

Find out what your peers are saying about Hewlett Packard Enterprise, Fortinet, Cisco and others in Network Access Control (NAC).
Direct comparisons with Forescout reveal up to 30% to 40% difference in cost savings.
On a B2B level, it opened up the market for TomTom to sell its services in a more efficient way to car companies.
We can use a Linux image from ForgeRock with different systems, applications, websites, and mobile apps to create various types of access for users.
I can definitely see that fewer employees are needed compared to using different SaaS applications.
I rate the technical support as one out of ten.
Cisco support has pretty good teams for support and every time we had good answers and we could somehow solve the issues we had.
Sometimes it's challenging to identify which support team is responsible for certain issues, which is a significant concern.
The support portals offer comprehensive documentation, troubleshooting guides, and community forums that have been helpful for resolving common issues independently.
For standard support tickets, response times were very decent, and the support team was helpful in identifying configuration issues, especially with authentication trees, token settings, and directory replications.
The team is very responsive and takes a sense of ownership and accountability.
Factors like architecture, business nature, and legal limitations such as GDPR affect it.
However, you can have some latency issues depending on where your devices are.
The access management layer is stateless, so I can scale horizontally by adding more nodes behind a load balancer as traffic increases.
The platform provides flexible authentication trees, enabling us to design custom MFA flows tailored for different user groups and risk profiles.
We scaled up with ForgeRock. My team received an award for implementing it for a 60 million customer base, which was the largest implementation at that time.
Cisco Identity Services Engine (ISE) is considered very reliable and stable.
The stability of Cisco Identity Services Engine (ISE) is poor for certain use cases, like authentication.
Sometimes when we have upgrades or failovers with Cisco Identity Services Engine (ISE), we had some minor issues.
ForgeRock supports integration with legacy systems in our organization by offering a wide range of connectors and APIs.
ForgeRock is very stable because it manages access, authentication, and authorization effectively.
The whole setup works well with Cisco access points and Cisco switches, but when you have multiple vendors in the environment, such as HP switches or access points like Aruba, you'll find they will not work well with Cisco Identity Services Engine (ISE).
Pricing can be more expensive compared to other vendors, and there is a significant price gap observed, which doesn't seem justified by some specific features.
They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases.
ForgeRock needs to focus on low-code, no-code solutions that allow for drag-and-drop functionality with good orchestration.
It would be better if they were available for support whenever the customer needs it, especially during migration or go-live time periods.
The main area is complexity. ForgeRock is extremely flexible, but the learning curve can be steep.
Compared to other solutions like HPE ClearPass, Cisco is more costly, and the conversation suggests a possible forty percent price gap compared to competitors.
The license costs can range between $50,000 to $100,000 per year for enterprises.
Cloud solutions are expensive, while on-prem setups with shared environments are cheaper but not effective.
One has to spend considerable time trying to understand the different modules and different needs for those modules on the licensing front.
Cisco Identity Services Engine (ISE) offers authentication using RADIUS, enhancing network security by separating and segregating networks.
There is value because it helps us secure the network and prevents certain things from happening which could cause financial loss.
The adaptability of Cisco Identity Services Engine (ISE) policy enforcement can fit to the site we have depending on which kind of devices we have on site and then the needs for authentication, granting access and then assigning each device into its correct network for segmentation.
Centralized management makes the biggest difference because it allows us to define, update, and enforce security and compliance rules from a single location.
ForgeRock positively impacts our organization as we manage a large number of users with ease, providing a standard IAM solution that simplifies our processes.
ForgeRock has positively impacted my organization by allowing us to migrate from the older system to the newer ForgeRock component, enabling us to go live with many products across geographies, enhancing security as it is all cloud-based, and with the company taking care of availability, it has reduced costs for the company.
| Product | Mindshare (%) |
|---|---|
| Cisco Identity Services Engine (ISE) | 18.6% |
| Aruba ClearPass | 18.0% |
| Fortinet FortiNAC | 13.7% |
| Other | 49.7% |
| Product | Mindshare (%) |
|---|---|
| ForgeRock | 4.2% |
| Microsoft Entra ID | 12.1% |
| Okta Platform | 11.1% |
| Other | 72.6% |
| Company Size | Count |
|---|---|
| Small Business | 45 |
| Midsize Enterprise | 32 |
| Large Enterprise | 91 |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 5 |
| Large Enterprise | 18 |
Cisco Identity Services Engine offers robust authentication, posture profiling, guest and secure access, and dynamic policy management. Known for its seamless integration with Cisco tools and network access control features, it ensures secure device and user authentication across networks.
Cisco Identity Services Engine is renowned for its capabilities in managing authentication, guest access, and policy management through segmentation. Its TrustSec functionality, alongside RADIUS and TACACS+ support, provides enhanced security, further augmented by its ability to operate in diverse environments. Its scalability and integration with Cisco solutions aid in maintaining network visibility and access control. Challenges include the complexity of initial deployments, somewhat cumbersome documentation, and limited integration in multi-vendor environments. While encountering issues in stability and updates, the demand for better analytics and straightforward troubleshooting alongside cost-effective licensing is notable.
What are the key features of Cisco Identity Services Engine?Industries implement Cisco Identity Services Engine primarily for network access control, ensuring secure authentication and segmentation in both wired and wireless environments. Supporting policies like bring-your-own-device and compliance standards, ISE manages identity-based access control, especially beneficial for entities that require detailed user rights management and integration within enterprise networks.
ForgeRock offers robust integration, customization, and identity management with support for SAML, OAuth 2.0, and DevOps readiness, ensuring enhanced security and scalability.
ForgeRock stands out in identity and access management featuring flexible authentication flows, risk-based authentication, centralized policy management, and comprehensive data protection. Its open-source foundation and cloud capabilities allow versatility and ease of use. While it provides excellent user path orchestration through the Journey feature, challenges exist in integration support and user-friendly customization. Improved documentation and streamlined interfaces are necessary to overcome deployment complexities. Additionally, the cost and support model may be burdensome for smaller organizations.
What are the key features?ForgeRock is widely utilized in industries like telecommunications, insurance, and open banking for secure user authentication and access management. It supports microservice authentications, customer identity management, single sign-on, and multi-factor authentication, integrating effectively with existing infrastructures to enhance security and user experience.
We monitor all Network Access Control (NAC) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.