Try our new research platform with insights from 80,000+ expert users

Cisco DNA Center vs Cisco Identity Services Engine (ISE) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco DNA Center
Average Rating
8.0
Reviews Sentiment
6.3
Number of Reviews
41
Ranking in other categories
Network Management Applications (1st), Network Monitoring Software (13th), Network Automation (2nd)
Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
142
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
 

Mindshare comparison

Cisco DNA Center and Cisco Identity Services Engine (ISE) aren’t in the same category and serve different purposes. Cisco DNA Center is designed for Network Management Applications and holds a mindshare of 25.1%, down 29.1% compared to last year.
Cisco Identity Services Engine (ISE), on the other hand, focuses on Network Access Control (NAC), holds 25.8% mindshare, down 31.3% since last year.
Network Management Applications
Network Access Control (NAC)
 

Q&A Highlights

Aymen FHOULA - PeerSpot reviewer
Jul 07, 2023
 

Featured Reviews

AvrahamSonenthal - PeerSpot reviewer
Efficiently manages our wireless network and provides valuable monitoring features
The platform's biggest benefit has been in managing our wireless network. Having a single pane of glass to control all wireless controllers and access points and to monitor activity has been a significant advantage. We're a small federal agency with around 300 network devices, so automation is a minor focus. It's more relevant for larger networks. The main benefits we've seen are in inventory management and the potential for configuration automation. However, I recommend using the DNA Centre only for larger networks with over a thousand devices; otherwise, it may not be cost-effective. Before proceeding, ensure that your devices are compatible with DNA Center, as not all Cisco devices are supported. Also, investing in proper training is different from plug-and-play. I rate it an eight.
SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It does a lot of things automatically, and that's the big thing with it. They're making the software so that you don't need to be as knowledgeable as me on the switching and routing side to get your work done. If you want, you can have DNA troubleshoot your problem for you and give you solutions or fix it itself, if it was something that's just a configuration issue."
"Cisco DNA Center is a user-friendly solution."
"I like that we can easily configure any new hardware. It's also easy to deploy and easy to troubleshoot."
"What I found valuable in Cisco DNA Center is the Software-Defined Access Network, so the entire LAN network can be centralized and managed from a single dashboard. Cisco DNA Center is suitable for centralized management and lets you deploy switches in a centralized fashion. You can also do multiple switch port configurations simultaneously and segregate your traffic into multiple fabrics. Another valuable feature of Cisco DNA Center is enhanced security through Scalable Group Tags. Cisco DNA Center can be integrated with your Cisco ISE to enhance the port securities, and this paves the way for Software-Defined Networking in the LAN segment, which is the main advantage of Cisco DNA Center. I also like that you can use Cisco DNA Center for data assurance or correlation. The solution shows your network and client health parameters, which I find convenient for troubleshooting."
"People like to use the dashboards to get an overview of their network."
"Has a good processing feature with a high level of accuracy."
"What's most valuable in Cisco DNA Center is the ability to manage any Cisco infrastructure and device through it. Setup was straightforward."
"The product's most valuable feature is the visual representation of the switch's front panel."
"Cisco ISE provides authentication for various applications. It can integrate with other applications to manage access, including Privileged Access Management for those applications. For a comprehensive environment, Cisco ISE should be able to integrate and provide asset management for an IT organization or any organization."
"[One of the most valuable features] is just the ease of use. It's pretty simple to set up certs that we can add to our clients to make sure that they connect properly, [as is] whitelisting Mac addresses."
"The interface is pretty easy to use."
"The most valuable feature is the visibility element, the ability for customers to be able to see what devices are actually on their network. Without a solution like ISE, they would have no idea what devices are connected to their network. It offers them the ability to authenticate devices via mobile."
"The feature that I most like is that it can notify me whenever someone plugs in their device, which is not allowed. I get notifications for new laptop devices. I think the user interface looks good compared to previous versions."
"The RADIUS Server holds the most value."
"The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval."
"The TACACS and RADIUS have been the most valuable features so far."
 

Cons

"In terms of the clustering part, there are some concerns."
"We encountered issues with their response times, which had a big impact on our workflow."
"They can improve the network visibility. Licensing and its maintenance are also needed."
"When it comes to deploying wireless fields, integrating defaults into the DNS interface can be challenging."
"The solution's technical support is an area with which my company's clients have a problem. Cisco doesn't provide good technical support unless a user has a big account that Cisco wants to retain."
"From the recent DNA point of view, there are some stability challenges with Cisco, but very minor."
"The tool's IoT integration should be better."
"An area that needs improvement is the integration with other vendors."
"It would be ideal if Cisco could provide some short training videos or documentation to customers to help them understand how to use the product."
"In order to make it a ten, it should be more user-friendly. You need somebody who is knowledgeable about it to use it. It's not easy to use. We have to rely heavily on technical support."
"Support and integration for the active devices needs to be worked on. Their features mainly work well with Mac devices. If we use an HP the Mac functionalities may no longer be able to deliver."
"There should be an easier way to do the upgrades. There are a lot of steps to get to the next version from the previous version which ends up being a bit of the headache with the upgrade."
"The solution is not so user-friendly."
"Cisco ISE does not recognize devices and that is an issue we faced during its integration with our existing devices."
"They should improve their licensing. Licensing is always trouble with Cisco, and Cisco Identity Services Engine is no different. The way the product is licensed could be improved."
"There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that."
 

Pricing and Cost Advice

"We get a yearly license at the time we buy the product."
"Affordability is a problem because it's created for large enterprises only. So, some customers, even if their engineers want the solution, might have problems with budget limitations."
"Cisco DNA Center is expensive."
"The tool is medium-priced."
"The partnership price is notably high, but it ultimately depends on the chosen business model."
"I would rate the pricing a six out of ten, with ten being expensive."
"It is an expensive solution."
"I rate the product's pricing an eight on a scale of one to ten, where one is very cheap, and ten is very expensive."
"The price is a bit on the high side."
"ISE has always been expensive compared to other products in terms of what it does on a user level."
"I have complaints. I don't enjoy the licensing model. Once we moved from 2.7 to 3.1, switching from Base, Plus, and Apex to Essential and Advantage in Premier, we went from a perpetual, with our base licenses, to now a subscription-base. So, we will have to renew those licenses every year, and I'm not a fan of that for our base licenses. Apex/Premier, we already expected, which is fine, but for basic connectivity, I am not a fan of that."
"It is difficult to measure security breaches, but since we have not been attacked so far, it has paid for itself over the years."
"Its price is probably good if you use all of its features and functionalities to protect your environment. If you use only a part of the functionality, its price is too high. It is just a question of value and the functionality you use."
"The solution’s pricing is okay."
"The recent changes in the licensing model have caused some issues with the team."
"For the Avast virus scan, we pay around USD $95 per machine for five years which includes all updates and technical support."
report
Use our free recommendation engine to learn which Network Management Applications solutions are best for your needs.
851,823 professionals have used our research since 2012.
 

Answers from the Community

Aymen FHOULA - PeerSpot reviewer
Jul 7, 2023
Jul 7, 2023
Prerequisite: 1) ISE and Cisco DNAC are compatible versions. 2) ISE GUI password matches ISE CLI password. 3) ISE and DNAC should have full privilege Credential. 4) Enable pxGride Service. 5) Enable ERS Read/Write service. 6) ISE and DNA Should be reachable.
See 2 answers
MOHAMEDELSHERIF - PeerSpot reviewer
Mar 9, 2023
Hi Anyman 1- first you need to enable pixgrid setting at CIsco ISE at Admin setting. 2- You Need to activate ISE as Radius in DNA Setting tab at the left corner (user name and password is any ISE administrator user ). 3- From Network Hierarchy Tab in DNA Cisco  choose ISE as your AAA server. 4- You need to create STG  group at policy tab to create the proper user grouping. 4-Then go to provision / fabric / switch interface then apply ISE as your authentication profile. Most Importantly you need to ensure that your fabric switch has DNA advantage license
VK
Jul 7, 2023
Prerequisite: 1) ISE and Cisco DNAC are compatible versions. 2) ISE GUI password matches ISE CLI password. 3) ISE and DNAC should have full privilege Credential. 4) Enable pxGride Service. 5) Enable ERS Read/Write service. 6) ISE and DNA Should be reachable.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Government
10%
Manufacturing Company
9%
Healthcare Company
6%
Educational Organization
24%
Computer Software Company
14%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco DNA Center?
The most valuable feature of the solution stems from the fact that it gives some kind of ease in operations, especially since our company is moving from CLI to GUI-based configuration.
What needs improvement with Cisco DNA Center?
The system is working fine for me currently.
Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
 

Also Known As

DNA Center
Cisco ISE
 

Overview

 

Sample Customers

Information Not Available
Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Management Applications. Updated: May 2025.
851,823 professionals have used our research since 2012.