Try our new research platform with insights from 80,000+ expert users

Cisco ACI vs Cisco Secure Workload comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco ACI
Ranking in Cloud and Data Center Security
4th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
101
Ranking in other categories
Network Virtualization (1st), Software Defined Networking (SDN) (2nd)
Cisco Secure Workload
Ranking in Cloud and Data Center Security
6th
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
15
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (16th), Microsegmentation Software (5th), Cisco Security Portfolio (9th)
 

Mindshare comparison

As of January 2025, in the Cloud and Data Center Security category, the mindshare of Cisco ACI is 11.2%, down from 11.5% compared to the previous year. The mindshare of Cisco Secure Workload is 19.0%, up from 15.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud and Data Center Security
 

Featured Reviews

Raj Metkar - PeerSpot reviewer
Provides scalability, ease of migration for future DC moves, multi-tenancy and programmability
Cisco's MSO (Multi-Site Orchestrator) or NDO has room for improvement. Cisco monitors ACI through a product called NDI. I find it very frustrating that Cisco has multiple monitoring platforms. It has DNAC for monitoring Cisco NX-OS, campus switches, and any other routers and switches you would have in the environment. That same thing does not work for Cisco ACI monitoring. MEraki cloudbasd platform for Meraki which will get extended to Campus monitoring, to be honest Cisco never got Monitoring 100% right from days of CiscoWorks to Prime to current platforms. To monitor and manage Cisco ACI, you need to have another platform called NDI and Cisco Dashboard Insights. What frustrates me about Cisco is that it never has a central, single pane of glass platform for all its solutions. It has one thing for Cisco ACI and another thing for campus switches. I would really appreciate it if Cisco came up with something centralized to monitor everything. I haven't thought about anything since the Cisco NDO is quite advanced, and you can deploy your cloud networking through it. I don't know how many people use it. I might explore it as my cloud orchestration tool in the future. We do a lot of cloud automation using our scripts like TerraForm, but I would like to see people using NDO more. We could have more case studies on how many people use NDO for their cloud orchestration. That might be a much easier journey for people when they move from an on-premises data center into a cloud and move from one cloud to another cloud. That is where I personally see an orchestrator being effectively used for multiple deployments.
Raj Metkar - PeerSpot reviewer
Discover internal application dependencies and create a dependency map
We actively seek improvements in integrating the Infoblox DDI platform with Cisco Secure Workload. This integration allows Cisco Secure Workload to learn about our networks and network tags, providing valuable insights into vulnerabilities related to the operating system and various applications installed on our servers. Recently, Cisco announced a new product called HyperShield, an AI-based autonomous micro-segmentation solution. While Cisco has not stated that HyperShield will replace Cisco Secure Workload, it represents a natural evolution for the company. HyperShield features dynamic policy discovery and enforcement; however, once policies are enforced, they do not change until a discovery occurs, requiring a re-enforcement process. This new platform operates autonomously, minimizing the need for user or security engineer intervention. I would have expected Cisco to incorporate more automatic discovery and enforcement features within the existing Cisco Secure Workload product. Instead of enhancing the current product, they have introduced a new solution. Cisco plans to honor existing Tetration licenses, allowing users to transition to HyperShield without additional costs, reflecting the investment enterprises have already made. From Cisco’s perspective, this represents a natural progression in their product line. While the product name changes, it seems more of a rebranding effort. The enhancements are greater autonomy, improved discovery, and automatic enforcement, which are now being introduced in HyperShield. Cisco Secure Workload offers automatic policy enforcement but cannot adjust policies dynamically as the application needs to change. Having used the platform for the past five years, the recent announcement has been reassuring. Cisco has confirmed that our investment in the platform will not go to waste. They will honor our existing licenses, providing a natural migration path to the new solution without any disruption

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cisco ACI can separate networks with a buoy interface. That is the most valuable feature."
"ACI's most valuable feature is its SDN capabilities. Everything is on your software design controller. Everything is blocked by default until you allow it."
"The security component is its most valuable feature."
"The most valuable features include microsegmentation, L3 Out features, and the common tenant and tenancy model."
"Having a lot of racks and switches with a single point of configuration which can be done with automation on one platform using one API. This makes everything work faster."
"We use Cisco ACI for perimeter security and threat detection."
"It has made it much easier to deploy and make changes in the data center versus the previous infrastructure, which was NX-OS based."
"The most valuable features of Cisco ACI are micro-segmentation, the VXLAN, and the ACI flattening services."
"The solution offers 100% telemetry coverage. The telemetry you collect is not sampled, it's not intermittent. It's complete. You see everything in it, including full visibility of all activities on your endpoints and in your network."
"Scalability is its most valuable feature."
"The only use case I can see that makes sense is micro-segmentation. I think there are other use cases for it. The main purpose of the product is to do micro-segmentation by collecting IP. That could be done by installing an agent, and then you have all the communication coming in and out. You could also use some flow sensors installed in the network that receive a copy of the traffic and then report that back to the system."
"The most valuable feature of this solution is security."
"Generally speaking, Cisco support is considered one of the best in the networking products and stack."
"The product provides multiple-device integration."
"Secure Workload's best feature is that it's an end-to-end offering from Cisco."
"The most valuable feature of the solution is that we don't have to do packet captures on the network."
 

Cons

"It would be great if ACI would include the next generation firewall feature."
"I think that technical support tickets should be escalated sooner."
"One of the things that makes it a lot more complicated is the way contracts are handled in ACI. Contracts are like their own access lists. They can improve the setting up of contracts between devices a lot. It can be simplified."
"The integration has room for improvement. There should be a drag-and-drop interface for configuring the integration where you connect some arrows to boxes, and the system takes care of the configuration. Right now, they have something similar, but it's limited. You have to take care of some things yourself. That is one area that the solution can work on. It's easy now, but it's much easier in other solutions."
"Training for this product is available from institutions but it is not available online where you can get users trained easily."
"The error messages should be improved. Sometimes we want to remove an error message so we acknowledge an error and we would then like to remove it but there's no real way of doing that. If we need to do it, we need to open a tech case. That could use improvement."
"An area for improvement in Cisco ACI is security, which Cisco needs to enhance in the solution. Though Cisco ACI uses a whitelist model, you must purchase an external product, such as a security firewall solution, to make whitelisting work, which the customer could find expensive. For example, you're a customer who has Cisco ACI, and the solution doesn't have IP-based filtering, so as a customer, you've purchased Cisco ACI. However, you still need to buy another product for security, and some customers wouldn't like that. However, some customers prefer to go with Cisco ACI because of its scalability and flexibility versus other solutions such as Juniper and Aruba. Technical support for Cisco ACI also needs improvement, particularly in product knowledge."
"More how-to videos and instructional information is required."
"It is highly scalable, but there is a limitation that it is only available on Cisco devices."
"It has an uninviting interface."
"The interface is really helpful for technical people, but it is not user-friendly."
"The product must be integrated with the cloud."
"Secure Workload is a little complicated to use, and the dashboard isn't intuitive, so it takes a while to learn how to use it."
"I'd like to see better documentation for advanced features. The documentation is fairly basic. I would also like to see better integration with other applications."
"There is some overlap between Cisco Tetration and AppDynamics and I need to have a single pane of glass, rather than have to jump between different tools."
"The multi-tenancy, redundancy, backup and restore functionalities, as well as the monitoring aspects of the solution, need improvement. The solution offers virtually no enterprise-grade possibility for monitoring."
 

Pricing and Cost Advice

"Yearly, we pay around one point two million for the solution."
"Price is always an issue."
"It saves time and resources."
"The product is not cheap."
"We have saved time on the provisioning and configuration."
"There are no additional costs. We only have to pay for a support contract apart from the license."
"The good thing about Cisco is that you can trade in your old products to replace them with ACI."
"The thing that I like the most from Cisco is the support and all the documentation that they have. We do have to pay for it though."
"The pricing is a bit higher than we anticipated."
"Regarding price, Cisco Secure Workload can be expensive if you don't have a budget. If you're not doing micro-segmentation, every extra security measure or enforcement you're putting on top of your existing environment will be an extra cost. It's not a cheap solution at all. But from my point of view, if you need to do micro-segmentation, this is one of the best tools I've seen for it. I can't compare that to Microsoft's solution because I haven't looked into it. I've looked into VMware and Cisco. Those are the only two that I know of. I didn't know that Microsoft could do micro-segmentation at all. Maybe they can, but I haven't heard anything about it."
"The price is based on how many computers you're going to install it on."
"It is not cheap and pricing may limit scalability."
"The price is outrageous. If you have money to throw at the product, then do it."
"Pricing depends on the scope of the application and the features. Larger installations save more."
"The cost for the hardware is around 300k."
report
Use our free recommendation engine to learn which Cloud and Data Center Security solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
23%
Financial Services Firm
13%
Government
7%
Manufacturing Company
7%
Computer Software Company
28%
Financial Services Firm
12%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Cisco ACI and VMware NSX?
There are some very major differences between both the Products and to name a few. -Cisco ACI have physical network gear (9K Switches) where the Code runs in ACI Policy Mode & the UCS server wh...
What are the biggest differences between Cisco ACI and VMware NSX?
Once you know your way around the Cisco ecosystem, using Cisco ACI is not so difficult. It is a global product, so when you change one interface, changes are automatically reflected on every switch...
What do you like most about Cisco ACI?
The flexibility of adding new components with minimal impact on existing services running in the data center is a key benefit of this ACI-based solution.
What do you like most about Cisco Secure Workload?
The product provides multiple-device integration.
What is your experience regarding pricing and costs for Cisco Secure Workload?
CloudStrike offers antivirus capabilities and firewall features for servers and VDI but lacks automatic policy discovery. This raises questions about the resources required to discover and write po...
What needs improvement with Cisco Secure Workload?
We actively seek improvements in integrating the Infoblox DDI platform with Cisco Secure Workload. This integration allows Cisco Secure Workload to learn about our networks and network tags, provid...
 

Also Known As

No data available
Cisco Tetration
 

Learn More

 

Overview

 

Sample Customers

Bowling Green State University, du, Qatar University
ADP, University of North Carolina Charlotte (UNCC)
Find out what your peers are saying about Cisco ACI vs. Cisco Secure Workload and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.