


Find out what your peers are saying about Hewlett Packard Enterprise, Cisco, Fortinet and others in Network Access Control (NAC).
Using Aruba ClearPass has resulted in less engineering time compared to other products we've used.
The investment is huge for enterprise clients, but Aruba ClearPass makes processes easier.
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
We assess Forescout Platform's device inventory for helping track vulnerabilities and ensure patch compliance through penetration testing.
Portnox is one level up, as their customer support is outstanding.
We have faced delays in the resolution of production issues after raising tickets, which impacts productivity.
If Aruba ClearPass is not working, then the organization is not working because this is the access control in the organization.
I rate the technical support as one out of ten.
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
We have had experience with their technical support and must pay additionally for maintenance, support, and regional service.
I believe the scalability of ClearPass is rated as ten out of ten.
Everything will be handled when you add new users because all configurations are deployed from the beginning.
In our environment, ClearPass handles up to 100,000 users, which is better than some other NAC solutions like Fortinox that scale up to 25,000.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
However, you can have some latency issues depending on where your devices are.
Scalability can be costly since a physical box needs to be installed for every site.
I have experienced more than three years without zero downtime with Aruba ClearPass.
There are issues with some versions, especially in integrating with AD and SSL configurations over port sixty-three.
However, there are disadvantages when it is not on-premises, as every NAC suffers from it if it is not on-premises.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
I would rate its stability as 9.5 out of ten.
The language and policy enforcement mechanisms are not clear, making it difficult to use the product effectively.
It is also better to improve threat intelligence for built-in threat detection and prevention.
A more streamlined menu of licensing options would be helpful.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
It would help if during integration, an admin user could check the password or credential used, as they currently cannot see the password after it is entered and saved.
Forescout Platform could enhance its integration of AI to improve IoT and OT device security to better meet our needs.
Easier integration through APIs to automation platforms is something that would really help us when it comes to future requirements or future features that we're looking for from Forescout Platform.
Achieving the best price requires careful selection from a menu of licensing options.
We cannot mix in prices, and of course, prices are going higher.
Aruba ClearPass is a premium product with higher pricing, which seems unnecessary given its complexity.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
The license costs can range between $50,000 to $100,000 per year for enterprises.
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
Installing a physical box on each site can be expensive.
The overall pricing of Forescout Platform is reasonable for the functionality it provides.
The price of Forescout Platform is reasonable and not overly costly.
In Aruba ClearPass, you can have control of all authentication in the company.
The ClearPass solution has reduced the amount of engineering time compared to previous solutions, making it more efficient for our purposes.
The most effective feature for us is the OnGuard feature.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Automated threat response helps manage potential breaches very much, because that's something that is very critical, especially to overcome zero-day attacks.
One of the most valuable features of Forescout Platform is its automation, particularly the ability to automate remediation of rogue devices on the network.
The most effective feature has been network access management, which has been crucial for our primary use cases in the organization.
| Product | Mindshare (%) |
|---|---|
| Aruba ClearPass | 18.5% |
| Cisco Identity Services Engine (ISE) | 19.4% |
| Forescout Platform | 9.3% |
| Other | 52.8% |


| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 25 |
| Large Enterprise | 34 |
| Company Size | Count |
|---|---|
| Small Business | 45 |
| Midsize Enterprise | 32 |
| Large Enterprise | 91 |
| Company Size | Count |
|---|---|
| Small Business | 30 |
| Midsize Enterprise | 10 |
| Large Enterprise | 45 |
Aruba ClearPass provides robust authentication and policy enforcement with seamless integration capabilities, enhancing security for corporate networks. It handles guest access, BYOD management, and offers dynamic segmentation and extensive network visibility.
Aruba ClearPass supports diverse environments through integrated device profiling, enhancing network and user security. Its intuitive GUI simplifies management while dynamic segmentation offers tailored user experiences. Though highly functional, users seek improvements in interface intuitiveness and simplified configurations. Streamlined integration, better support, and clarity in licensing are also desired to enhance user experience. Deployed primarily for network access control and wireless management, Aruba ClearPass ensures secure corporate network access with identity authentication, policy enforcement, and detailed visibility.
What are the core features?In healthcare, Aruba ClearPass manages secure access for medical devices and personnel, ensuring compliance and confidentiality. Schools utilize it for managing student and guest network access, while enterprises integrate it for consistent security across corporate environments.
Cisco Identity Services Engine offers robust authentication, posture profiling, guest and secure access, and dynamic policy management. Known for its seamless integration with Cisco tools and network access control features, it ensures secure device and user authentication across networks.
Cisco Identity Services Engine is renowned for its capabilities in managing authentication, guest access, and policy management through segmentation. Its TrustSec functionality, alongside RADIUS and TACACS+ support, provides enhanced security, further augmented by its ability to operate in diverse environments. Its scalability and integration with Cisco solutions aid in maintaining network visibility and access control. Challenges include the complexity of initial deployments, somewhat cumbersome documentation, and limited integration in multi-vendor environments. While encountering issues in stability and updates, the demand for better analytics and straightforward troubleshooting alongside cost-effective licensing is notable.
What are the key features of Cisco Identity Services Engine?Industries implement Cisco Identity Services Engine primarily for network access control, ensuring secure authentication and segmentation in both wired and wireless environments. Supporting policies like bring-your-own-device and compliance standards, ISE manages identity-based access control, especially beneficial for entities that require detailed user rights management and integration within enterprise networks.
Forescout Platform provides comprehensive device visibility and asset management without requiring agent installation. It strengthens network access control and endpoint compliance, integrating flexibly with zero-trust architecture.
Forescout Platform offers organizations a robust solution for maintaining network security by enabling detailed monitoring of connected devices and enforcing compliance policies across IT and OT networks. Effective in sectors like finance, healthcare, and manufacturing, it controls unauthorized access, authenticates, quarantines, and remediates noncompliant devices while supporting both on-premises and cloud environments. Notable for its third-party integration, easy configuration, and customizable threat responses, Forescout Platform aids in efficient security measure maintenance.
What are the key features?Forescout Platform finds widespread adoption across industries like finance, healthcare, and manufacturing. It is particularly valued for enforcing cybersecurity measures and maintaining compliance in diverse operational environments, handling network access and device management challenges efficiently.