Try our new research platform with insights from 80,000+ expert users

Cisco DNA Center vs Cisco Identity Services Engine (ISE) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco DNA Center
Average Rating
8.0
Reviews Sentiment
6.3
Number of Reviews
41
Ranking in other categories
Network Management Applications (1st), Network Monitoring Software (13th), Network Automation (2nd)
Cisco Identity Services Eng...
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
142
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
 

Mindshare comparison

Cisco DNA Center and Cisco Identity Services Engine (ISE) aren’t in the same category and serve different purposes. Cisco DNA Center is designed for Network Management Applications and holds a mindshare of 27.4%, down 28.7% compared to last year.
Cisco Identity Services Engine (ISE), on the other hand, focuses on Network Access Control (NAC), holds 27.1% mindshare, down 31.6% since last year.
Network Management Applications
Network Access Control (NAC)
 

Q&A Highlights

Aymen FHOULA - PeerSpot reviewer
Jul 07, 2023
 

Featured Reviews

AvrahamSonenthal - PeerSpot reviewer
Efficiently manages our wireless network and provides valuable monitoring features
The platform's biggest benefit has been in managing our wireless network. Having a single pane of glass to control all wireless controllers and access points and to monitor activity has been a significant advantage. We're a small federal agency with around 300 network devices, so automation is a minor focus. It's more relevant for larger networks. The main benefits we've seen are in inventory management and the potential for configuration automation. However, I recommend using the DNA Centre only for larger networks with over a thousand devices; otherwise, it may not be cost-effective. Before proceeding, ensure that your devices are compatible with DNA Center, as not all Cisco devices are supported. Also, investing in proper training is different from plug-and-play. I rate it an eight.
SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Automation is another key highlight. With automation, you can automate everything through a single port."
"The monitoring features are very useful for network engineers."
"Cisco is a leading network company."
"I like that we can easily configure any new hardware. It's also easy to deploy and easy to troubleshoot."
"The automation features are significant, reducing configuration time. This means outstanding functionality. By deploying the controller automatically, the rest becomes automated"
"It enables monitoring of various components such as access points, switch cards, and other elements within the company's solutions."
"It does a lot of things automatically, and that's the big thing with it. They're making the software so that you don't need to be as knowledgeable as me on the switching and routing side to get your work done. If you want, you can have DNA troubleshoot your problem for you and give you solutions or fix it itself, if it was something that's just a configuration issue."
"People like to use the dashboards to get an overview of their network."
"I found the CMDB Direct Connect in Cisco ISE 3.2 the most promising feature for my use case."
"The most valuable features are authentication, we have more granular control on the access policies for the administrators. The solution is easy to use, has a center point administration, and has a good GUI."
"TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
"ISE's most valuable feature is integration between IT and OTs."
"It does a good job of establishing trust for each access request, no matter the source. It's also very effective at helping with the distributed network and at securing access."
"For my use cases, the in-depth troubleshooting into why a client can't connect or why they failed, is very valuable. I can go back to someone and say, 'Hey, it's not my network. It's their certificates or user error,' or something else."
"One of the advantages is that you can easily find rogue endpoints. For example, if you don't want to allow any endpoints where you don't know the people plugging into what kind of devices, ISE can give you a big, clear picture, e.g., what kind of endpoints are getting connected to your network. That is one of the advantages."
"It is stable and easy to use."
 

Cons

"Cisco DNA Center was a new technology for us, at the beginning, it was not easy to do, but Cisco did a lot of training with us to a level we could handle everything. The team is managing itself now without the assistance of Cisco."
"What could be improved is the licensing cost of Cisco DNA Center. It's a little bit expensive."
"The task failure reporting or provisioning failure reporting could be a little bit better in the UI, with more information given to the user."
"The tool's IoT integration should be better."
"The weaknesses primarily involve pricing and the ongoing need for increased bandwidth and data throughput."
"Integration with analytic tools and API integrations would be ideal."
"The solution can be quite pricey."
"DNA Center has been on the market for a few years and they need to update it."
"There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that."
"Cisco ISE is very complex and not very easy to deploy."
"The installation is not straightforward, it took us approximately one month."
"There are issues with respect to the posture assessment function. It's been observed that customers are not receiving total access to the network because the assessment agent is glitchy and malfunctions from time-to-time. I would like to see refining of the compliance assessment and adding more detailed compliance of endpoints on the user end."
"There are still some bugs in ISE that need to be worked out."
"The licensing scheme is complex and could use enhancement to provide more options."
"There should be an easier way to do the upgrades. There are a lot of steps to get to the next version from the previous version which ends up being a bit of the headache with the upgrade."
"The product is expensive. It would also be a good add-on to have some machine learning."
 

Pricing and Cost Advice

"The product is very costly."
"Affordability is a problem because it's created for large enterprises only. So, some customers, even if their engineers want the solution, might have problems with budget limitations."
"Our licensing agreement is for three years."
"The tool's licensing may not come across as something that may be friendly for users."
"I do know that Cisco does offer some really good promotions for DNA Center to bring the costs down."
"The price could be better. It's a very expensive tool."
"The tool is medium-priced."
"Licensing for Cisco DNA Center is a little bit expensive, just like any Cisco solution. Its cost could still be improved."
"Its price is probably good if you use all of its features and functionalities to protect your environment. If you use only a part of the functionality, its price is too high. It is just a question of value and the functionality you use."
"This solution requires an annual license and it is a bit expensive than competitors."
"I am not aware of the current price for Cisco ISE, but considering it is a Cisco product, it is likely to be quite high."
"Pricing is not a problem for Cisco because it has a lot of features and not much competition, although it's more expensive than other products. But if I do a cost-benefit analysis, Cisco provides high quality."
"In terms of the licensing and the pricing structure of the Cisco Identity Services Engine, there's been a huge advantage to our clients recently with the advent of the enterprise agreement."
"There are other cheaper options available."
"The recent changes in the licensing model have caused some issues with the team."
"According to my sales and account team, the prices we're getting are pretty good."
report
Use our free recommendation engine to learn which Network Management Applications solutions are best for your needs.
842,466 professionals have used our research since 2012.
 

Answers from the Community

Aymen FHOULA - PeerSpot reviewer
Jul 7, 2023
Jul 7, 2023
Prerequisite: 1) ISE and Cisco DNAC are compatible versions. 2) ISE GUI password matches ISE CLI password. 3) ISE and DNAC should have full privilege Credential. 4) Enable pxGride Service. 5) Enable ERS Read/Write service. 6) ISE and DNA Should be reachable.
See 2 answers
MOHAMEDELSHERIF - PeerSpot reviewer
Mar 9, 2023
Hi Anyman 1- first you need to enable pixgrid setting at CIsco ISE at Admin setting. 2- You Need to activate ISE as Radius in DNA Setting tab at the left corner (user name and password is any ISE administrator user ). 3- From Network Hierarchy Tab in DNA Cisco  choose ISE as your AAA server. 4- You need to create STG  group at policy tab to create the proper user grouping. 4-Then go to provision / fabric / switch interface then apply ISE as your authentication profile. Most Importantly you need to ensure that your fabric switch has DNA advantage license
VK
Jul 7, 2023
Prerequisite: 1) ISE and Cisco DNAC are compatible versions. 2) ISE GUI password matches ISE CLI password. 3) ISE and DNAC should have full privilege Credential. 4) Enable pxGride Service. 5) Enable ERS Read/Write service. 6) ISE and DNA Should be reachable.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Government
10%
Manufacturing Company
9%
Financial Services Firm
6%
Educational Organization
26%
Computer Software Company
14%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco DNA Center?
The most valuable feature of the solution stems from the fact that it gives some kind of ease in operations, especially since our company is moving from CLI to GUI-based configuration.
What needs improvement with Cisco DNA Center?
The system is working fine for me currently.
Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
 

Also Known As

DNA Center
Cisco ISE
 

Overview

 

Sample Customers

Information Not Available
Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Management Applications. Updated: March 2025.
842,466 professionals have used our research since 2012.