engine (ISE)
June 2025
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
reviewer1895505 - PeerSpot reviewer
Technical account manager at a computer software company with 51-200 employees
MSP
Eliminates trust from a network and we know exactly what to open and what to trust
Pros and Cons
  • "SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms."
  • "I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it."

What is our primary use case?

We were looking for secure network access.

How has it helped my organization?

It's important that the solution considers all resources to be external because we are introducing new endpoints to the environment every day. We want to make sure that endpoints are secured. In addition, we want to see what that endpoint is doing in our environments.

ISE has eliminated trust from our network architecture. It has changed the methodology of how we look at security. Instead of having everything open, now we know exactly what to open and what to trust.

What is most valuable?

SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms.

What needs improvement?

I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it.

The deployment is complex. I get that it's very configurable, but there is the challenge of how to get to certain things. You go to different places to get the same things done. There needs to be improvement to the GUI.

For how long have I used the solution?

I have been using Cisco ISE (Identity Services Engine) for seven years. 

What do I think about the stability of the solution?

It's now way more stable than 2.0 was.

What do I think about the scalability of the solution?

It's scalable, but we get back to the point that you have to deploy multiple nodes across the environment to get the bandwidth for larger environments.

How are customer service and support?

TAC is pretty good. They're solid. The product has been out there for a little bit so that side of things is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had ClearPass.

How was the initial setup?

It's pretty good when it comes to supporting an organization across a distributed network but it's not easy to implement. It requires a lot of expertise. It requires a full understanding of your environment and the traffic flow.

Our clients have it in multiple locations. At the same time, there are multiple SSIDs on the wireless side and each SSID has a different function for a different group of users. It's not like there is just one set of policies. It has to be multiple policies and sometimes the policies cross each other when moving from one campus to another campus.

Deployment requires a minimum of two solid engineers. One can focus on the network side and the other one can focus on the ISE side.

The way you establish trust is that you first have to "untrust" everything and then you set your points and your profiles and, based on that, you build your policy.

What's my experience with pricing, setup cost, and licensing?

It's damn expensive and the licensing is terrible. There are three different types of licenses: Essential, Advantage, and Premier, and each one of them has certain features. I work with the SLED accounts and it's not easy for customers to find the money. I'm trying to sell their product but, at the same time, to utilize the product fully they have to pay millions of dollars on the licensing alone. And it's software. It's not like I'm selling them hardware with hardware value. It's just software. The prices need to be brought down.

The majority of our clients are still using 2.7, while some have moved to 3.0 or 3.1. That's another issue with the licenses. If you have perpetual licenses on 2.7 and you upgrade to 3, you are forced to go with Essentials. That is one of the issues that I'm seeing with my clients now.

What other advice do I have?

Go for it. It's a great solution. It's very configurable and you can tie your environment together from a wireless or from a wired side. I love the solution.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Sait Kilinc - PeerSpot reviewer
Manager of IT at a financial services firm with 10,001+ employees
Real User
Enables us to control certificates of each device, preventing unauthenticated devices from entering our network
Pros and Cons
  • "The access policies, and all of the policies in Cisco ISE, are important to us."
  • "The user interface could be more user-friendly."
  • "The pricing is fair."

What is our primary use case?

We use it for the identification of our devices, users, and wireless users.

How has it helped my organization?

Unauthenticated devices are not allowed on our network and that has been an improvement for our company. With Cisco ISE, we control the certificates of each device so that devices have internet access. The solution has eliminated trust from our network architecture.

What is most valuable?

The access policies, and all of the policies in Cisco ISE, are important to us.

What needs improvement?

The user interface could be more user-friendly.

For how long have I used the solution?

I have been using Cisco ISE (Identity Services Engine) for about six years.

What do I think about the stability of the solution?

The stability has been perfect. Our company has been using it for more than 10 years and it's stable. It's really good.

What do I think about the scalability of the solution?

The scalability is also good.

How are customer service and support?

The customer service has been perfect.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not have a previous solution.

What's my experience with pricing, setup cost, and licensing?

The pricing is fair. We have a base license and an OpEx license.

Which other solutions did I evaluate?

We looked at other solutions, but that was a long time ago.

What other advice do I have?

I would recommend ISE to colleagues. We are happy with it and we want to use it in the cloud, next. Our on-prem devices go end-of-support in 2023 and we will try to use it on the cloud.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Andres Lopera - PeerSpot reviewer
Technical Leader at Línea Directa S.A.S / Aplicación e Ingreso
Real User
We are very secure now because only corporate endpoints can be authenticated on our wireless
Pros and Cons
  • "Authentication is the most valuable feature because it puts our company at another level of security."

    What is our primary use case?

    We use it for MAC Authentication Bypass, 802.1X authentication, and certification and validation against Active Directory. Because MAC devices can't be enrolled in the domain, we were doing a manual installation of certificates.

    How has it helped my organization?

    We are a very secure enterprise now because only our corporate endpoints can be authenticated on our wireless. Before, any device could be connected to our production network. And the corporate endpoints have antivirus and anti-malware. Things are more and more secure.

    What is most valuable?

    Authentication is the most valuable feature because it puts our company at another level of security. It establishes trust for every access because we use only corporate endpoints. If somebody has another device, they can't connect it to the enterprise network because we haven't implemented bring-your-own-device yet. We have five warehouse buildings and all our operations are around logistics and that means external people don't come to our buildings.

    For how long have I used the solution?

    I have been using Cisco ISE (Identity Services Engine) for three years.

    What do I think about the stability of the solution?

    It's very stable.

    What do I think about the scalability of the solution?

    It's expensive to scale Cisco ISE, but our situation is stable so we don't need to scale it for now. In the future, we will need a more scalable solution.

    It is used for all our departments, all end-users, all corporate endpoints. And when we use MAC Authentication Bypass, we include printers and VIP cell phones.

    How are customer service and support?

    Tech support is very good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We didn't have a previous solution.

    How was the initial setup?

    The deployment was a little complex, but not because of the solution. It was more an issue for our people because it was a mindset change.

    It took us about six months to deploy. Because we didn't have a previous solution, we just deployed it one department at a time across our four departments.

    What about the implementation team?

    We used an integrator, ITS Infocom. Experience-wise, it was very good. On our side, we had three people involved. 

    What was our ROI?

    Since implementing Cisco ISE, we haven't had any attacks against our application.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is not a problem for Cisco because it has a lot of features and not much competition, although it's more expensive than other products. But if I do a cost-benefit analysis, Cisco provides high quality.

    Which other solutions did I evaluate?

    We looked at Aruba. Cisco ISE is much better.

    What other advice do I have?

    Be patient with the implementation. It can be very difficult for the clients, the people using it, because it requires a change of mindset.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Jeff Burdette - PeerSpot reviewer
    Cyber Security Administrator at a aerospace/defense firm with 11-50 employees
    Real User
    Helps us meet PCI compliance and improve our pen-testing scores
    Pros and Cons
    • "Profiling is one of the most valuable features. We have a lot of different devices between cameras, access points, and laptops that get plugged in."
    • "There are always some things that I would request."

    What is our primary use case?

    We use it for identity services, profiling, and locking down devices.

    We're an airport, so when anybody plugs in a device, it's obviously a really big security point for us.

    How has it helped my organization?

    We have a lot of different devices that get plugged in and we really don't have the manpower to address each one individually, as far as our network goes. Cisco ISE has really cut down a lot on the size of our ticket queues and the manpower. My boss is extremely happy about that.

    The solution has also eliminated trust from our organization's network architecture and that has actually been positive because we have to meet PCI compliance. It is very important for us to be able to take cards. It has also helped to improve our pen-testing scores at the end of the year.

    Resilience, in cyber security, is at the top of the list. It's one of the most valuable aspects and has been extremely important for us. Before, we had mid-range scores, but over the last couple of years, between implementing ISE and a few other technologies and SIEMs, we've gotten into the 90th percentile with our pen-testing scores. We were sitting at about 75 to 80, so this is a pretty huge jump for us.

    What is most valuable?

    Profiling is one of the most valuable features. We have a lot of different devices between cameras, access points, and laptops that get plugged in.

    Establishing trust for every access request, no matter where it comes from, is extremely important for us, especially because we are an airport entity. We do have port security implemented throughout our airport, but on the more sensitive side of things, it's a little bit more hardcore regarding what we need to allow, per security zone.

    What needs improvement?

    There are always some things that I would request.

    For how long have I used the solution?

    I first started using Cisco ISE (Identity Services Engine) in about 2015, but we recently just spun it up here at my current job.

    What do I think about the stability of the solution?

    The stability of the solution is a 10 out of 10.

    What do I think about the scalability of the solution?

    The scalability is also a 10 out of 10.

    How are customer service and support?

    For this particular solution, the technical support has been pretty good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I've worked with ISE before, and it was actually my suggestion that we buy the license for it.

    How was the initial setup?

    The initial deployment was pretty straightforward only because I had done it before. I worked on it with a colleague and taught him everything about it, just in case I was incapacitated.

    From the start, including getting to an agreement, budgeting, and scheduling, the deployment took about three months.

    In terms of an implementation strategy, once we got the licensing, we just stood the nodes up. Then we did the features one-by-one, with proper RFCs done, just to see, in a break-fix manner, if each thing we implemented would break something.

    What about the implementation team?

    We used a consultant. The deployment required two people on our side. I was in charge of the initial rollout and implementation, and I'm in charge of managing it. However, if I'm not there, we have another network guy who does the day-to-day tasks and checks the logs to see if he needs to approve anything.

    What was our ROI?

    We have definitely seen return on investment. We have so many different security solutions in place, and ISE just works really seamlessly with them. I get to keep my job, so that's a pretty ROI from my point of view.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is fair for what it does. The only time I've really not been too crazy about the price is for Cisco Prime, which is a management solution for Cisco products.

    Which other solutions did I evaluate?

    We implemented a request for purchase and talked to a few different companies. One of the companies was Presidio. There was another company close by called Net Solutions. Three out of the five companies that we talked to were outsourcing the work to pretty much just bring in an ISE solution, so we just decided to do it in-house.

    What other advice do I have?

    If you are on the fence about it, and you don't have someone on your team who has worked with the product before, definitely reach out to a company or a certified Cisco entity to help with the rollout. It's pretty painful if you don't know what you're doing.

    Resilience is never a bad idea and it's never too late to start working towards it or to begin the journey to Zero Trust. It's very important in this day and age. 

    I'm the only cyber security administrator that we have currently, so if we hadn't gotten this solution in place, I highly doubt that I would have been able to make it here to Cisco Live 2021, so it's excellent.

    From 2015, when I first started using it, until now, there's not really a lot that I would ask be changed. They've been hard at it ever since I first started using it.

    It's been incredible ever since we got it in place.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Chinthaka Kannangara - PeerSpot reviewer
    Network System Engineer at VSIS
    Real User
    Allows you to control or restrict access on your network and has a scalable licensing structure
    Pros and Cons
    • "The best features are the scalability and the license structure."
    • "The licensing documentation needs to be better."

    What is our primary use case?

    The solution is used for controlled access in the network, like if you want to restrict access.

    The solution is deployed on-prem. I am an integrator of this solution.

    What is most valuable?

    The best features are the scalability and the license structure. The license structure is like a tier. If a customer doesn't actually want the highest features, then they can just start with the basic license package and upgrade it if their network is growing. For the smaller customers, they can start with the smaller plans and so on. If you have a financial customer or banking customer, they can go for the full features, and if it's not that critical, the customer can get the basic license package and implement that.

    What needs improvement?

    The licensing documentation needs to be better. We found some old documents describing the license names, like the Base license and Apex license. Cisco used both names. We have found that they changed the Advantage license and Premier License. If someone misunderstands that, they might end up with a hassle. I don't know if it's possible or not for Cisco to remove the older documents from the official website.

    For how long have I used the solution?

    We have been working with this solution for more than two years.

    We were using two solutions on Cisco's network, so we had a few ISE plans in that network.

    What do I think about the stability of the solution?

    The solution is stable. We have maybe 4,000 users for the Next solution.

    How are customer service and support?

    We haven't used technical support very much, but in general, Cisco's support is always responsive.

    How was the initial setup?

    Initial setup was straightforward from our point of view because we have engineers who did that, so of course it was not an issue with us.

    The accesses took maybe three or four months to complete, but the Next part took about three weeks.

    For deployment and maintenance, the team was average sized. You need to follow the correct documents for deployment. There can be misunderstandings if you use old documentation.

    What's my experience with pricing, setup cost, and licensing?

    The licensing is subscription-based and based on the user account.

    What other advice do I have?

    I would rate this solution 8 out of 10. 

    I would recommend this solution.

    If someone is looking for a concrete solution to control the access, then ISE is a better solution.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
    PeerSpot user
    reviewer779877 - PeerSpot reviewer
    Senior Software Engineer with 501-1,000 employees
    Reseller
    Good technology that works well with networks, routers and switches, but should include third-party integration
    Pros and Cons
    • "When you push out the policy, it is able to populate the entire network at one time."
    • "Third-party integration is important, as well as the continuous adaptation feature which is the AIOps. It would be helpful to include the AIOps."

    What is our primary use case?

    We are resellers. We provide and deploy solutions for our customers.

    Cisco ISE (Identity Services Engine) helps the operation to automate.

    What is most valuable?

    It works very well with the network, router, and switches. It is able to enforce the policy and assigns the traffic a Security Group tag.

    A Google user is able to enforce access throughout the router and switches ensuring the traffic going through has the same policy.

    When you push out the policy, it is able to populate the entire network at one time.

    It's quite good, the market is using this solution.

    What needs improvement?

    This solution has enhanced features that make it difficult to use. To make it easier, it should be made without PxGrid.

    It should be able to work with third-party routers and switches. We want to work in an environment where there are multi-vendors that require PxGrid.

    Their software-defined access is not easy to implement. You have to have a good understanding of how to implement it. It would be helpful if they could make it easier for the customer to adopt.

    Third-party integration is important, as well as the continuous adaptation feature, which is the AIOps. It would be helpful to include the AIOps.

    For how long have I used the solution?

    They are currently on version 3.1.

    What do I think about the stability of the solution?

    If the customer has more than 200,000 users, the performance becomes a bit laggy.

    What do I think about the scalability of the solution?

    In terms of scalability, it's available on the cloud, but I have not yet tested the features on the cloud.

    It is used mainly by our customers, who use it for their entire infrastructure. They have anywhere from 50,000 to 100,000 users.

    How are customer service and technical support?

    Technical support could be better. They outsource the support.

    We are brought all around the world, it is similar to following the sun.

    Which solution did I use previously and why did I switch?

    Currently, I am using SD-WAN (Software-Defined WAN) from Silver Peak.

    How was the initial setup?

    To complete the installation, you need to be technically knowledgeable. The setup could be easier.

    What's my experience with pricing, setup cost, and licensing?

    For the content, and the technologies it is made to be a bit more complex. 

    The technology is good, but to use some of the other features, and capabilities, they request that we purchase the Cisco DNA Center. As a result, the bundled price is a little high.

    Once you purchase the DNA, you will need the SNA then the license, overall it's very expensive.

    If, however, you implement Cisco ISE without the DNA and the SDA, the price is reasonable.

    What other advice do I have?

    To avoid running into any complications when getting this solution up and running, you should get technically trained and comfortable with it before applying it.

    I would rate Cisco ISE (Identity Services Engine) a seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2025
    Buyer's Guide
    Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.