Aruba ClearPass and Cisco Identity Services Engine (ISE) are leading solutions in network access control. Aruba ClearPass has the upper hand due to its open vendor support and comprehensive device management capabilities, making it more appealing for diverse environments.
Features: Aruba ClearPass offers a wide range of networking security features, including essential components like Policy Manager and OnGuard. It ensures strong integration with third-party systems and supports flexible deployment options, making it suitable for various environments. Additionally, ClearPass is well-regarded for its guest onboarding and device management functions. Cisco Identity Services Engine focuses on secure access control through policy enforcement and posture assessments, making it ideal for Cisco-centric environments. ISE provides seamless integration with other Cisco products and advanced security features.
Room for Improvement: Aruba ClearPass can enhance its user interface for easier setup and management and improve its documentation. The clarity on licensing, especially in educational setups, also needs improvement, along with better integration capabilities with non-Aruba products. Cisco ISE faces challenges with its complex deployment process and unclear licensing model. User feedback suggests a requirement for improved updates, documentation, and a simplified feature set for better usability. The high infrastructure demands further differentiate it from ClearPass's agile deployment possibilities.
Ease of Deployment and Customer Service: Aruba ClearPass often requires consulting for initial setup due to its complexity but is lauded for its efficient customer service and support expertise. Cisco ISE faces complexity in deployment, particularly in hybrid or multi-vendor environments, highlighting a common challenge for its users. While Cisco's support tends to be reliable post-deployment, ClearPass is often preferred for its broader vendor compatibility and satisfactory customer support experiences.
Pricing and ROI: Aruba ClearPass leads to higher initial costs with add-ons and hardware maintenance, yet it provides a simpler licensing model with long-term cost advantages for large deployments. Cisco ISE incurs substantial costs due to its complex licensing structure and hardware requirements, posing financial challenges, particularly for smaller organizations. Despite both products offering valuable security capabilities, ClearPass potentially promises a more favorable cost-benefit trajectory over extended usage.
Using Aruba ClearPass has resulted in less engineering time compared to other products we've used.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
Portnox is one level up, as their customer support is outstanding.
We have escalated questions to tech support, and I would rate the technical support an eight out of ten.
We have local support, so it's much easier.
I rate the technical support as one out of ten.
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
I believe the scalability of ClearPass is rated as ten out of ten.
In our environment, ClearPass handles up to 100,000 users, which is better than some other NAC solutions like Fortinox that scale up to 25,000.
Once the policy is defined, scaling works automatically and is fast.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
The language and policy enforcement mechanisms are not clear, making it difficult to use the product effectively.
I don't see any limitations in ClearPass.
It is also better to improve threat intelligence for built-in threat detection and prevention.
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Additionally, the product is vulnerable and has many bugs.
We cannot mix in prices, and of course, prices are going higher.
Achieving the best price requires careful selection from a menu of licensing options.
Aruba ClearPass is a premium product with higher pricing, which seems unnecessary given its complexity.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
The most effective feature for us is the OnGuard feature.
The ClearPass solution has reduced the amount of engineering time compared to previous solutions, making it more efficient for our purposes.
Cisco Identity Services Engine (ISE) is very good at device administration.
The solution is integrated with other Cisco devices and can offer automation for an organization, making deployments more dynamic and providing real-time visibility.
Aruba ClearPass is a network access control (NAC) solution that provides a range of security and access management capabilities for wired, wireless, and VPN networks. ClearPass enables organizations to secure their networks and devices, enforce security policies, and provide secure access to network resources.
Aruba ClearPass Features
Aruba ClearPass has many valuable key features. Some of the most useful ones include:
Aruba ClearPass Benefits
There are many benefits to implementing Aruba ClearPass. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Aruba ClearPass is a solution that stands out when compared to many of its competitors. Some of its major advantages are that it’s easy to use, has a valuable Guest Captive Portal and virtual security enforcement, and has a good web dashboard and policy manager.
“It is easy to use and more integrated with the Aruba wireless networks,” says Muhammad N., Network & Information Security Engineer at a healthcare company.
Ammar F., Head of IT at Hubtech, explains, “What I like most about Aruba ClearPass is that it has the best enforcement feature for the network. I also like its Guest Captive Portal and virtual security enforcement features, but the virtual security enforcement feature is still under testing by my company. Aruba ClearPass also has a wonderful UI which I find valuable."
Another PeerSpot reviewer mentions, "The web dashboard and the policy manager are very intuitive and very easy for the engineers to use."
Cisco ISE is an all-in-one solution that streamlines security policy management and reduces operating costs. Cisco ISE delivers visibility and access control over users and devices across wired, wireless, and VPN connections.
Identity Services Engine enables enterprises to deliver secure network access to users and devices. It shares contextual data, such as threats and vulnerabilities, with integrated solutions from Cisco technology partners. You can see what is happening in your network, which applications are running, and more.
Features of Cisco ISE
Benefits of Cisco ISE
Cisco’s holistic approach to network access security has several advantages:
Support
You can get ISE as a physical or virtual appliance. Both deployments can create ISE clusters that create scale, redundancy, and requirements.
Licensing
Cisco ISE has four primary licences. Evaluation for up to 100 endpoints with full platform functionality. The higher tiers are Partner, Advantage and Essential.
Reviews from Real Users
"The user experience of the solution is great. It's a very transparent system. according to a PeerSpot user in Cyber Security at a manufacturing company.
Omar Z., Network & Security Engineer at an engineering company, feels that "The RADIUS Server holds the most value."
“Whether I deploy in China, the US, South Africa, or wherever, I can get all the capabilities. It allows me to directly integrate with 365, and from a communications point of view, that is a good capability," says Rammohan M., Senior Consultant at a tech services company.
Hassan A.,Technology Manager at Advanced Integrated Systems, says that "The most valuable feature is the integration with StealthWatch and DNA as one fabric."
We monitor all Network Access Control (NAC) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.