

Forescout Platform and Cisco Identity Services Engine (ISE) are key competitors in the network access control category. Forescout offers broader integration across diverse environments, while Cisco ISE provides tighter security within the Cisco ecosystem, benefiting from enhanced user authentication and policies.
Features: Forescout Platform excels in comprehensive endpoint visibility and flexible deployment without needing the 802.1x protocol. It integrates across various security solutions, facilitating control over network devices. Cisco ISE integrates seamlessly with the Cisco ecosystem, employing TrustSec and 802.1x for secure access control and centralized user authentication.
Room for Improvement: Forescout requires enhanced third-party integrations and scalability options. Users seek more intuitive reporting and interface enhancements. Cisco ISE could simplify deployment, reduce interface complexity, and clarify licensing.
Ease of Deployment and Customer Service: Forescout is known for its flexible deployment suitable for diverse environments but sometimes falls short in technical support responsiveness. Cisco ISE, though complex in setup, benefits from strong customer and technical support, leveraging Cisco's partner network.
Pricing and ROI: Forescout’s licensing is flexible yet expensive, based on device counts. Despite its cost, it is seen as valuable for strong security control. Cisco ISE is also costly but offers enterprise agreement discounts, making it feasible for larger enterprises.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
We also save money because we increased security, stopped incidents, and reduced breaches and security breaches.
I rate the technical support as one out of ten.
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
TAC support from Cisco is a notable feature; it provides very professional support.
We have had experience with their technical support and must pay additionally for maintenance, support, and regional service.
You can run an all-in-one deployment and switch to distributed mode as your company grows, relying on Cisco Identity Services Engine (ISE) to support your scalability needs.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
However, you can have some latency issues depending on where your devices are.
Scalability can be costly since a physical box needs to be installed for every site.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
I would rate its stability as 9.5 out of ten.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
It would help if during integration, an admin user could check the password or credential used, as they currently cannot see the password after it is entered and saved.
Forescout Platform could enhance its integration of AI to improve IoT and OT device security to better meet our needs.
The console is a fat client, and a web interface would be preferable.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
The license costs can range between $50,000 to $100,000 per year for enterprises.
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Installing a physical box on each site can be expensive.
The overall pricing of Forescout Platform is reasonable for the functionality it provides.
The price of Forescout Platform is reasonable and not overly costly.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
One of the most valuable features of Forescout Platform is its automation, particularly the ability to automate remediation of rogue devices on the network.
The most effective feature has been network access management, which has been crucial for our primary use cases in the organization.
When it comes to the effectiveness of Forescout Platform's real-time visibility in reducing the overall attack surface, I give it a 9 out of 10.
| Product | Market Share (%) |
|---|---|
| Cisco Identity Services Engine (ISE) | 22.4% |
| Forescout Platform | 10.8% |
| Other | 66.8% |

| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 32 |
| Large Enterprise | 91 |
| Company Size | Count |
|---|---|
| Small Business | 30 |
| Midsize Enterprise | 10 |
| Large Enterprise | 44 |
Cisco Identity Services Engine (ISE) offers comprehensive network access control and visibility, supporting features like 802.1X authentication, profiling, and posturing. It integrates with Microsoft and other Cisco products, facilitating robust security policies across distributed networks.
Cisco Identity Services Engine is a key player in network access control, offering centralized management and a user-friendly interface. It supports zero trust principles and provides strong authentication for wired and wireless networks. ISE's capabilities include granular security policies, enhanced device posturing, and seamless integration, bolstering security infrastructure. Users benefit from its dual authentication through EAP, simplifying access management across networks.
What are the key features of Cisco ISE?In industries like finance, healthcare, and education, Cisco ISE is pivotal for securing wired and wireless networks, implementing BYOD policies, and managing user access. Organizations leverage ISE for effective authentication and authorization, while maintaining compliance with industry security standards.
Forescout Platform provides today’s busy enterprise organizations with policy and protocol management, workflow coordination, streamlining, and complete device and infrastructure visibility to improve overall network security. The solution also provides concise real-time intelligence of all devices and users on the network. Policy and protocols are delineated using gathered intelligence to facilitate the appropriate levels of remediation, compliance, network access, and all service operations. Forescout Platform is very flexible, integrates well with most of today’s leading network security products, and is a very cost-effective solution.
Forescout Platform Features
Real User Reviews
An important main feature of Forescout is the visibility the solution offers.
One reviewer who is a Consultant at a tech services company, says, "Within three or four days, you can have complete visibility of your infrastructure on the network. Compared to other solutions, the deployment of the solution is easier and we can close the project quickly."
Users also appreciate that the user interface is clear and easy to understand.
An Instructor at a tech services company, shares, "The most valuable feature of the Forescout Platform is the large capacity it can handle. Additionally, the interface of the platform is good."
We monitor all Network Access Control (NAC) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.