Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs WSO2 Identity Server comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Identity Services Eng...
Average Rating
8.2
Number of Reviews
139
Ranking in other categories
Network Access Control (NAC) (1st), Cisco Security Portfolio (1st)
WSO2 Identity Server
Average Rating
8.2
Number of Reviews
10
Ranking in other categories
Customer Identity and Access Management (CIAM) (9th)
 

Mindshare comparison

Cisco Identity Services Engine (ISE) and WSO2 Identity Server aren’t in the same category and serve different purposes. Cisco Identity Services Engine (ISE) is designed for Network Access Control (NAC) and holds a mindshare of 29.2%, down 31.6% compared to last year.
WSO2 Identity Server, on the other hand, focuses on Customer Identity and Access Management (CIAM), holds 4.3% mindshare, down 4.5% since last year.
Network Access Control (NAC)
Customer Identity and Access Management (CIAM)
 

Featured Reviews

Rohit-Joshi - PeerSpot reviewer
Aug 3, 2023
Enables us to ensure that any machine that comes into the network is patched and secure
Posturing is the most valuable feature. There are other tools available that can do some of their other features, like network authentication. The posturing was something because of the nature of the industry that we are in. There are people who go outside for work. Their machines are at times not in the network, and not patched properly. We don't know when they're going to come back, whether it is in a good state, whether it has antivirus, whether it's installed on those machines. Posturing is something that we have made our baseline policy that whenever a machine comes back to our network, it should have a certain level of the operating system and a level of security and antivirus installed. We couldn't have done this posturing without Cisco ISE. This is its greatest feature. It does help me to detect and remediate my network. It enables me to detect any external threat that comes to my network and remediate. If a machine comes into my network that does not qualify per my baseline policy, I have a policy that the machine gets redirected to where it can be patched and remediated. I can ensure that it is fully patched and secure. The entire idea of having ISE is to enhance cybersecurity resilience. The zero trust architecture was coined by the cybersecurity team itself. It was a task given to us in the infrastructure space to see how we can bring resilience into the cybersecurity network and ISE was the solution.
Clement Hsieh - PeerSpot reviewer
Jun 11, 2024
Supports API integrations with different systems
My company uses multi-factor authentication and we tried using it integrating with FIDO Server. It was done to make sure that the multi-factor authentication feature gets used during the authentication process. AI can be used for better authentication, but right now, our company has not used any such feature. I recommend the product to others. It is easy to install and easy to use. Understanding a feature before you integrate a tool with other tools is important. In my company, there is another team with five to six engineers that takes care of the support part of the tool. The product has helped me to meet my security management requirements as per ISO 7001. I rate the tool a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The implementation is very simple."
"The solution enables us to authenticate with AD."
"Cisco ISE integrates with everything else."
"Having access and being able to add people or change authentication yourself is nice. In the past, we've used other group authentication services, and we always had to go to them and get permissions. Having that control is key."
"The core point is that Cisco ISE is the same globally compared to FortiAuthenticator. Whether I deploy in China, the US, South Africa, or wherever, I'm can get all the capabilities. It allows me to directly integrate with 365, and from a communications point of view, that is a good capability."
"The most valuable features are authentication, we have more granular control on the access policies for the administrators. The solution is easy to use, has a center point administration, and has a good GUI."
"It is a good product for what it does...So, it is one of the most critical systems that we have."
"The RADIUS Server holds the most value."
"It's very easy to implement everything."
"Some of the valuable features of the solution are the easy integration with processes, such as Single Sign-On. Overall WSO2 is straightforward and does not need customization."
"The product's initial setup phase is easy."
"I would rate the solution's stability eight or nine out of ten."
"The single sign-on procedure itself, as well as the ability to connect to external user sources such as Microsoft Active Directory and LDAP servers, are the solution's most valuable features."
"We use the solution for customer identity management, authenticating customers coming in through a web portal."
"The solution gets the job done, and we don't have to do the main configuration."
"Comprehensive ecosystem."
 

Cons

"Cisco ISE's real-time data analytics for database logging could be improved."
"The policies could be adjusted to make them more easily implementable."
"There are issues with respect to the posture assessment function. It's been observed that customers are not receiving total access to the network because the assessment agent is glitchy and malfunctions from time-to-time. I would like to see refining of the compliance assessment and adding more detailed compliance of endpoints on the user end."
"In the next release, I would want to see this kind of solution in the cloud as opposed to on prem because when enhancements are made to the software, if it's in the cloud, it's overnight. I mean you're not going to have to respin the servers that the license sits on, it's all microservices kinds of things in the cloud. That would be my recommendation. If I'm a customer, that's what I'm looking at - for cloud based software subscriptions."
"Cisco ISE could be simplified somewhat. I would also prefer certificate-based authentication over confirmation-based authentication for all the processes. It's possible for us to do a workaround, but the process needs to be simplified."
"We face many bugs."
"The area where things could be improved is education. It's complicated to deploy initially because you have to know what you're getting into."
"The interface could be more user-friendly and the ability to apply rules to MAC addresses, for example, if I wanted to allow a certain MAC address access at a particular time I cannot make this adjustment."
"This solution requires extensive knowledge to be used effectively as certain areas of its use are not user friendly."
"The solution's licensing model could be more flexible, and pricing could be improved."
"The solution seems to be pretty outdated."
"The high availability architecture has to be improved."
"This solution does not have BPM workflows already integrated, we had to integrate the BPM module externally. They do not provide full-featured auditing and certification modules out of the box."
"Sometimes working with the code is difficult because I search for documentation about the code and how to work with the code, which is where I believe they should improve, by providing some documentation on how to work with the code."
"There needs to be a good support model and easy-to-understand documentation."
"I found the initial setup to be very complex."
 

Pricing and Cost Advice

"Licensing has got much simpler since Cisco moved to the DNA model because we just have the three tiers, but it could always stand to be improved upon."
"Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security wise or information wise, it really has been a powerful tool."
"I have complaints. I don't enjoy the licensing model. Once we moved from 2.7 to 3.1, switching from Base, Plus, and Apex to Essential and Advantage in Premier, we went from a perpetual, with our base licenses, to now a subscription-base. So, we will have to renew those licenses every year, and I'm not a fan of that for our base licenses. Apex/Premier, we already expected, which is fine, but for basic connectivity, I am not a fan of that."
"I would rate the pricing an eight out of ten, one being cheap and ten being expensive."
"There are other cheaper options available."
"Its price is probably good if you use all of its features and functionalities to protect your environment. If you use only a part of the functionality, its price is too high. It is just a question of value and the functionality you use."
"I don't know too much about the actual pricing on it. The licensing part is pretty straightforward. It's a lot more simple than some of the other Cisco licensing models. In that aspect, it's great."
"Standard licensing gives backup access and very few features, and then there's VM licensing - each VM we use needs to be licensed."
"They should bring in some good pricing models to host the marketplace."
"I rate the product price an eight out of ten. There is a need to pay more for the extra features provided by the solution."
"I have found the solutions license is priced competitively compared to others."
"We have to take their support, but that is a minimal charge if I'm comparing it to other identity managers."
"At this time we are working with the open-source version."
"WSO2 Identity Server is not an expensive solution."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
26%
Computer Software Company
15%
Financial Services Firm
8%
Government
7%
Financial Services Firm
17%
Computer Software Company
13%
Government
8%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What do you like most about WSO2 Identity Server?
The product provides easy integration between API manager and IT server components.
What is your experience regarding pricing and costs for WSO2 Identity Server?
I rate the product price an eight out of ten. There is a need to pay more for the extra features provided by the solution.
What needs improvement with WSO2 Identity Server?
The solution's licensing model could be more flexible, and pricing could be improved.
 

Also Known As

Cisco ISE
No data available
 

Learn More

 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Nutanix, ELM, AlmavivA, BDigital, StubHub, M-creations, MedVision360
Find out what your peers are saying about Cisco, HPE Aruba Networking, Fortinet and others in Network Access Control (NAC). Updated: October 2024.
815,854 professionals have used our research since 2012.