Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs Sophos Network Access Control comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Ranking in Network Access Control (NAC)
2nd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Cisco Security Portfolio (4th)
Sophos Network Access Control
Ranking in Network Access Control (NAC)
7th
Average Rating
8.4
Reviews Sentiment
6.2
Number of Reviews
24
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 21.7%, down from 27.1% compared to the previous year. The mindshare of Sophos Network Access Control is 2.3%, up from 1.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)21.7%
Sophos Network Access Control2.3%
Other76.0%
Network Access Control (NAC)
 

Featured Reviews

NF
Network and Technology Information Manager at Akkodis
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
HirenPatel2 - PeerSpot reviewer
Manager at rspl
Have faced delays in support despite strong multi-layer policy configuration
I have observed some disadvantages as we have experienced one particular problem. We were facing an issue of synchronization of the endpoint with our firewall with help on a cloud for heartbeat syncing. However, it was not syncing as per our requirement. The user has to connect our firewall with the help of VPN. We were supposed to assume a solution on a cloud, which has good synchronization on a cloud with Sophos Central. It will sync with our firewall as well with the help of Sophos Central. Endpoint and firewall synchronization is not as smooth as we are expecting from Sophos Network Access Control. We have to connect with VPN. We are expecting that if we have already installed an endpoint on our system and it is connected to the internet, then it must be synchronized on a cloud with Sophos Central. Through Sophos Central, it must connect with our firewall. If the endpoint is configured on Sophos Central and the firewall is also configured in Sophos Central, then there should be no need to connect to VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For me, the TACACS feature is the most valuable. I have also used Cisco ISE with LDAP, not with Active Directory. That works for me because I prefer LDAP versus Active Directory."
"One of the advantages is that you can easily find rogue endpoints. For example, if you don't want to allow any endpoints where you don't know the people plugging into what kind of devices, ISE can give you a big, clear picture, e.g., what kind of endpoints are getting connected to your network. That is one of the advantages."
"The features that do work, work well, and we use it on a daily basis."
"Since migrating towards doing wired ports over ISE with 802.1X and MAB authentication, our organization's security risk has been better. We have been able to establish better layouts, so devices can move and we don't have to worry about where they need to go."
"I like the logging feature."
"The way the ISE works is you can get into defining. Let's say, in my case, I've got a Windows laptop and I've got an Apple product and those have unique identifiers, unique back addresses. It would say that this in my profile so I could get to those apps with either device, 24/seven. That's how granular the ISE or these NAC Solutions can get."
"The most valuable feature is the provisioning of the device so as to ensure that they are compliant with the security policy that we need to have."
"The most valuable feature is the ASDM - the user interface makes it very easy to configure the firewall."
"The biggest advantage of Sophos Network Access Control is that it is very synchronized with the security on both the endpoint and the firewall on a single platform, and it is easy to maintain."
"The initial setup is very easy."
"Sophos Network Access Control has many valuable features: for access controls, MAC binding is available, the authentication page is useful, and continuous device assessments have a positive impact on our network security management."
"The installation is very straightforward."
"The scalability of the system and the performance of the system and the solution's most valuable features."
"The platform's most valuable features include robust reporting and analytics capabilities, which provide deep insights into our sales performance and customer behavior."
"I found all Sophos Network Access Control features valuable, but IP blocking is the most useful."
"The most valuable features of Sophos Network Access Control are the quick response times to threats and reliable security."
 

Cons

"There should be a single button that can be pressed to dismiss all of the alarms at once."
"I would rate this solution a 7.5 out of ten. To make it a ten they should have more people on tech support. They need to invest more in the product. It's a good product. They should just work on tech support. More support for the customer. It's not that easy to get somebody to understand this product. I have had some issues with tech before for the solution. One of them brought the solution down due to some of his activity. They need to hugely invest in their tech support."
"Deploying to a machine, as opposed to a dedicated appliance, can be a bit difficult."
"The solution can lag somewhat as we have a large database."
"The licensing scheme is complex and could use enhancement to provide more options."
"The licensing scheme is complex and could use enhancement to provide more options."
"Compatibility and integration with other vendors is what needs to be improved in Cisco ISE (Identity Services Engine)."
"The UI is not as intuitive as some other products, even products inside of Cisco's wheelhouse."
"One area in which the product could be improved is the user interface. While functional, it can be somewhat cluttered and unintuitive, especially for new users."
"There is room for improvement in pricing."
"What needs to be improved on is the fact that Sophos consumes a lot of processor resources and, once it starts scanning, the RAM utilization is very high."
"Continuous development in specific areas might be required."
"Endpoint and firewall synchronization is not as smooth as we are expecting from Sophos Network Access Control."
"The solution could offer more useful documentation."
"I would like more details on the incoming connection, like what is the download speed and how it fluctuates. If Sophos can give that information, it would be really good."
"Sophos Network Access Control needs improvement regarding its slow interface, loading time, and reporting."
 

Pricing and Cost Advice

"The price of the solution is price fair for the features you receive."
"Cisco is moving towards a subscription service, which would mean additional costs."
"Licensing has got much simpler since Cisco moved to the DNA model because we just have the three tiers, but it could always stand to be improved upon."
"The price of Cisco ISE (Identity Services Engine) is expensive and we are thinking about changing to FortiGate."
"It is fair."
"Over the years, licensing has been confusing and complicated because there are so many different licenses for each different product and each different iteration of the product."
"There is a license to use this solution and the price is reasonable."
"Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security wise or information wise, it really has been a powerful tool."
"Sophos Network Access Control is costly but has a similar price range as CrowdStrike and Check Point. The product can get more market share if Sophos can play around with Sophos Network Access Control pricing and improve it."
"It provides a moderate pricing option for all of its features and benefits."
"I rate the price of Sophos Network Access Control a five out of ten."
"It is quite expensive."
"Sophos Network Access Control is an expensive solution."
"Sophos Network Access Control is very cheap compared to other solutions like Cisco, Barracuda, and Palo Alto."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
884,797 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
11%
Computer Software Company
9%
Financial Services Firm
9%
Government
8%
Manufacturing Company
8%
Government
8%
Computer Software Company
8%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What is your experience regarding pricing and costs for Sophos Network Access Control?
The pricing of Sophos Network Access Control is good, but it is somewhat high.
What needs improvement with Sophos Network Access Control?
In my opinion, one feature that should be added is the ability to trace emails from individuals who change their IP address or send misbehaving emails from alternative networks. If someone sends a ...
What is your primary use case for Sophos Network Access Control?
Sophos Network Access Control serves primary use cases for both networking purposes and security purposes.
 

Also Known As

Cisco ISE
No data available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Rushmoor Borough Council
Find out what your peers are saying about Cisco Identity Services Engine (ISE) vs. Sophos Network Access Control and other solutions. Updated: March 2026.
884,797 professionals have used our research since 2012.