Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs Portnox vs Varonis Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Access Control (NAC)
Network Access Control (NAC)
Data Loss Prevention (DLP)
 

Featured Reviews

SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.
Scott Kerr - PeerSpot reviewer
It is seamless and integrates well with our Azure setup
We use devices like PLCs and controllers, and when we receive a request to allow one on the network, we bypass typical authentication, associate it with a group account, and push it to a firewalled VLAN. However, problems arise when the same MAC address is requested for a different project. Our current system only finds authenticated MAC addresses, making it difficult to troubleshoot when the same device is used for multiple purposes. Ideally, we should be able to search for any MAC address in the database, regardless of its authentication status, to see all its associated groups and potential conflicts.
Frederic  Delos - PeerSpot reviewer
Offers the ability to identify sensitive areas, allowing you to drill down into the sensitive data
The most effective feature for me is its ability to identify sensitive areas, allowing you to drill down into the sensitive data, provided you have access, to determine whether it's a false positive or a true positive. That's the best thing for me, out of all of it. It's got everything, like other ones, but I like to be able to look at something if I'm doing forensics on the alert and say, "Okay, do I really need to do something with this?" For example, we don't want sensitive data in our OneDrive. So it identifies the sensitive data that's possibly in the OneDrive. And what I can do is look at it and identify whether it's actually sensitive data in Datalert or whether it looks like sensitive data, but I know it's a false positive. If it is a false positive, I can basically say ignore this pattern based on X, Y, and Z, you know, whether it's Redjax or keyword proximity. So I like that. With other tools, I gotta go through a whole process because it's a little bit more complex. Here, I can tag it and bag it in one shot. And the next good time I scan, it slips over it. So it helps in that.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Among the most valuable features is TACACS."
"It provides client provisions and profiling as well as guest access."
"The solution is integrated with other Cisco devices and can offer automation for an organization, making deployments more dynamic and providing real-time visibility."
"I love the policy sets, they are really nice and dynamic."
"It has allowed us to pull in multiple authentication databases, then centralize them into a captive portal system."
"I like the logging feature."
"It is a good product for what it does...So, it is one of the most critical systems that we have."
"It has all of the features available, in fact, more than what you need."
"The product's initial setup phase was straightforward."
"The cloud-based feature is very nice. We use Meraki for our switching, and it is simple to point all of our networks and offices to Portnox. It is pretty seamless."
"The minute people have issues on their network, we can see what is happening right away."
"The technical support is top-notch."
"Previous to the deployment we didn't have complete visibility of all the endpoints, all the devices that are connected to the network. But with the deployment of portnox, we could see all the devices and where they're connecting. We can equally segregate and apply different rules, policies to each location that we didn't monitor specifically."
"The cloud-based feature of Portnox is excellent."
"The simplicity of the product is commendable."
"The cloud-based feature is very nice."
"I also appreciate the reporting feature, which allows for the extraction of various reports based on specific needs. These reports can be used for audit purposes, such as tracking changes in file locations or deletions."
"The most important feature is remediation. In remediation support, there is no group permission. We'll go ahead and remediate the access from the Dell folder to the parent folder."
"There's also a 90-day policy where if a user is not using the warehouse, it will automatically delete that username."
"The solution has significantly improved data security and compliance posture by allowing us to track and monitor activities. We can see who accesses data and when files are created and understand what's happening in our environment."
"The solution ensures that users have not accidentally shared sensitive information with the wrong people or too many people."
"The telemetry to capture everything and the reports are very easy to configure without having a developer degree."
"It can easily identify unusual behavior or access patterns that may pose a potential threat, while operating as a unified reporting system."
"That alerting and reporting service is great."
 

Cons

"It would be ideal if Cisco could provide some short training videos or documentation to customers to help them understand how to use the product."
"One of the issues that we used to have was with profiling because we're working with a service provider that uses a lot of bring your own devices."
"The user interface could be more user-friendly."
"It is too complex. It should be easy to use. We are not such a big team. We only have three engineers to work with this, and we don't use all of the functionality of the product. Its range of functionality is too wide for us, and this is the reason why we are thinking of switching to a more simple product. We have shortlisted a Microsoft solution. We have a big footprint for Microsoft products, especially in security. As a global strategy, we try to leverage to the maximum what is possible around Microsoft."
"The templates could be better. When you have to do certs, especially with X.500 certs, it isn't very intuitive."
"It would be nice if it could be configured easily by default."
"There is room for improvement in its ability to allow end users to self-enroll their devices. Instead, you should be able to assign that permission by AD group, which is currently not available."
"I would definitely improve the deployment and maybe a little bit of the support. Our first exposure to ISE had a lot of issues."
"The integration between Portnox CORE and Portnox CLEAR can be better. These are two different systems, and there is no unique console for both devices. Portnox CORE is agentless, whereas Portnox CLEAR is not agentless."
"I believe there is a lot of room for improvement in terms of integration."
"The support team is very limited. They don't have much support during Asia Pacific hours; the team sits in during the EMI and US hours."
"We have been having some issues with it. That's why we're considering migrating to Portnox Clear due to some limitations with CORE."
"The product should consider more integration with vendors like Huawei. It should also improve visibility. The solution should offer a partner portal that can provide customers training on the in and out of the solution."
"From a resource perspective, the OEM can do better in terms of resource utilization."
"In terms of operational efficiency, things are more complicated now. It takes more time to get devices on the network, but we increased security quite a bit."
"The Wi-Fi integration could be done better from their end."
"It is significantly complex."
"The GUI should be more functional. There should be a process for connecting through Chrome, Internet Explorer, etc."
"I'd like to see automatic updates for this solution. Currently, it's a manual process to update all the keywords"
"There is one thing that if I add something manually, I get so many alerts. That's the biggest bad thing."
"The solution's interface is a little complicated with regard to setting up filters and reports."
"For unstructured data monitoring, it's one of the top ones, if not the top one, due to its usability."
"The solution's areas of improvement are the interface and the dependency on on-premises deployment for some components."
"The product is very complicated."
 

Pricing and Cost Advice

"Cisco has actually transitioned to a lot of subscription models, fees, and licenses."
"The technology is good, but to use some of the other features, and capabilities, they request that we purchase the Cisco DNA Center. As a result, the bundled price is a little high."
"I would rate the pricing an eight out of ten, one being cheap and ten being expensive."
"Cisco is moving towards a subscription service, which would mean additional costs."
"It's an expensive solution when compared to other vendors."
"If you consider money only, Cisco ISE is not a cheap solution."
"Previously, Cisco ISE had a perpetual licensing model, but now they have shifted to a subscription-based licensing system."
"Standard licensing gives backup access and very few features, and then there's VM licensing - each VM we use needs to be licensed."
"The tool is more expensive than Fortinet."
"It's not cheap. It's not expensive. It's in the middle."
"Pricing is quite reasonable."
"The solution is very expensive and I would rate it 10 out of 10."
"We pay for port licensing and support on a yearly basis, and it's not cheap."
"The pricing is a bit high, possibly due to the cloud features and running instances across regions like the US, Asia, and Europe."
"The licensing module should be reviewed to count the number of devices instead of port numbers of total switches. There is a case for this where not all ports for a switch are used by devices. Unused ports are calculated in the license, then the customer pays for license for those unused ports."
"Portnox CORE's pricing is adequate and cheaper compared to other complex solutions. Its licensing costs are yearly and include support. Cost is calculated per device."
"I would rate the pricing an eight out of ten, with ten being the most expensive."
"The platform is expensive. I rate the pricing a nine out of ten."
"It's expensive, kind of, really expensive."
"Licensing is on an annual basis. Maintenance and renewal fees are separate. Varonis Datalert is quite expensive."
"The pricing is good. It neither expensive nor cheap. It is average."
"Varonis Platform wasn't certainly the cheapest solution."
"You could do a subscription, where you pay yearly, or you could purchase it outright. The licensing cost is based on the number of users on the system that you are monitoring."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
859,438 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Educational Organization
15%
Financial Services Firm
9%
Government
8%
Manufacturing Company
15%
Computer Software Company
13%
Financial Services Firm
12%
Healthcare Company
7%
Financial Services Firm
16%
Computer Software Company
10%
Manufacturing Company
9%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cann...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if some...
What do you like most about Portnox CORE?
It's easy to manage and troubleshoot thanks to the lightweight components.
What is your experience regarding pricing and costs for Portnox CORE?
It's not cheap. It's not expensive. It's in the middle, so I'll probably give it a seven out of ten, where one is che...
What needs improvement with Portnox CORE?
We have been having some issues with it. That's why we're considering migrating to Portnox Clear due to some limitati...
What do you like most about Varonis Platform?
The solution has significantly improved data security and compliance posture by allowing us to track and monitor acti...
What needs improvement with Varonis Platform?
Varonis started as an on-premises solution and is transitioning to cloud. It hasn't fully moved yet, which is an area...
What is your primary use case for Varonis Platform?
The primary use case for Varonis Platform is data discovery, specifically for discovering sensitive data in our organ...
 

Also Known As

Cisco ISE
Access Layers Portnox, Portnox CLEAR
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Data Realty, Royal London, Wales Millennium Centre, McLaren Construction Group, EL AL Israeli Airlines, 
Nottingham Building Society
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Access Control (NAC). Updated: June 2025.
859,438 professionals have used our research since 2012.