Forescout Platform and Cisco Identity Services Engine (ISE) compete in the network access control market. Forescout is preferable for non-802.1x environments and seamless third-party integrations, whereas Cisco ISE offers superior integration with other Cisco products and robust 802.1x features.
Features: Forescout Platform provides agentless visibility, non-802.1x solutions, and third-party system integration, making it adaptable for various infrastructures. Cisco ISE excels in 802.1x and TrustSec features, leveraging integration with other Cisco products for comprehensive network control and security.
Room for Improvement: Forescout could enhance detection capabilities for dual-homed devices and improve policy customization. Its graphical interface and error messaging also need refinement, along with reporting features. Cisco ISE would benefit from an improved upgrade process, user interface adjustments, and better policy management. Both platforms face integration challenges, though ISE's setup complexity is a notable concern.
Ease of Deployment and Customer Service: Forescout supports on-premises, public cloud, and hybrid cloud deployments, providing flexibility. Cisco ISE is mainly on-premises with hybrid and private cloud support. Customer service for both gets mixed reviews; Forescout's support is prompt but lacks depth, while Cisco's support is reliable yet complex.
Pricing and ROI: Forescout's cost is deemed high but competitive in large deployments; licensing is device count-based, affecting costs in multi-device scenarios. Cisco ISE also comes with a high price, featuring a complex transition from perpetual to subscription-based licenses. Both solutions are costly compared to alternatives, with ROI depending on deployment size and usage.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
I rate the technical support as one out of ten.
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
Scalability can be costly since a physical box needs to be installed for every site.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
I would rate its stability as 9.5 out of ten.
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
Additionally, the product is vulnerable and has many bugs.
The console is a fat client, and a web interface would be preferable.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Installing a physical box on each site can be expensive.
Cisco Identity Services Engine (ISE) is very good at device administration.
The solution is integrated with other Cisco devices and can offer automation for an organization, making deployments more dynamic and providing real-time visibility.
One of the most valuable features of Forescout Platform is its automation, particularly the ability to automate remediation of rogue devices on the network.
Cisco ISE is an all-in-one solution that streamlines security policy management and reduces operating costs. Cisco ISE delivers visibility and access control over users and devices across wired, wireless, and VPN connections.
Identity Services Engine enables enterprises to deliver secure network access to users and devices. It shares contextual data, such as threats and vulnerabilities, with integrated solutions from Cisco technology partners. You can see what is happening in your network, which applications are running, and more.
Features of Cisco ISE
Benefits of Cisco ISE
Cisco’s holistic approach to network access security has several advantages:
Support
You can get ISE as a physical or virtual appliance. Both deployments can create ISE clusters that create scale, redundancy, and requirements.
Licensing
Cisco ISE has four primary licences. Evaluation for up to 100 endpoints with full platform functionality. The higher tiers are Partner, Advantage and Essential.
Reviews from Real Users
"The user experience of the solution is great. It's a very transparent system. according to a PeerSpot user in Cyber Security at a manufacturing company.
Omar Z., Network & Security Engineer at an engineering company, feels that "The RADIUS Server holds the most value."
“Whether I deploy in China, the US, South Africa, or wherever, I can get all the capabilities. It allows me to directly integrate with 365, and from a communications point of view, that is a good capability," says Rammohan M., Senior Consultant at a tech services company.
Hassan A.,Technology Manager at Advanced Integrated Systems, says that "The most valuable feature is the integration with StealthWatch and DNA as one fabric."
Forescout Platform provides today’s busy enterprise organizations with policy and protocol management, workflow coordination, streamlining, and complete device and infrastructure visibility to improve overall network security. The solution also provides concise real-time intelligence of all devices and users on the network. Policy and protocols are delineated using gathered intelligence to facilitate the appropriate levels of remediation, compliance, network access, and all service operations. Forescout Platform is very flexible, integrates well with most of today’s leading network security products, and is a very cost-effective solution.
Forescout Platform Features
Real User Reviews
An important main feature of Forescout is the visibility the solution offers.
One reviewer who is a Consultant at a tech services company, says, "Within three or four days, you can have complete visibility of your infrastructure on the network. Compared to other solutions, the deployment of the solution is easier and we can close the project quickly."
Users also appreciate that the user interface is clear and easy to understand.
An Instructor at a tech services company, shares, "The most valuable feature of the Forescout Platform is the large capacity it can handle. Additionally, the interface of the platform is good."
We monitor all Network Access Control (NAC) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.