No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Identity Services Engine (ISE) vs macmon Network Access Control comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Identity Services Eng...
Ranking in Network Access Control (NAC)
2nd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
144
Ranking in other categories
Cisco Security Portfolio (4th)
macmon Network Access Control
Ranking in Network Access Control (NAC)
13th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 18.4%, down from 24.5% compared to the previous year. The mindshare of macmon Network Access Control is 2.6%, down from 2.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC) Mindshare Distribution
ProductMindshare (%)
Cisco Identity Services Engine (ISE)18.4%
macmon Network Access Control2.6%
Other79.0%
Network Access Control (NAC)
 

Featured Reviews

NF
IT Network Manager at a tech services company with 10,001+ employees
Has improved authentication management and simplified visitor network access
The log capacity in Cisco Identity Services Engine (ISE) could be enhanced because today natively on the ISE can only have a look at the logs from the day before. You cannot search into the oldest logs; you have to use another tool for that. This can be blocking if you don't have any log consolidation solution. To do a search for an issue or something that happened two days ago, you cannot search directly in there. The capacity of Cisco Identity Services Engine (ISE) could be enhanced. Something between one week and one month for the log capacity would be nice.
SA
Wireless Network Engineer at Forvia
The product is stable and easily connects with clients, but it is not scalable and does not provide deeper troubleshooting
There is no information on the protocol where the clients stop to authenticate. There are some policies, but I don't know whether the device stopped on the authentication or authorization levels. I don't know whether it is getting the right certificate. I have to work on assumptions. If I want to go to the history to see what happened to a client the previous day or two days ago, it will be very hard because the server is used by multiple devices. For every device and user, macmon creates a file into the RADIUS appliance for deep troubleshooting. To troubleshoot, it creates a bunch of files. If I want to check what happened in the history, I have to check all the files. In some cases, there are 100 files. It is impossible for me to go to each file to see where it happens. It will be good to find the file my client authenticated based on the MAC address. Otherwise, the product must have one file for a specific date. I don't have any problem in terms of dates because it's normal. However, having hundreds of files per day is very hard to troubleshoot. The solution must allow users to filter files based on dates. It must provide deeper troubleshooting and reduced log. Also, the RADIUS logs are very huge.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"They have recently made a lot of improvements. My clients don't have much to complain about."
"It has all of the features available, in fact, more than what you need."
"Cisco Identity Services Engine (ISE) is very good at device administration."
"The most valuable feature is the visibility element, the ability for customers to be able to see what devices are actually on their network. Without a solution like ISE, they would have no idea what devices are connected to their network. It offers them the ability to authenticate devices via mobile."
"Before, our port would be wide open, anyone could come to the network and put their laptop into the port or any device and they would be able to get the IP; now, if someone tries to connect to our network through an IU port or internet, they will not be able to access it."
"It's easy to change and add policies."
"By implementing ISE, it can lighten the overhead of the Cisco Catalyst Switches by not implementing port security, Dynamic Arp Inspection, DHCP Snooping, and this will also improve the switch's performance since the ISE server takes over the duty of posturing with its Policy Service Node persona."
"When you push out the policy, it is able to populate the entire network at one time."
"When we started with macmon we had immediate success, we could see our network and see the devices and could easily go online."
"We use it with our Cisco switches so we can see which switch it is actually connected to."
"The ease of connecting with the client is valuable for me."
"The API is a great way to get information from other tools."
 

Cons

"Profiling is a really good feature. However, it sometimes is a challenge for customers when there are issues with the remediation part. I would add a built-in remediation solution. That would be a very nice feature."
"The user interface could be improved to make it more user-friendly."
"The user interface could be more user-friendly."
"It would be ideal if Cisco could provide some short training videos or documentation to customers to help them understand how to use the product."
"I would like the product to include support for OSVS version three."
"I would like to see them simplify the dashboard. It's very configurable, but, at the same time, it's not easy to maneuver through it. They should "Merakify" it."
"I don't like that the licensing structure doesn't allow us to have the 3.1 operating system — it forces us to use version 2.9."
"We are waiting for TACACS integration to completely replace the Cisco ACS line of products."
"The single sign-on process can be improved and the interface should be made more user-friendly."
"The solution must allow users to filter files based on dates."
"The service macmon offers is already great."
 

Pricing and Cost Advice

"Over the years, licensing has been confusing and complicated because there are so many different licenses for each different product and each different iteration of the product."
"There are three levels of pricing: basic, plus, and apex. Basic satisfied our needs."
"It's an expensive solution when compared to other vendors."
"If you consider money only, Cisco ISE is not a cheap solution."
"I think licensing costs roughly $2,000 a year. ISE is more expensive than Network Access Control."
"Licensing has got much simpler since Cisco moved to the DNA model because we just have the three tiers, but it could always stand to be improved upon."
"Previously, Cisco ISE had a perpetual licensing model, but now they have shifted to a subscription-based licensing system."
"It is fairly expensive and that's part of why we have implemented it in the type of 'hack' that we did, to service multiple clients."
"The solution is not expensive."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
10%
Outsourcing Company
9%
Comms Service Provider
7%
Manufacturing Company
17%
Comms Service Provider
12%
Outsourcing Company
10%
Computer Software Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise32
Large Enterprise91
No data available
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
Ask a question
Earn 20 points
 

Also Known As

Cisco ISE
macmon NAC
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
More than 1,500 installations in all over Europe in all industries: Stepchange, Volkswagen, Vivantes Healthcare, MBDA Weapons, APS engineering, Alfred Ritter GmbH (Ritter Sport), Haßberg-Kliniken, 1. FSV Mainz 05 eV., Siempelkamp, AEB etc.
Find out what your peers are saying about Cisco Identity Services Engine (ISE) vs. macmon Network Access Control and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.