Try our new research platform with insights from 80,000+ expert users

F5 BIG-IP Access Policy Manager (APM) vs Forescout Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

F5 BIG-IP Access Policy Man...
Ranking in Network Access Control (NAC)
8th
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
14
Ranking in other categories
Secure Web Gateways (SWG) (19th), SSL VPN (5th), Remote Access (13th), Access Management (10th)
Forescout Platform
Ranking in Network Access Control (NAC)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
76
Ranking in other categories
IoT Security (1st), Endpoint Compliance (5th), Extended Detection and Response (XDR) (16th)
 

Mindshare comparison

As of January 2025, in the Network Access Control (NAC) category, the mindshare of F5 BIG-IP Access Policy Manager (APM) is 1.0%, down from 1.4% compared to the previous year. The mindshare of Forescout Platform is 13.6%, up from 12.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC)
 

Featured Reviews

Ashish Kumar Rai - PeerSpot reviewer
Offers remote access control, good GUI and easy to configure
I'd suggest improved documentation integration directly within the GUI. Right now, finding comprehensive documentation often requires going to external websites like the community portal. In the APM interface itself, they could add direct hyperlinks to relevant online documentation. This would provide easy access to admin guides and other resources when working within the GUI.
Odai Halawani - PeerSpot reviewer
It's an easy and effective solution, especially for device profiling without agents
Forescout Platform's most valuable aspect is its excellent device profiling for devices without agents, which is crucial for our work due to challenges with agent-based devices. Its isolation and blocking actions are particularly effective for network security. The device compliance feature helps us ensure device compliance through immediate actions like updating antivirus software. We have already integrated Forescout with antivirus and vulnerability assessment tools, allowing it to monitor vulnerability scores and automatically isolate devices if critical vulnerabilities are detected.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This is a product that is easy to install and integrate, and it is simple to use."
"The portal access was very good."
"The tool is reliable and easy to configure."
"We have seen a return on investment from F5 BIG-IP Access Policy Manager. It provided access at a time when we didn't have it."
"The product allows us to create customized portals for your users."
"The solution is stable and reliable."
"In my opinion, the GUI is perfect with the configuration options provided. F5 BIG-IP has given customization options and policy configuration tools in the GUI. It's good and good enough to work."
"Our customers have never complained about the stability"
"It allows for good detection of all the vendor products we have on-site."
"The initial setup is easy, taking no more than two or three weeks."
"The most valuable features are remote access and administration scripts."
"You can quickly filter your view of devices and zero in on the ones you want using a variety of tools, such as what subnet it is on or what it has been classified as."
"It's one of the tools that has given the federal government visibility into network devices and everything."
"This is clearly the best product for the NAC use cases in this field for Forescout."
"We really like that we get full visibility of devices in the local network."
"The platform enables automated policy enforcement, allowing us to simulate and test policies before enforcement, streamlining our security operations."
 

Cons

"F5 BIG-IP Access Policy Manager has room for improvement in integration with other products."
"We do not have knowledgeable support teams locally."
"The solution’s GUI looks very old."
"The price of this product can be improved."
"The solution is quite costly."
"F5 BIG-IP APM disconnects when you leave it for long enough, but that is natural for IT solutions to do. That's a little bit frustrating."
"Regarding price, I'm not directly involved in purchasing, but our CIO thinks the product is very expensive. He's considering moving from the tool to Citrix NetScaler WAF because it's cheaper, and we already have Citrix for VDI. We got NetScaler almost free as part of our VDI deal. Three years ago, I convinced him to use the solution because it's better, but now, with budget constraints, he may want to switch."
"Cloud services are something that F5 Access Policy Manager could do better"
"The licensing costs are quite high. With the amount of hardware we have, we need too many licenses to make the product effective and it's ultimately just too costly."
"The initial setup is a bit complex."
"Forescout Platform needs to improve how the device works in preventing rogue servers."
"The solution could always improve by adding more features to make it more robust."
"Forescout Platform would benefit from using AI. Everything has to be set up manually, but AI can learn and suggest rules over time. It also lacks visualization, and some interface configurations need improvement. The visualization seems a couple of years behind compared to other products."
"I should be able to integrate my Forescout with any other third party security technology, to build that connected security strategy."
"As a product, there is nothing to complain about. However, they should improve their overall support. You need that level of knowledge, that level of information is clearly not available. First and foremost, that information is not accessible. The second point to mention is that once you purchase the later support and services. That is, they will continue to charge you for every service."
"More detailed analysis during the authentication process, especially for troubleshooting access issues. We have found that troubleshooting RADIUS controls is quite arduous, as it is today. A trace function could easily resolve this by providing a means by which access issues from a certificate to passwords or accounts could easily be identified and remediated."
 

Pricing and Cost Advice

"Recently, they have simplified the licensing"
"The tool is a little bit expensive."
"I rate the tool's pricing an eight out of ten."
"The product is very expensive."
"They base the license on the number of devices, which is quite misleading."
"Time savings in finding rogue devices as well as identifying potentially unwanted devices on the network has saved the organization time and money."
"For one license, we pay around 3,000 Indian rupees."
"It's about $160,000, but I'm not sure how long that is for or what it includes. Because we were a test base, we were provided with servers, but now, Forescout wants us to buy servers because those servers are now end-of-life or end-of-service. For our lifecycle management program, in order to get a refresh on those servers, we would have to buy servers or use our own network resources to house Forescout. Forescout takes up about 13 or 14 virtual CPUs."
"The setup cost, pricing, and licensing are on the high side."
"The solution is not priced low. There are no hidden costs."
"It is expensive because you have to pay for their CSM, the customer's access manager, and their professional services on top of that, and they charge you roughly $400 per hour, which is overhead."
"I would rate Forescout Platform's pricing as four out of five."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
11%
Government
10%
Computer Software Company
10%
Educational Organization
33%
Computer Software Company
10%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about F5 BIG-IP Access Policy Manager (APM)?
In my opinion, the GUI is perfect with the configuration options provided. F5 BIG-IP has given customization options and policy configuration tools in the GUI. It's good and good enough to work.
What needs improvement with F5 BIG-IP Access Policy Manager (APM)?
Regarding price, I'm not directly involved in purchasing, but our CIO thinks the product is very expensive. He's considering moving from the tool to Citrix NetScaler WAF because it's cheaper, and w...
What advice do you have for others considering Forescout Platform?
Forescout is a very powerful NAC product that does not rely on port level configuration. It can detect and block unauthorized devices very quickly. But it has a lot of capabilities and really would...
What advice do you have for others considering Forescout Platform?
I would rate the Forescout Device and Visibility Control Platform at a six out of ten.
What advice do you have for others considering Forescout Platform?
I recommend doing a compression demo. If people use it, they will buy it. So they have to see the product in place. That's the main recommendation is to do a proof of concept. If they do, they will...
 

Also Known As

F5 Access Policy Manager
Forescout Platform, CounterACT for Endpoint Compliance, ForeScout CounterACT
 

Learn More

 

Overview

 

Sample Customers

City Bank, Ricacorp Properties, Miele, American Systems, Bangladesh Post Office
NHS Sussex, SAP, SEGA, Vistaprint, Miami Children's Hospital, Pioneer Investments, New York Law School, OmnicomGroup, Meritrust
Find out what your peers are saying about F5 BIG-IP Access Policy Manager (APM) vs. Forescout Platform and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.