Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs Forescout Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 15, 2022
 

Categories and Ranking

Cisco Identity Services Eng...
Ranking in Network Access Control (NAC)
1st
Average Rating
8.2
Number of Reviews
139
Ranking in other categories
Cisco Security Portfolio (1st)
Forescout Platform
Ranking in Network Access Control (NAC)
4th
Average Rating
8.4
Number of Reviews
75
Ranking in other categories
IoT Security (1st), Endpoint Compliance (4th), Extended Detection and Response (XDR) (16th)
 

Mindshare comparison

As of September 2024, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 29.9%, down from 31.4% compared to the previous year. The mindshare of Forescout Platform is 13.6%, up from 12.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC)
 

Featured Reviews

Adam Boldin - PeerSpot reviewer
Jun 26, 2022
Helps us protect our SCADA systems by segmenting them from the rest of the network
The endpoint profiling feature is among the most valuable because it keeps me from having to manually maintain a MAC address bypass list to track endpoints. I can have ISE profile them for me and then put them in the right bucket. In addition, ISE really adopts and is strong in the Zero Trust model where we consider everybody a foreign endpoint until they prove they belong on the network. ISE just seems to be built from the ground up to do that, whereas with other solutions, you have to "shoehorn" that in. I also rate it pretty highly for securing access to our applications and network. If you have the good fortune of being a total Cisco shop, you can utilize SGTs, end to end, across the network. It can be a little tricky to get working, but once it does, it creates quite a consistent experience for any endpoint, even if it moves anywhere in the network.
Senthil_Kumar - PeerSpot reviewer
Feb 6, 2022
Helpful support, comprehensive, and simple configuration
Forescout Platform's most valuable features are that it is very granular. We are able to cull out a lot of information about our particular device or endpoint. The configuration and the visibility are very seamless. Overall the solution is very easy to handle and it's very comprehensive. We have visibility of all the hidden assets and there are various versions of implementations of an AV in our environment. From the Forescout Platform, we have clarity of the device, and all the different versions reported in a simple dashboard. The number of attacks has been minimal. After this installation, we didn't have any kind of noticeable incident.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Being able to authenticate wired users through 802.1X is valuable as it enhances our security."
"The most important feature for us is visibility in terms of user connections. It's the ability to see what devices are online for a particular user that helps a lot with our troubleshooting."
"SGTs are valuable because they make it easy to enforce policies, instead of pushing them across all the other platforms."
"The interface is pretty easy to use."
"TACACS and .1X security are the most valuable features. TACACS acts for user control, so no one can authenticate to our network devices, and .1X is to validate that unauthorized devices are plugged into our network."
"The solution is very reliable."
"Assisting a larger number of users in gaining access and guiding them through the process of getting on Cisco ISE has been seamless."
"Cisco ISE is a comprehensive solution that allows you to control access to network resources granularly based on policies."
"Obtaining visibility into the network and connected devices is very simple with this tool. It takes me three minutes to do a base deployment when all the parameters are available."
"Forescout has a feature that blocks the endpoint at the point of collection. It sets preconditions and will block the system if those aren't met."
"The most valuable feature is the blocking of USB devices."
"Being able to actively identify the client without a certificate allows you to control every device on your network regardless of the make, model, and software running. This allows for end-to-end security."
"The visibility is the main benefit. We now know how many devices are connected, what the use for each device is and what kind of devices we have in our environment."
"The most valuable feature of Forescout Platform is that it has everything that Aruba has at significantly less cost."
"The best parts of Forescout Platform are its orchestration features, discovery capabilities, classification buckets, and flexibility in creating policies."
"The actions that the agentless visibility, allow us to perform on the endpoint, are really amazing, especially in the way that it is done."
 

Cons

"There should be a single button that can be pressed to dismiss all of the alarms at once."
"I would like the product to include support for OSVS version three."
"One of the issues that we used to have was with profiling because we're working with a service provider that uses a lot of bring your own devices."
"The user interface could be more user-friendly."
"An area that could be improved is the agent. The challenge now is that agent and most of the computers have changed. They could think about agent-less deployment."
"Cisco ISE has almost all the features we are looking for now, but sometimes the configuration, such as the conditions, is a little difficult to understand and not so easy to navigate."
"Profiling is a really good feature. However, it sometimes is a challenge for customers when there are issues with the remediation part. I would add a built-in remediation solution. That would be a very nice feature."
"The admin interface is really slow. It's horrible."
"Better integration with third-party vendors is needed because as it is now, the list of third-party solutions that we can integrate and automate is quite limited."
"The reporting feature needs improvement."
"For improvements, I think technical support could be enhanced. The time zone difference makes remote support difficult - I'm in Indonesia, and they're in the US. Maybe the Forescout Platform could provide engineers from Asia Pacific."
"Custom integrations need to be better."
"When adding what is in scope to a policy, it would be nice if you could select multiple policies instead of one policy at a time to add what is in the scope for network segmentation. I have found that during the install and configuration of the policies that if you want to modify multiple policies or enable multiple policies that you need to define what is in the scope (IP range or segments) one rule at a time. This caused some slow downs when implementing policies."
"As a product, there is nothing to complain about. However, they should improve their overall support. You need that level of knowledge, that level of information is clearly not available. First and foremost, that information is not accessible. The second point to mention is that once you purchase the later support and services. That is, they will continue to charge you for every service."
"I should be able to integrate my Forescout with any other third party security technology, to build that connected security strategy."
"When we automate an email to send to a user, sometimes it gets blocked, but that has nothing to do with Forescout. It depends on the mail gateway that we use or integrate with."
 

Pricing and Cost Advice

"Being fully honest, the Cisco licensing model right now is really confusing. We don't know what licenses we have where. We have Smart licensing, but the different levels are way confusing."
"It is not that pricey."
"Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security wise or information wise, it really has been a powerful tool."
"The price can be lower, especially for subscriptions. It should be a lot cheaper to have a wide range of customers. The price should be comparable to competitive products like Forescout or Fortinet FortiNAC. Forescout is cheaper for customers looking for a cloud solution."
"The price is okay."
"For the Avast virus scan, we pay around USD $95 per machine for five years which includes all updates and technical support."
"The Essentials licensing is reasonable, but I would like the Premier version to be perpetual instead of a subscription."
"The solution is not that cheap."
"We need to pay for integration for each integration that we want to do and there is an additional license fee. This adds more costs. It is not something that anyone can afford. If you want to integrate this with a lot of other tools, it can be costly."
"The Forescout Platform's pricing is in the middle range, not too cheap or expensive."
"We went with the virtual appliance option. The biggest cost to running these types of appliances would be to either have multiple virtual appliances at every data center or running Remote SPAN hardware to provide you the real-time network visibility."
"You can have a flexible license depending on your environment."
"The price of the solution is reasonable. We have paid for the license for five years. We have integration with Symantec AV for orchestration, and we have an additional license."
"5,000 user licenses will cost you between seven and eight million dollars, compared to 20 million for Aruba."
"For one license, we pay around 3,000 Indian rupees."
"We have a very clear licensing model for business. I don't have to have a Ph.D. to be able to understand the licensing model as you might need for other solutions. If I know exactly what we want, it can tell you which license you need. The solution is easy for purchasing, ordering, and ease of deployment as well."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
801,394 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
16%
Government
8%
Financial Services Firm
7%
Educational Organization
30%
Computer Software Company
11%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What advice do you have for others considering Forescout Platform?
Forescout is a very powerful NAC product that does not rely on port level configuration. It can detect and block unauthorized devices very quickly. But it has a lot of capabilities and really would...
What advice do you have for others considering Forescout Platform?
I would rate the Forescout Device and Visibility Control Platform at a six out of ten.
What advice do you have for others considering Forescout Platform?
I recommend doing a compression demo. If people use it, they will buy it. So they have to see the product in place. That's the main recommendation is to do a proof of concept. If they do, they will...
 

Also Known As

Cisco ISE
Forescout Platform, CounterACT for Endpoint Compliance, ForeScout CounterACT
 

Learn More

 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
NHS Sussex, SAP, SEGA, Vistaprint, Miami Children's Hospital, Pioneer Investments, New York Law School, OmnicomGroup, Meritrust
Find out what your peers are saying about Cisco Identity Services Engine (ISE) vs. Forescout Platform and other solutions. Updated: September 2024.
801,394 professionals have used our research since 2012.