Try our new research platform with insights from 80,000+ expert users
Technology Manager at Advanced Integrated Systems
Reseller
Good integration, visibility, and automation
Pros and Cons
  • "The most valuable feature is the integration with StealthWatch and DNA as one fabric."
  • "The ISE software needs to be improved so that it is easier to administer."

What is our primary use case?

We are a system integrator and Cisco ISE is one of the products that we sell and implement at our customers side. I have built ISE's POC and provided training to our customers.

I also used real rent lab which was including; Active Directory integration, network access and core switches, access points, wireless access controller, and end points. (some end points have cisco client - anyconnect, and have not), and Web Server for creating wireless authentication portal solution end to end

The AAA features were awesome and have important attributes, and also the security groups (SGTs) concept to enforce policies for each group of users, regardless they coming via wired or wireless network devices. also i see the guest authentication is very rich and easy tom implement 

How has it helped my organization?

Cisco ISE offer one central point to create different policies for different group of users and enforce policies to each entity regardless it connected to network through wired or wireless network devices. it provide in this way more mobility and wireless-wired converged network. Also it integrates very well with network devices to control ports configurations services authentication and authorization. ISE also integrate with DNA center and stealthwatch to enable customer have SDN (Software defined Network) Fabric. 

What is most valuable?

Combines authentication,authorization,accounting(AAA),posture,and profilerinto one appliance

Provides for comprehensive guest access management for Cisco ISE administrators.

Enforces endpoint compliance by providing comprehensive client provisioning measures and assessing the device posture for all endpoints that access the network,including 802.1X Environments

EmploysadvancedenforcementcapabilitiesincludingTrustsecthroughthe use of SecurityGroup Tags(SGTs) and Security Group Access Control Lists (SGACLs)• Supports scalability to support a number of deployment scenarios from small office to large enterprise environments

What needs improvement?

The ISE software needs to be improved  in role to be easier to administer. SOftware enhancement required to have easier way to find the featured required to implement and also need enhancement of features sorting. Completing processes can be complex when try to implement some solutions. also steps are complex and the troubleshooting as well. As an example, if you intend to make AAA policy and enforce it on a group of users, you will find the software very confusing................................

Buyer's Guide
Cisco Identity Services Engine (ISE)
December 2024
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Cisco ISE for three months.

Which solution did I use previously and why did I switch?

We did not use another similar solution prior to this one.

How was the initial setup?

The initial setup was fine.

What's my experience with pricing, setup cost, and licensing?

The price for Cisco ISE is high.

Which other solutions did I evaluate?

We did not evaluate other options before adopting this solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: My Company is Cisco Reseller
PeerSpot user
Ntwrkengine0887 - PeerSpot reviewer
Senior Network Engineer at a comms service provider with 1,001-5,000 employees
Reseller
Compatible with Microsoft products and offers advanced firewall support
Pros and Cons
  • "The best feature of the Cisco ISE platform is that it is compatible with Microsoft products."
  • "Cisco ISE is complex. The deployment and design of networks with it is so complex. If it could change it would be better."

What is our primary use case?

We use Cisco ISE for network management, user access for enterprise clients, and advanced firewall support. We use Cisco ISE on domains and clients jointly with other network software utilities.

How has it helped my organization?

We use Cisco ISE as our main controller for the management of clients that need to join our network.

What is most valuable?

The best feature of the Cisco ISE platform is that it is compatible with Microsoft products. 

What needs improvement?

Cisco ISE is complex. The deployment and design of networks with it is so complex. If it could change it would be better. 

It needs a better solution for reduced complexity.

I think to add more people to four-thousand users is going to be hard. Cisco needs to make it easier to add more people.

For how long have I used the solution?

We have been using the solution for three years.

What do I think about the stability of the solution?

The Cisco ISE platform is stable.

What do I think about the scalability of the solution?

On our network, we use Cisco ISE as a platform utility to support three thousand users.

How was the initial setup?

The initial setup of the Cisco ISE platform was complex and the deployment was also difficult.

What other advice do I have?

On a scale from one to ten, I would rate Cisco ISE an eight because the server is so complex. Cisco needs to re-program or re-issue it and release a new version with more adequate sizing for small businesses. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Cisco Identity Services Engine (ISE)
December 2024
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
PeerSpot user
Senior Network Operations Specialist at a government with 1,001-5,000 employees
Vendor
This technology is based upon utilizing other Cisco products such as IDS, IPS, ASA and Catalyst switches.

Valuable Features:

Cisco Identity Services Engine (ISE) version 1.3 has improved it's GUI margin and much easier to navigate than the previous versions. 

This technology pride itself with Trust Sec and 802.1x  feature. Trust Sec can be an advantage when an environment is nothing but a Cisco workshop.

This technology is based upon utilizing other Cisco products such as IDS, IPS, ASA and Catalyst switches. It provides the RADIUS feature for Active Directory so that 802.1x (EAP over LAN) is properly utilized for User Authentication.  

It also does MAC Address Bypass (MAB) for MAC Address verification and authentication.  

Cisco will integrate the TACACS+ feature into ISE version 2.0 and enterprises no longer need Cisco ACS for this reason.  

Improvements to My Organization:

Many organizations and large enterprises are faced with the daunting task of keeping their security issues at bay. They also need to be in compliant with the Cyber Security's strict guidelines and orders.  

While there are many cyber attacks from the outside of the edge routers, cyber attacks can also be implemented within the organization whether it is either intentional or unintentional.  Cisco ISE can mitigate many attacks such as MAC spoofing, VLAN hopping, DHCP Starvation and ARP Snooping.

By implementing ISE, it can lighten the overhead of the Cisco Catalyst Switches by not implementing port security, Dynamic Arp Inspection, DHCP Snooping. This will also improve the switch's performance since the ISE server takes over the duty of posturing with its Policy Service Node persona.  

Room for Improvement:

Cisco ISE has improved performances on Access Switches and closely monitored the daily suspicious or rogue activities within the organization.  

Deployment Issues:

We've had no issues with deployment.

Stability Issues:

We've had no issues with stability.

Scalability Issues:

We've been able to scale it for our needs.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1024695 - PeerSpot reviewer
Owner at a tech services company with 11-50 employees
Real User
A network administration product that is easy to use, but migration could be better
Pros and Cons
  • "I like that Cisco ISE is easy to use."
  • "Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things. Whenever we choose a product, it's very difficult because we have to meet the requirements of each feature. There is no standard feature, so the best system that we bought may not fit the solution. We have to look at every feature that the customer uses. If you compare it with other products like Aruba, it's not the same. With Cisco, I have to read all about the features on this version and the licensing required for the product. In Aruba, that thing is covered when you get one license because it covers almost everything. It could also be more scalable."

What is our primary use case?

We use Cisco ISE to develop products for other people. We don't really use it in our system. We just buy it and implement it when our customers require ISE.

What is most valuable?

I like that Cisco ISE is easy to use.

What needs improvement?

Migration could be better. Right now, we back up with the new version, and it requires a lot of licensing and other things. Whenever we choose a product, it's very difficult because we have to meet the requirements of each feature. There is no standard feature, so the best system that we bought may not fit the solution. 

We have to look at every feature that the customer uses. If you compare it with other products like Aruba, it's not the same. With Cisco, I have to read all about the features on this version and the licensing required for the product. In Aruba, that thing is covered when you get one license because it covers almost everything. It could also be more scalable.

For how long have I used the solution?

We have been using Cisco ISE for 20 to 30 years.

What do I think about the scalability of the solution?

It could be more scalable. It's easy to scale initially, but it will become very difficult at a certain point. In the beginning, it's in the previous environment, and it's pretty easy. But after we integrate it, we need to do a couple more to scale the product, which is more difficult.

We have less than 300 people using it worldwide. We deal with an airline company, so people who come to use it aren't many, but it's available to everyone from everywhere around the world.

How are customer service and support?

We deal with a local Cisco partner for technical support. I haven't dealt with Cisco directly in Bangkok. 

How was the initial setup?

I think Cisco takes around six months to complete the migration from the old one to the new one. This is because we have compliance and a lot of other things here.

What about the implementation team?

Our in-house team implements this solution. It takes about three people to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

It costs around 50,000 baht in the first year, but I'm unsure about the second year.

What other advice do I have?

On a scale from one to ten, I would give Cisco ISE a seven.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Principal ICT Assistant at a educational organization with 1,001-5,000 employees
Real User
Allows us to use our public ID properly
Pros and Cons
  • "The most valuable feature is the ASDM - the user interface makes it very easy to configure the firewall."
  • "I would like the product to include support for OSVS version three."

What is our primary use case?

My primary use case is network address translation and layer 4 filtering.

How has it helped my organization?

Without this product, we wouldn't be able to use our public ID the way we need to.

What is most valuable?

The most valuable feature is the ASDM - the user interface makes it very easy to configure the firewall.

What needs improvement?

I would like the product to include support for OSVS version three.

For how long have I used the solution?

I've been using this solution for about five years.

What do I think about the stability of the solution?

This is a stable product.

What do I think about the scalability of the solution?

The scalability is good - currently, we don't have an internet bandwidth greater than 10GB, so it's efficient for us.

How was the initial setup?

The initial setup was straightforward, and deployment was done in one night.

What about the implementation team?

I implemented using an in-house team.

What was our ROI?

This product has helped us protect our infrastructure.

Which other solutions did I evaluate?

I considered some open source solutions, but those are usually difficult to set up.

What other advice do I have?

I would recommend this solution as it is very easy to set up and has a very easy user interface. I would rate this solution as eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Engineer at a energy/utilities company with 201-500 employees
Real User
Good stability and enables us to identify and isolate a machine that is infected or that is going to be infected
Pros and Cons
  • "The initial setup was easy. It took around one month. We did the installation part within half an hour to two hours but we found a couple of issues so we raised a case and once everything was resolved it was a month in total."
  • "Since we have started, we struggled a lot to implement this solution into our network, and we opened a case a couple of times. Up until this point, nothing else needs to be improved with this product."

What is our primary use case?

We use this solution to authenticate the domain users and if someone is not the domain user to make them a guest.

How has it helped my organization?

Before, our port would be wide open, anyone could come to the network and put their laptop into the port or any device and they would be able to get the IP. Now, if someone tries to connect to our network through an IU port or internet, they will not be able to access it. Another way this solution has improved our organization is that when we integrate this with our OpenGate server we are able to identify and isolate the machine that is infected, or that is going to be infected.

Plus, we had control on which device we can block in real-time and white list, or according to the MAC address, we can send this device to get an assigned IP from a special VLAN.

What is most valuable?

The identification with McAfee DHL is the most valuable feature. It gives us full visibility to see if there's any malware or malicious activity going on in the network and will then isolate the device.

What needs improvement?

Since we have started, we struggled a lot to implement this solution into our network, and we opened a case a couple of times. Up until this point, nothing else needs to be improved with this product.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Stability is very good. We haven't faced any issues and there aren't any bugs. 

What do I think about the scalability of the solution?

We currently have around 400 users and we only need two staff members for maintenance. It is being used extensively because all of the users are dependent on it. If the ISE is down no one will be able to authenticate.

How is customer service and technical support?

Technical support is very good because, on the user phase, it shows who was on the call with us and who helped us. 

How was the initial setup?

The initial setup was easy. It took around one month. We did the installation part within half an hour to two hours but we found a couple of issues so we raised a case and once everything was resolved it was a month in total. 

What about the implementation team?

We used an integrator. We had a good experience with them because we have already worked with them in the past couple of years

Which other solutions did I evaluate?

We researched this solution and found that it fulfills all of our requirements so we didn't look into any other solutions.

What other advice do I have?

I would rate this solution a nine out of ten. 

I would advise someone considering this solution not to enable it with MAC. They are going to be in a very bad state after enabling this with MAC because if you do it is going to isolate so many devices which do not comply with the policy.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Network Engineer with 1,001-5,000 employees
Real User
It can handle Radius and TACACS+. It is quite complex when it comes to troubleshooting.

What is most valuable?

It can handle Radius and TACACS+.

How has it helped my organization?

Authorisation and Authentication Policy creation is easier. Access right limitation is pretty easy in ISE. Context exchange feature is present.

What needs improvement?

It is quite complex when it comes to troubleshooting.

For how long have I used the solution?

2 years

What was my experience with deployment of the solution?

Upgrade was quite a pain. It doesn't exactly go according to the document.

What do I think about the stability of the solution?

On TACACS side, we see some issues. The rest is all going well.

How are customer service and technical support?

Customer Service:

It's good.

Technical Support:

Tech support is still lacking on TACACS troubleshooting on ISE.

Which solution did I use previously and why did I switch?

We were using ACS and IAS servers for radius and TACACS. ISE is one stop shop for everything with more to offer.

What about the implementation team?

Initially done with a Cisco consultant and started with Radius services. Expertise was excellent.

What's my experience with pricing, setup cost, and licensing?

Smartnet is not so cheap depending on the deployment.

What other advice do I have?

We have deployed this solution and we keep on exploring more and more. It can do wonders for authentication and limiting access with the network.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user375078 - PeerSpot reviewer
it_user375078Senior Network Engineer/Mobility Specialist at CCSI - Contemporary Computer Services, Inc.
Real User

We may have borrowed ideas from other sources, but I do not think so. More based on years of experience with ACLs, firewall rule sets and working on the ISE flow and best practices. Also creating a flow chart of ISE flow is great. If you can create it prior to configuration it will guide you. And then create or adjust after implementation. Remember that if your flow chart is clumsy or difficult to organize chances are that your logic is also clumsy or even incorrect. With that said if you are new to ISE (and Dot1x, EAP and RADIUS) a poor flow chart may not reflect an incorrect implementation but a lack of understanding of the underlying principles. GOOD LUCK again!

See all 11 comments
reviewer935628 - PeerSpot reviewer
Sr.Manager at a energy/utilities company with 10,001+ employees
Real User
Easy to use, centralized administration, and scalable
Pros and Cons
  • "The most valuable features are authentication, we have more granular control on the access policies for the administrators. The solution is easy to use, has a center point administration, and has a good GUI."
  • "The solution could be more secure."

What is our primary use case?

We use Cisco ISE for device authentication, such as auto switches, and wireless authentication.

What is most valuable?

The most valuable features are authentication, we have more granular control on the access policies for the administrators. The solution is easy to use, has a center point administration, and has a good GUI.

What needs improvement?

The solution could be more secure.

For how long have I used the solution?

I have been using Cisco ISE (Identity Services Engine) for approximately five years.

What do I think about the stability of the solution?

Cisco ISE is stable.

What do I think about the scalability of the solution?

I have found Cisco ISE to be scalable.

We have approximately 500 people using this solution in my organization.

Which solution did I use previously and why did I switch?

We were using Cisco ACS previously. I have found Cisco ISE to be a more advanced and easy-to-use solution than the Cisco ACS.

How was the initial setup?

The installation is straightforward since we have worked on Cisco platforms previously.

What about the implementation team?

We have approximately 100 people for the maintenance and support of this solution.

What other advice do I have?

I rate Cisco ISE (Identity Services Engine) an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.