Endpoint visibility, policy flexibility, compatibility and integration with other products.
Network Access Control Security at a government with 10,001+ employees
Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP
What is most valuable?
How has it helped my organization?
Automation! One broad example is that we can now stop network threats right away and without intervention.
What needs improvement?
Forescout is constantly adding new features, so this may change as of this writing, but sometimes the switch management interface doesn't display accurate information which relates to false positives on individual switch access errors.
For how long have I used the solution?
1 year
Buyer's Guide
Forescout Platform
April 2025

Learn what your peers think about Forescout Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
846,617 professionals have used our research since 2012.
What was my experience with deployment of the solution?
None that were Forescout related. CounterACT always opens a bunch of little IP sessions with endpoints, ake sure you have a large enough connection table on your firewall if you plan to put it behind one.
What do I think about the stability of the solution?
Minor. Had to reinstall one virtual appliance, which is painless when you have an Enterprise Manager.
What do I think about the scalability of the solution?
No, this is one of the products strengths.
How are customer service and support?
Customer Service:
10 out of 10. Very responsive and address concerns quickly.
Technical Support:9 out of 10. Really fast response, high level of competency.
Which solution did I use previously and why did I switch?
I switched from Cisco NAC because it is reliant on 802.1X, and has no other function than to ensure endpoints have authenticated via your method of choice.
How was the initial setup?
Straightforward. Setup is simple with a solid, pre-defined set of policies that you build on and customize as you learn.
What about the implementation team?
In house.
What was our ROI?
Without access specific numbers, we now have the ability to instantly shut down internal malicious hosts or traffic, refuse or restrict access to non-compliant hosts, discover risks on the network we didn't know were there, and automate the remediation of a multitude of security risks. As I work for an organization that spends a lot on security administration, at a minimum, the cost savings must have already paid for the product.
Which other solutions did I evaluate?
Palo Alto
What other advice do I have?
Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP address. For example, a busy core switch can have 20+ IP addresses, and each one goes against your license count. Also, if you plan to have it behind a firewall, take into consideration your firewall's connection limitations. Although CounterACT isn't really a heavy bandwidth user, it does open a ton of short connections on a constant basis. The more you tune these down, the less accurate your real time host information becomes.
Disclosure: My company has a business relationship with this vendor other than being a customer: I currently work as a Solution Architect for ForeScout, but I wrote this review when I was a customer.
Chief Executive Officer at Grand Ortus Solutions Pvt Ltd
Comprehensive and advanced cybersecurity excels in providing device visibility and control, robust integration capabilities
Pros and Cons
- "The standout strength of this solution lies in its unique capability to effectively manage unmanaged switches."
- "Regarding pricing, there is room for improvement to enhance competitiveness with other vendors and solutions."
What is our primary use case?
It enhances cybersecurity by allowing us to monitor and manage all connected devices on our network.
What is most valuable?
The standout strength of this solution lies in its unique capability to effectively manage unmanaged switches. In addition to its comprehensive feature set, it focuses on AAA for enhanced security and network control.
What needs improvement?
Incorporating additional features such as NetFlow DLP, would serve as valuable add-ons. Regarding pricing, there is room for improvement to enhance competitiveness with other vendors and solutions.
For how long have I used the solution?
I have been working with it for seven months.
What do I think about the stability of the solution?
I would rate its stability capabilities nine out of ten.
What do I think about the scalability of the solution?
Scaling it poses no challenges or obstacles. I would rate it nine out of ten.
What about the implementation team?
The deployment time varies based on the customer's network and its complexity. It could range from as little as five to seven days to one or two months, depending on factors such as the number of switches involved. I oversee a maintenance team comprising over 35 skilled individuals dedicated to network and security solutions. Our technical staff is well-rounded, with three experts specializing in Mac solutions, while others are adept in various network features such as routing and firewall management.
What's my experience with pricing, setup cost, and licensing?
The pricing structure should be enhanced.
What other advice do I have?
Overall, I would rate it nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Forescout Platform
April 2025

Learn what your peers think about Forescout Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
846,617 professionals have used our research since 2012.
CEO at Mazeedah
It can block the endpoint at the point of collection, but it needs to improve cloud management and remote connectivity
Pros and Cons
- "Forescout has a feature that blocks the endpoint at the point of collection. It sets preconditions and will block the system if those aren't met."
- "Forescout needs to improve its cloud management and remote connectivity."
What is our primary use case?
We're a financial institution with about 30,000 users.
What is most valuable?
Forescout has a feature that blocks the endpoint at the point of collection. It sets preconditions and will block the system if those aren't met.
What needs improvement?
Forescout needs to improve its cloud management and remote connectivity.
For how long have I used the solution?
We have been using Forescout since 2018.
What do I think about the scalability of the solution?
Forescout's scalability isn't robust or straighforward enough. You need to plan ahead and purchase the correct appliance before scaling up. You will be limited if you buy a smaller plan.
How are customer service and support?
You often need in-person support, so Forescout should invest more in training its customers. Customers need to be confident that they can service the solution themselves because it's often hard to get a technician to show up on-site.
Which solution did I use previously and why did I switch?
We also use FortiClient, depending on the use case. Both solutions are good.
How was the initial setup?
Deploying Forescout is complex and takes about four hours. You have to configure the devices before you can send packets. If you miss any of those devices, the application endpoint security will be compromised In other solutions, you don't need to start the configuration before you can access the network advice. It pushes a policy based on the outcome of the process.
What's my experience with pricing, setup cost, and licensing?
The price could be reduced. During COVID, many offices switched to remote work, but you still need to pay the same cost to renew the license even though workers are connecting remotely through one VPN.
What other advice do I have?
I rate Forescout Platform six out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technology Officer at Mehbub General Trading PLC
A stable and scalable tool that is very easy to work with and easy to deploy
Pros and Cons
- "The product is very easy to work with and easy to deploy."
- "The fact that Forescout Platform doesn't have a presence in the South African region is a weakness because of which you can't ask for help from them if you have any problems."
What is most valuable?
The most valuable feature of the solution is that it is not dependent on whatever suite or product you use.
The product is very easy to work with and easy to deploy.
What needs improvement?
Weaknesses of the product are usually present from the side of vendors. In the case of Cisco's vendors, they do have a presence in the South African region. The fact that Forescout Platform doesn't have a presence in the South African region is a weakness because of which you can't ask for help from them if you have any problems. Though they offer support, Forescout Platform does not offer a vendor like other products do for even East Africa ensuring they deliver better services to their customers. The aforementioned area can be considered for improvement.
Maybe integration with or onboarding an XDR solution is something I would like to see in future product releases.
For how long have I used the solution?
I have experience with Forescout Platform for about three years. My company has a partnership with Forescout. We are also resellers of Forescout.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution.
I can recommend the solution to medium and enterprise-sized companies. I recommend an open-source product over Forescout Platform to small businesses.
How are customer service and support?
The solution's technical support can onboard more users. I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
An advantage of Forescout Platform is that it is easy to deploy.
The deployment process took around a week.
What's my experience with pricing, setup cost, and licensing?
The product's pricing is reasonable. Considering the deployment or the professional service, on the other side, along with the basic service, which was a bit technical, with the product and the licenses, Forescout Platform can compete with other products.
What other advice do I have?
My company does help our customers manage Forescout Platform.
I would definitely recommend the solution to those planning to use it.
Overall, I rate the solution a nine and a half out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Senior Manager Network Design at MEEZA, Managed IT Services Provider
Easy deployment, good support, and highly scalable
Pros and Cons
- "The stability is amazing for the Forescout Platform. We have been using Forescout for four years, and no one complained about the stability."
- "Two things can be improved in the Forescout Platform. First of all, the support for some certain proprietary protocols from other vendors, but they are very widely used. If the TechEx from Cisco, was added to Forescout, then it will be a full solution for me."
What is our primary use case?
Forescout Platform can be deployed on the cloud or on-premise.
When we have a large enterprise environment with a lot of users, different security policies are to be applied in certain situations and locations. This is where the Forescout Platform is used. If we have some compliance requirements to have the NAC solution in place, we prefer the Forescout Platform over other solutions.
What needs improvement?
Two things can be improved in the Forescout Platform. First of all, the support for some certain proprietary protocols from other vendors, but they are very widely used. If the TechEx from Cisco, was added to Forescout, then it will be a full solution for me.
Forescout Platform can be much improved. The support for certain proprietary protocols from other vendors, but they are very widely used. If I can go a little bit technical here, I would say the TechEx from Cisco, if added to Forescout, then it will be a full solution for me. Additionally, the Forescout Platform can have better integration with other solutions, such as Cisco NFG firewalls. They need to integrate seamlessly.
For how long have I used the solution?
I have been using the Forescout Platform for four years.
What do I think about the stability of the solution?
The stability is amazing for the Forescout Platform. We have been using Forescout for four years, and no one complained about the stability.
What do I think about the scalability of the solution?
The scalability of the Forescout Platformall depends on the license. For example, if you have a certain amount of users, endpoints, and anything else you need to put under governance. If you scale out to a higher number, all you need to do is increase the license.
We have five customers and a total endpoints users of approximately 15,000.
How are customer service and support?
The support from the vendor we have received was good.
How was the initial setup?
The initial setup is straightforward. We had to implement the solution in a short timeframe and we managed to do it in one month as a managed service.
Forescout Platform is easy to deploy. It's the fastest NAC solution that you can deploy in a large environment. There is the opportunity to improve as you go. It can be the first deployment, and you can improve as you go without any big disturbance to the environment. It's very flexible when it comes to implementing a certain security policy. You can have very complex security policies for the Forescout Platform. It makes the deployment much easier than others.
What about the implementation team?
The deployment for the Forescout Platform takes two to three engineers. However, it depends on the size of the environment. The integration or the co-operation should happen with a lot of other teams. The main deployment team for the solution is from two to three persons.
What's my experience with pricing, setup cost, and licensing?
We have a very clear licensing model for business. I don't have to have a Ph.D. to be able to understand the licensing model as you might need for other solutions. If I know exactly what we want, it can tell you which license you need. The solution is easy for purchasing, ordering, and ease of deployment as well.
As a managed service provider and system integrator, we are on an annual licensing model.
What other advice do I have?
I highly recommend Forescout Platform, unless, there is a need to integrate with any Cisco TechEx environment. For other use cases, it should be the first choice as a NAC solution. It should come as the first option, with one exception only, if the environment has a lot of Cisco devices. The Forescout Platform does not support authentication to Cisco devices. There is a lack of some protocols on the box itself.
I rate Forescout Platforma nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Ingeniero Senior en seguridad y telecomunicaciones at a non-tech company with 1,001-5,000 employees
A straightforward setup with good technical support and good stability
Pros and Cons
- "The user management has been very easy for the most part."
- "The licensing costs are quite high. With the amount of hardware we have, we need too many licenses to make the product effective and it's ultimately just too costly."
What is our primary use case?
We needed some protection in our environment. We use this product in some areas in our network to monitor the security of the endpoints of our users.
What is most valuable?
The environment was easy to configure.
The user management has been very easy for the most part.
The initial setup is pretty easy.
Technical support has been very helpful.
The stability overall is good.
What needs improvement?
The licensing costs are quite high. With the amount of hardware we have, we need too many licenses to make the product effective and it's ultimately just too costly.
We may have some problems with compatibility - specifically with Cisco switches. We have the perimeter a Check Point firewall as an alarm for VPN connections. We have users integrating the VPN Check Point with Forescout. We can't seem to scale due to compatibility issues and price.
For how long have I used the solution?
We have been working with the solution for around two years. It hasn't been that long. That said, we are moving away from the solution.
What do I think about the stability of the solution?
Overall, the stability of the product has been very good. It doesn't crash or freeze. There aren't bugs or glitches. It's been set up very well. We've found it to be reliable and the performance is good.
What do I think about the scalability of the solution?
Our issue, in terms of scalability, is that we have a brittle machine. We struggled to get the licenses loaded. We would need to change the machine in order to develop a certain level of scalability capabilities.
At the moment, we have about 100 users on the solution, however, we require more licenses. Our goal was 1000 users on devices, however, it wasn't possible. The economics were against us.
How are customer service and technical support?
While I have never personally opened a case with technical support in the past, my colleague has. He found them to be very responsive and helpful. He was satisfied with their level of service.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. Forescout was our first.
We are just now migrating to Cisco ISE. The problem is that we have around 500 users and we have only 100 licenses from Forescout due to the fact that it is a little expensive for us. We are trying instead to move to Cisco ISE, which has better pricing.
How was the initial setup?
The initial setup was not complex. It was pretty easy. Installation maybe takes one or two days, and the implementation in total takes around two weeks.
We have a partner from Forescout in my country. He came to my company to meet with us. He helped explain a few things and assisted with network displays.
There were about eight people that handled deployment between our end and the technical support side.
What about the implementation team?
A Forescout representative ultimately came to our company for us. They assisted a little. They understood the cloud very well and were very helpful.
What's my experience with pricing, setup cost, and licensing?
The licenses are quite expensive. Ultimately, we couldn't afford the amount we needed, and therefore we are moving off the product.
We might have paid in the ballpark of $20,000 yearly for our licenses. I do not recall there being other fees over and above the standard licensing fee.
Which other solutions did I evaluate?
We evaluated Cisco. The difference is the compatibility with our network. Other switches are Cisco devices, and therefore the compatibility and the integration were a little easier. With Forescout we have had some issues with some other access points. With Cisco ISE, we don't have that problem.
What other advice do I have?
I do not recall which version of the solution we are using. We use the on-premises deployment model, however, we also have some clients on the cloud.
I would advise other organizations that, if they have multi-vendors in their network, use Forescout. However, if most of the devices are Cisco, it is best to use Cisco ISE.
It is a great tool and solution. We looked into it with the Magic Quadrant of Gartner and we have seen that it is a leader in the space. However, for us, it just doesn't work as well in terms of compatibility.
I'd recommend the solution. I would rate it at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Network Engineer at William Blair & Company
Monitors network access globally and improves overall security while reducing risk
Pros and Cons
- "Forescout CounterACT has allowed us to better open our access and control wireless access globally from our HQ. This allows us to monitor the network access for every office globally. This has improved overall security, reducing risk and opening up the opportunity to provide greater end user flexibility."
- "More detailed analysis during the authentication process, especially for troubleshooting access issues. We have found that troubleshooting RADIUS controls is quite arduous, as it is today. A trace function could easily resolve this by providing a means by which access issues from a certificate to passwords or accounts could easily be identified and remediated."
What is our primary use case?
To be able to improve security within our network. We needed Network Access Control (NAC). As such, we reviewed the available vendors who could provide this service to us and selected the Forescout CounterACT (CA) product primarily because we needed to be able to position the product in several regional locations. At the same time, we managed and controlled it locally and dynamically where we have it responding to a single control center. While we have implemented today strictly for wireless access, we will be extending that to include wired access in the future.
How has it helped my organization?
NAC: Forescout CounterACT has allowed us to better open our access and control wireless access globally from our HQ. This allows us to monitor the network access for every office globally. This has improved overall security, reducing risk and opening up the opportunity to provide greater end user flexibility.
What is most valuable?
The key feature we use is AD integration. That feature needs the least amount of attention once set up.
Monitoring and logging are the pieces that we use most day-to-day. These are used by both our network and security teams to ensure proper operation with minimal risk. Whether machines attempting access are firm managed, vendors visiting, or IoT, all are available within the CA appliance. We plan to extend the use to further support growth functionalities and new work from home initiatives going forward.
What needs improvement?
Better reporting and analysis of access (based on client) would be helpful. Also, a tool that allows tracing a user through the rules to authentication.
More detailed analysis during the authentication process, especially for troubleshooting access issues. We have found that troubleshooting RADIUS controls is quite arduous, as it is today. A trace function could easily resolve this by providing a means by which access issues from a certificate to passwords or accounts could easily be identified and remediated.
For how long have I used the solution?
Two years.
What do I think about the stability of the solution?
ForeScout CA has proven itself to be very solid.
What do I think about the scalability of the solution?
It is very scalable with a lot of features that we aren't even using yet today.
How are customer service and technical support?
Technical support has been great. They are very knowledgeable, helpful, and considerate.
Which solution did I use previously and why did I switch?
We used Cisco ISE but found that it did not have the flexibility that we needed within our organization.
How was the initial setup?
Setup was anything but straightforward, but this had nothing to do with Forescout. This is the nature of NAC solutions in general.
Setup takes significant preplanning. Don't expect to just drop it in, then have it up and running, even if you already use an alternative NAC product. However, it is worth it.
What about the implementation team?
We used a Professional Services engagement from Forescout, but still experienced a lot of issues.
What was our ROI?
I don't know.
What's my experience with pricing, setup cost, and licensing?
The fact that we were allowed to spin up as many servers as we had need of to support our geographic requirements while paying for licensing as an enterprise truly set Forescout apart from the crowd and improved the way we could design our access.
Which other solutions did I evaluate?
We had ISE. As that product reached EOL, we considered whether there were alternatives to a NAC that we should consider but felt that a NAC is a security requirement.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Cyber Security Engineer at Beta Information Technology
The solution has easy implementation and operation, along with a user-friendly GUI
Pros and Cons
- "The solution's implementation and operation are very easy."
- "The solution's customer support is bad and should be improved."
What is our primary use case?
I use the Forescout Platform for different customers from the enterprise, banking, and telecom sectors.
What is most valuable?
The solution's implementation and operation are very easy. The solution's GUI is very user-friendly. It doesn't have a lot of components. It has only one device or a few devices connected to one management with only one agent.
What needs improvement?
The solution's customer support is bad and should be improved. When our customers try to reach or discuss with the support team, they don't even answer.
For how long have I used the solution?
I have been using Forescout Platform for two years.
What do I think about the stability of the solution?
I rate Forescout Platform a seven out of ten for stability.
What do I think about the scalability of the solution?
I rate the solution an eight or nine out of ten for scalability.
How was the initial setup?
The solution’s initial setup is very easy.
What other advice do I have?
Overall, I rate Forescout Platform an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Forescout Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Network Access Control (NAC) IoT Security Endpoint Compliance Extended Detection and Response (XDR)Popular Comparisons
Cisco Identity Services Engine (ISE)
Aruba ClearPass
Fortinet FortiNAC
F5 BIG-IP Access Policy Manager (APM)
macmon Network Access Control
Sophos Network Access Control
ExtremeControl
Ivanti NAC
Genian NAC
Impulse Point SafeConnect
SecureTrust Network Access Control
Buyer's Guide
Download our free Forescout Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- PRICING FOR FORESCOUT CT10K APPLIANCE
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Comparison of Aruba Clearpass, Bradford Networks and Forescout NACs
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- PRICING FOR FORESCOUT CT10K APPLIANCE
- When evaluating Network Access Control, what aspect do you think is the most important to look for?
- Which is the best choice of Zero Trust Network Access (ZTNA)?
- What is your recommended Network Access Control (NAC) solution for an enterprise?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
Technology improved network security via access layer L2.