Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Senior Network Engineer with 1,001-5,000 employees
Real User
Oct 20, 2016
It can handle Radius and TACACS+. It is quite complex when it comes to troubleshooting.

What is most valuable?

It can handle Radius and TACACS+.

How has it helped my organization?

Authorisation and Authentication Policy creation is easier. Access right limitation is pretty easy in ISE. Context exchange feature is present.

What needs improvement?

It is quite complex when it comes to troubleshooting.

For how long have I used the solution?

2 years

Buyer's Guide
Cisco Identity Services Engine (ISE)
December 2025
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.

What was my experience with deployment of the solution?

Upgrade was quite a pain. It doesn't exactly go according to the document.

What do I think about the stability of the solution?

On TACACS side, we see some issues. The rest is all going well.

How are customer service and support?

Customer Service:

It's good.

Technical Support:

Tech support is still lacking on TACACS troubleshooting on ISE.

Which solution did I use previously and why did I switch?

We were using ACS and IAS servers for radius and TACACS. ISE is one stop shop for everything with more to offer.

What about the implementation team?

Initially done with a Cisco consultant and started with Radius services. Expertise was excellent.

What's my experience with pricing, setup cost, and licensing?

Smartnet is not so cheap depending on the deployment.

What other advice do I have?

We have deployed this solution and we keep on exploring more and more. It can do wonders for authentication and limiting access with the network.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user375078 - PeerSpot reviewer
it_user375078Senior Network Engineer/Mobility Specialist at a tech services company with 51-200 employees
Top 20Real User

We may have borrowed ideas from other sources, but I do not think so. More based on years of experience with ACLs, firewall rule sets and working on the ISE flow and best practices. Also creating a flow chart of ISE flow is great. If you can create it prior to configuration it will guide you. And then create or adjust after implementation. Remember that if your flow chart is clumsy or difficult to organize chances are that your logic is also clumsy or even incorrect. With that said if you are new to ISE (and Dot1x, EAP and RADIUS) a poor flow chart may not reflect an incorrect implementation but a lack of understanding of the underlying principles. GOOD LUCK again!

See all 11 comments
PeerSpot user
Senior Network Engineer/Mobility Specialist at a tech services company with 51-200 employees
Real User
Top 20
Mar 15, 2016
Profile Sets help organize how AAA is handled by grouping, like traffic into separate subroutines.

What is most valuable?

Profile Sets help organize how AAA is handled by grouping, like traffic into separate subroutines.

How has it helped my organization?

We implement this for customers is various verticals. Most of the time oit is in Education. It really helps secure, classify and manage users including guest and BYOD users.

What needs improvement?

The product has improved with its evolution. The initial setup, though, is extremely complex.

For how long have I used the solution?

10 years. I have used this since it was Cisco ACS

What was my experience with deployment of the solution?

As the product matures I encounter less and less problems.

What do I think about the scalability of the solution?

The produt scales well.

How are customer service and technical support?

Excellent. TACis quite knowledgable.

Which solution did I use previously and why did I switch?

I have used Microsoft IAS/NPS, Funk, and Aruba ClearPass. ClearPass is the only product in the same league as Cisco ISE.

How was the initial setup?

ISE is extremely complex. With the functionality and flexibility it offers that is to be expected.

What about the implementation team?

I am the vendors's partner.

What's my experience with pricing, setup cost, and licensing?

Licensing and pricing is a complicated calculation, so it is best to really understand your customers' needs. Also team up with the right resources at Cisco for help.

Disclosure: My company has a business relationship with this vendor other than being a customer. We resell this product and the services associated with it. I have used several other RADIUS/security products from various vendors.
PeerSpot user
Buyer's Guide
Cisco Identity Services Engine (ISE)
December 2025
Learn what your peers think about Cisco Identity Services Engine (ISE). Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
PeerSpot user
Senior Network Operations Specialist at a government with 1,001-5,000 employees
Vendor
Feb 14, 2016
This technology is based upon utilizing other Cisco products such as IDS, IPS, ASA and Catalyst switches.

Valuable Features:

Cisco Identity Services Engine (ISE) version 1.3 has improved it's GUI margin and much easier to navigate than the previous versions. 

This technology pride itself with Trust Sec and 802.1x  feature. Trust Sec can be an advantage when an environment is nothing but a Cisco workshop.

This technology is based upon utilizing other Cisco products such as IDS, IPS, ASA and Catalyst switches. It provides the RADIUS feature for Active Directory so that 802.1x (EAP over LAN) is properly utilized for User Authentication.  

It also does MAC Address Bypass (MAB) for MAC Address verification and authentication.  

Cisco will integrate the TACACS+ feature into ISE version 2.0 and enterprises no longer need Cisco ACS for this reason.  

Improvements to My Organization:

Many organizations and large enterprises are faced with the daunting task of keeping their security issues at bay. They also need to be in compliant with the Cyber Security's strict guidelines and orders.  

While there are many cyber attacks from the outside of the edge routers, cyber attacks can also be implemented within the organization whether it is either intentional or unintentional.  Cisco ISE can mitigate many attacks such as MAC spoofing, VLAN hopping, DHCP Starvation and ARP Snooping.

By implementing ISE, it can lighten the overhead of the Cisco Catalyst Switches by not implementing port security, Dynamic Arp Inspection, DHCP Snooping. This will also improve the switch's performance since the ISE server takes over the duty of posturing with its Policy Service Node persona.  

Room for Improvement:

Cisco ISE has improved performances on Access Switches and closely monitored the daily suspicious or rogue activities within the organization.  

Deployment Issues:

We've had no issues with deployment.

Stability Issues:

We've had no issues with stability.

Scalability Issues:

We've been able to scale it for our needs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Senior Network Engineer with 1,001-5,000 employees
Real User
Sep 1, 2015
We use it for implementing wireless 802.1X with Active Directory and guest portal, but we're waiting for TACACS integration to completely replace the Cisco ACS line of products.

What is most valuable?

  • I'ts compatibility with 802.1X
  • Posture
  • Profiling
  • Guest Portal

How has it helped my organization?

As an integrator, I can tell that this product is mostly used for implementing wireless 802.1X with Active Directory and guest portals. It can be integrated with Active Directory and an external SMS gateway, can be used to track user authentications with Cisco WLC, can be therefore used to completely implement BYOD (considering the tight integration with leading MDM vendors). The product can be bought as a physical appliance as well a virtual appliance.

What needs improvement?

We are waiting for TACACS integration to completely replace the Cisco ACS line of products.

For how long have I used the solution?

I've used it for about four years.

What do I think about the stability of the solution?

Being a product relatively young the product seems incredibly stable and not prone to system outages.

What do I think about the scalability of the solution?

Having a Cisco consolidated experience with this type of products, the product encounters very little of no scalability problem.

How are customer service and technical support?

Cisco has implemented a special ATC partner program to help partners and customers to have a smooth deployment. As far as I know there is also a dedicated TAC area for this product, Cisco commitment on the ISE line of product is really at a top level. I can say this with an high degree of certainty being a Cisco Gold Partner.

Which solution did I use previously and why did I switch?

We use this product because we mainly sell this as a premier class NAC solution, compared to other similar products.

How was the initial setup?

The initial setup is very straightforwardly done by following the product’s document guides.

What about the implementation team?

I work for a vendor/system integrator.

What other advice do I have?

The main advice is to seek for an accredited ATC system integrator with a large ISE portfolio.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are a Gold Partner and an authorized ISE system integrator.
PeerSpot user
Joni Saputro - PeerSpot reviewer
System Engineer at a tech services company with 201-500 employees
Real User
Dec 4, 2023
A cost-effective and stable solution to secure the endpoints

What is our primary use case?

We use the solution to secure the endpoint. Before the user connects to the network, it can be investigated whether to connect.

What is most valuable?

Cisco ISE has a powerful posturing tool with security requirements. This data can be integrated with the device identity and threat intelligence surface, enabling you to create granular policies based on a device's identity. Just like we made policies based on Samsung or Lenovo, you can now do the same based on its compliance posture.

What needs improvement?

You have to restart the system to change the DNS or NTP server.

For how long have I used the solution?

I have been using Cisco ISE as a system integrator for three years.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

The solution’s scalability is good. We cater the solution to medium-sized businesses.

I rate the solution’s scalability an eight out of ten.

How was the initial setup?

The initial setup is easy. One engineer can deploy it in three hours.

What's my experience with pricing, setup cost, and licensing?

The product has moderate pricing and comes with a subscription model.

What other advice do I have?

We must check the compatibility with the other device before using Cisco ISE. Fortinet or Palo Alto provides integration to another device.

The solution has medium maintenance.

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Director of Security and Computer Risks at a comms service provider with 11-50 employees
Real User
Jun 20, 2022
A next-generation NAC solution that is easy to use
Pros and Cons
  • "Our clients like Cisco ISE because they already use various Cisco solutions. It's easy for them to use this solution because they have an engineer with Cisco certifications."
  • "The price could be better. I would like to see more integration with third-party solutions in the next release. This is because many of my clients don't have Cisco."

What is our primary use case?

Our clients use Cisco ISE for security, especially in the finance industry.

What is most valuable?

Our clients like Cisco ISE because they already use various Cisco solutions. It's easy for them to use this solution because they have an engineer with Cisco certifications.

What needs improvement?

The price could be better. I would like to see more integration with third-party solutions in the next release. This is because many of my clients don't have Cisco.

For how long have I used the solution?

We have been a partner dealing with Cisco ISE for about 14 years.

What do I think about the stability of the solution?

Cisco ISE is very stable.

What do I think about the scalability of the solution?

Scalability is good.

How are customer service and support?

I think Cisco has already improved its support for this solution.

On a scale from one to five, I would give technical support a five.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is easy. We have two engineers who implement this solution.

On a scale from one to five, I would give the initial setup a four.

What's my experience with pricing, setup cost, and licensing?

Cisco is expensive, but it's the cost for all the functions and value it brings. Functions like internet solutions, integrations, security, and many more features are important, but it's expensive for some clients.

What other advice do I have?

I would tell potential users that this is a good solution.

On a scale from one to ten, I would give  Cisco ISE a ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1454613 - PeerSpot reviewer
VP of IT at a tech services company with 51-200 employees
Real User
Jan 31, 2021
Good support, provides visibility of traffic, and is easy to use
Pros and Cons
  • "It is stable and easy to use."
  • "The user interface can be improved."

What is our primary use case?

We are a solution provider and we provide Cisco products, including ISE, to our customers.

This product is used to facilitate the connection of a local network to wireless access. This allows us to restrict users and their access.

What is most valuable?

This product allows them to see the traffic that is going through the network.

It is stable and easy to use.

What needs improvement?

The user interface can be improved.

For how long have I used the solution?

I have been using Cisco ISE for approximately three years.

What do I think about the stability of the solution?

Cisco ISE is stable.

What do I think about the scalability of the solution?

This is a scalable solution. There are more than 500 users in my client's organization.

How are customer service and technical support?

The technical support from Cisco is very good

How was the initial setup?

ISE is very easy to configure, although it takes time because we have to take input from the customer. It will take about two days to implement and deploy.

What about the implementation team?

We have a consultant to assist with deployment. A team of four engineers is required for deployment and maintenance.

What's my experience with pricing, setup cost, and licensing?

The price is okay.

What other advice do I have?

As of now, this product is working fine.

I would rate this solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
General Manager, Enterprise Solutions at a tech consulting company with 51-200 employees
Real User
Top 20
May 30, 2024
Helped improve our security and is reliable
Pros and Cons
  • "The solution is very reliable."
  • "Cisco ISE does not recognize devices and that is an issue we faced during its integration with our existing devices."

What is our primary use case?

The solution is being used for authentication purposes and for sharing assessments. 

How has it helped my organization?

Cisco ISE has helped improve our security. 

What is most valuable?

It helps ensure that you are working in accordance with the organizational policy before you join the network. Also, the solution is very reliable. 

What needs improvement?

I would like to see better management. Integration with other platforms can also be improved. 

Cisco ISE does not recognize devices and that is an issue we faced during its integration with our existing devices.

For how long have I used the solution?

I have been working with Cisco ISE (Identity Services Engine) for ten years. 

What do I think about the stability of the solution?

The stability of the solution is average. I would rate the stability of the solution a seven out of ten. 

What do I think about the scalability of the solution?

The solution's scalability is average. I would rate the scalability a seven out of ten. 

How was the initial setup?

The initial setup of Cisco ISE is complex. For the deployment, the solution needs to be installed and then it needs to be integrated with the network and certificates to get to the endpoints. 

What other advice do I have?

I would like to advice that Cisco ISE is a reliable and stable solution although it is not very easy to use. They should work on integrating the solution with other platforms.

Overall, I will rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free Cisco Identity Services Engine (ISE) Report and get advice and tips from experienced pros sharing their opinions.