We are provided with real-time visibility and control of devices accessing our network.
We've been using it for over two years.
It's good, but certainly it needs improvement especially on the side of the partners.
Initial setup was straightforward. All it required was to integrate traffic sniffing/monitoring and management ports into our core switch, and instruct the core switch to mirror every traffic to the device through the sniffing port. The rest was simply to define all our network segments on the device and integrate all access switches via SNMP.
We implemented it through ForeScout's only Nigerian partner, and this is what I would advise everyone interested in the solution to do.
It is quite expensive, but there are specs for small companies as well.
Cisco ISE was also evaluated, but the CT10000 was easier to implement and integrate into our environment.
You can go ahead, but you will need good network skills to get the maximum benefits from it.
I would also advise that you don't activate all the add-on features, but use it solely for its primary function - visibility and rogue detection/blocking.
Thanks :).. your points are well noted and taken.. i know who you are but i wanna keep it anonymous and i wish you the best in your new place..