Try our new research platform with insights from 80,000+ expert users

Cisco DNA Center vs Cisco Identity Services Engine (ISE) comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco DNA Center
Average Rating
8.0
Number of Reviews
39
Ranking in other categories
Network Management Applications (1st), Network Monitoring Software (20th), Network Automation (2nd)
Cisco Identity Services Eng...
Average Rating
8.2
Number of Reviews
139
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
 

Mindshare comparison

Cisco DNA Center and Cisco Identity Services Engine (ISE) aren’t in the same category and serve different purposes. Cisco DNA Center is designed for Network Management Applications and holds a mindshare of 29.3%, up 26.5% compared to last year.
Cisco Identity Services Engine (ISE), on the other hand, focuses on Network Access Control (NAC), holds 29.9% mindshare, down 31.4% since last year.
Network Management Applications
Network Access Control (NAC)
 

Q&A Highlights

Aymen FHOULA - PeerSpot reviewer
Jul 07, 2023
 

Featured Reviews

Olajide Olusegun - PeerSpot reviewer
Aug 8, 2024
It gives good visibility on all network devices (switches, routers, waps, and so on) within a network infrastructure from a single page on the dashboard, and its reporting is fantastic
The best feature of Cisco DNA Center is the visibility page, which is unavailable in Cisco Prime. You can see everything on a single plane of glass on the dashboard, and you don't have to be a technical person to view different data and statistics. For example, you can see the issue alarms, errors, topology, and availability. So the tool gives you good visibility into all that's happening within your network infra. It also provides visibility into your computing environment. Application and performance analytics in huge detail is available in the DNA center. The reporting is fantastic in both Cisco Prime and Cisco DNA Center, so I rate that feature a nine out of ten. My company migrated clients to the Cisco DNA Center, and the reporting is incredible.
Junaid Shaikh - PeerSpot reviewer
May 3, 2024
Used in-house for phone profiling and for users' computer authentication needs
The initial setup is straightforward. They are very easy to manage and not complicated at all. We have received all our files from the client and deployed them. Currently, we are using single active nodes. We have one Primary Admin Node, which is active, and one Policy Service Node. We don't have a secondary admin node for administrative purposes. We have an active operational node. The deployment is pretty simple. You download the file from Cisco, import it into your Cisco ISE, and follow the prompts to set it up based on your requirements, including IPs, basic security needs, DNS servers, etc. Once the initial setup is complete, you can begin creating policies.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have many people from the team who manage a lot of devices. By using Cisco DNA Center, it has taken some of that burden away, we are impressed with it. We did the investment in CAPEX, but in the OPEX was very low."
"Has a good processing feature with a high level of accuracy."
"The product offers an intuitive and automated way to manage user networks. It gives me an insight into the network health."
"It offers automation, security enforcement, analytics, and integration with other Cisco technologies, making it a key driver for efficient network operations and compliance with security protocols."
"The most valuable features of the solution are all of its security features...It is a highly scalable solution."
"It is simple to manage and it is all done from a single dashboard."
"Application Assurance works very well."
"The best feature of Cisco DNA Center is the visibility page, where you can see everything on the dashboard, and you don't have to be a technical person to view the issues."
"The ability to integrate our Cisco AnyConnect connections to the active directory has been great."
"For me, the TACACS feature is the most valuable. I have also used Cisco ISE with LDAP, not with Active Directory. That works for me because I prefer LDAP versus Active Directory."
"The interconnection with the ecosystem and the ability to force rules all over the network are the most important features."
"Cisco ISE is a powerful solution. It gives us the ability to control who's accessing our network, and Cisco has made it very easy."
"The core point is that Cisco ISE is the same globally compared to FortiAuthenticator. Whether I deploy in China, the US, South Africa, or wherever, I'm can get all the capabilities. It allows me to directly integrate with 365, and from a communications point of view, that is a good capability."
"Technical support is okay."
"The most valuable features are the ability to retrieve information about Active Directory user names, viewing the log files to see which MAC address tried to connect with the created SSIDs, portal designing for your company, hotspot tools, and creating network rules for WiFi access."
"The integration with Active Directory is the most valuable feature for us."
 

Cons

"Integration with analytic tools and API integrations would be ideal."
"The solution can be quite pricey."
"I would like is to have a small information pointer available. It could be a plus feature that I want to implement. When I hover my mouse over the user interface, it should provide a brief explanation. It would be helpful to have it incorporated into the UI."
"The features of Cisco DNA Center and Cisco Prime could have more parity."
"When it comes to deploying wireless fields, integrating defaults into the DNS interface can be challenging."
"DNA Center has been on the market for a few years and they need to update it."
"What I want to see in Cisco DNA Center in the future is more support for other platforms so that you can manage third-party products, such as Fortinet."
"An area for improvement in Cisco DNA Center is the latency in data correlation. For example, sometimes, when an issue happens, and I check the logs, I can't find the corresponding log. There's a delay in log replication, so this is what needs improvement in Cisco DNA Center. Reporting in Cisco DNA Center could also be improved because it only has a few templates, and you can't customize it based on your requirements. There aren't many options available in Cisco DNA Center regarding reporting, versus Cisco Prime, which has excellent features for different levels of detailed reports. I'd like to see real-time data replication in the next release of Cisco DNA Center, similar to what's done in Meraki. Data in Meraki is real-time with no delay, so data is immediately replicated in the cloud. Currently, there's a lag in Cisco DNA Center, and addressing that lag is the enhancement I'd like to see in Cisco DNA Center. The solution also needs to be more user-friendly."
"Some of the reporting could be improved."
"On the network services devices, when you click on filter, the filter comes up. However, when I type in a search and I want to click on something it defaults back to the main page. I keep having an issue with that, and I'm not doing anything wrong."
"It could be more intuitive in terms of how to configure the policies."
"We do tend to run into a lot of issues with ISE when it comes to bugs."
"They should improve the documentation. There tends to be a lot of old text, or the new things aren't always up to what's been released on the code, and sometimes the documentation is inconsistent."
"There are still some bugs in ISE that need to be worked out."
"Cisco ISE could be simplified somewhat. I would also prefer certificate-based authentication over confirmation-based authentication for all the processes. It's possible for us to do a workaround, but the process needs to be simplified."
"In order to make it a ten, it should be more user-friendly. You need somebody who is knowledgeable about it to use it. It's not easy to use. We have to rely heavily on technical support."
 

Pricing and Cost Advice

"The price of the solution is expensive. The hardware is licensed on the device, but the hardware on the server is expensive."
"Cisco DNA Center is a licensed product with multiple levels of licensing available such as basic, advanced, and essential. I don't have the exact figure, but Cisco DNA Center is costly. For example, the box has information about the essential license and costs a considerable amount of money. You need to pay extra to use advanced features in Cisco DNA Center. My company sees Cisco DNA Center as a solution that's worth the money, which is why it invested in the solution. If you want centralized management for your network, especially when upgrading it, Cisco DNA Center is perfect, but it's more suitable for a large-scale rather than a small-scale network."
"The solution is a little bit expensive but depends a lot on the customer's usage. If you use it in the right place, you can easily pay for it."
"It is an expensive solution."
"The product is very costly."
"We get a yearly license at the time we buy the product."
"We have a three-year license with them."
"I do know that Cisco does offer some really good promotions for DNA Center to bring the costs down."
"Its price is probably good if you use all of its features and functionalities to protect your environment. If you use only a part of the functionality, its price is too high. It is just a question of value and the functionality you use."
"Licensing is a disaster. It's a mess and I hope they fix it soon."
"I think licensing costs roughly $2,000 a year. ISE is more expensive than Network Access Control."
"Cisco ISE is not inexpensive, but the solution is well-built and worth the expense."
"The price of Cisco ISE (Identity Services Engine) is expensive and we are thinking about changing to FortiGate."
"Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security wise or information wise, it really has been a powerful tool."
"For the Avast virus scan, we pay around USD $95 per machine for five years which includes all updates and technical support."
"Pricing is not a problem for Cisco because it has a lot of features and not much competition, although it's more expensive than other products. But if I do a cost-benefit analysis, Cisco provides high quality."
report
Use our free recommendation engine to learn which Network Management Applications solutions are best for your needs.
801,634 professionals have used our research since 2012.
 

Answers from the Community

Aymen FHOULA - PeerSpot reviewer
Jul 7, 2023
Jul 7, 2023
Prerequisite: 1) ISE and Cisco DNAC are compatible versions. 2) ISE GUI password matches ISE CLI password. 3) ISE and DNAC should have full privilege Credential. 4) Enable pxGride Service. 5) Enable ERS Read/Write service. 6) ISE and DNA Should be reachable.
See 2 answers
MOHAMEDELSHERIF - PeerSpot reviewer
Mar 9, 2023
Hi Anyman 1- first you need to enable pixgrid setting at CIsco ISE at Admin setting. 2- You Need to activate ISE as Radius in DNA Setting tab at the left corner (user name and password is any ISE administrator user ). 3- From Network Hierarchy Tab in DNA Cisco  choose ISE as your AAA server. 4- You need to create STG  group at policy tab to create the proper user grouping. 4-Then go to provision / fabric / switch interface then apply ISE as your authentication profile. Most Importantly you need to ensure that your fabric switch has DNA advantage license
VK
Jul 7, 2023
Prerequisite: 1) ISE and Cisco DNAC are compatible versions. 2) ISE GUI password matches ISE CLI password. 3) ISE and DNAC should have full privilege Credential. 4) Enable pxGride Service. 5) Enable ERS Read/Write service. 6) ISE and DNA Should be reachable.
 

Top Industries

By visitors reading reviews
Computer Software Company
21%
Government
10%
Manufacturing Company
9%
Healthcare Company
6%
Educational Organization
25%
Computer Software Company
16%
Government
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco DNA Center?
The most valuable feature of the solution stems from the fact that it gives some kind of ease in operations, especially since our company is moving from CLI to GUI-based configuration.
What is your experience regarding pricing and costs for Cisco DNA Center?
I would rate the pricing a six out of ten, with ten being expensive.
What needs improvement with Cisco DNA Center?
The solution's setup process needs enhancement.
Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
 

Also Known As

DNA Center
Cisco ISE
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Find out what your peers are saying about Cisco, Fortinet, HPE Aruba Networking and others in Network Management Applications. Updated: September 2024.
801,634 professionals have used our research since 2012.