Cisco ISE (Identity Services Engine) vs Cisco Secure Network Analytics comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco ISE (Identity Service...
Ranking in Cisco Security Portfolio
1st
Average Rating
8.2
Number of Reviews
139
Ranking in other categories
Network Access Control (NAC) (1st)
Cisco Secure Network Analytics
Ranking in Cisco Security Portfolio
3rd
Average Rating
8.2
Number of Reviews
58
Ranking in other categories
Network Monitoring Software (25th), Network Traffic Analysis (NTA) (3rd), Network Detection and Response (NDR) (6th)
 

Mindshare comparison

As of July 2024, in the Cisco Security Portfolio category, the mindshare of Cisco ISE (Identity Services Engine) is 22.4%, up from 16.3% compared to the previous year. The mindshare of Cisco Secure Network Analytics is 14.3%, up from 13.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cisco Security Portfolio
Unique Categories:
Network Access Control (NAC)
25.7%
Network Monitoring Software
1.5%
Network Traffic Analysis (NTA)
15.1%
 

Featured Reviews

Darren Hill - PeerSpot reviewer
Aug 3, 2023
Offers users the ability to be able to see what devices are actually on their network
I don't really know how to improve it, I think it's a great product. If I compare Cisco with something like ClearPass, for example, ISE is a lot more intuitive in terms of all the workflows and the work centers. They give you all the building blocks you need to be able to configure it. It's quite useful and quite easy to manage. If I was going to improve anything, it would be the ease of migration. It's really difficult at the moment if you're looking to upgrade ISE 2.1 and you want to go to ISE 3.1 or 3.2, that whole upgrade path and, particularly, the licensing is quite a minefield to sort out. If I wanted anything to be easier, it would be this.
Richard Payne - PeerSpot reviewer
Feb 13, 2023
Improved our organization greatly but greater customizability would be beneficial
The customizability of the UI should improve. With Splunk and other SIEM tools, you have the ability to create custom dashboards and manipulate the data in a way that works for you. Cisco gives you some creative ability, but you are very much locked into their train of thought. It would be helpful if they went more down the Splunk and Elastic route. We found flaws in Stealthwatch, but thankfully it has the ability to interconnect with Splunk and other such tools. This enabled us to plug the information over where it falls flat and then start working on other platforms. The solution falls down but tries to make up for it. I would also like to have greater insight into how it works under the hood. I appreciate that that might not be possible due to commercial confidentiality. However, having that greater insight would allow us to covey a level of trust to the people who use it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"At the moment, ISE seems to integrate very well with a number of other technologies."
"The solution enables us to authenticate with AD."
"There is good integration with third-party systems like antivirus patch management, MDM."
"A lot of customers use a third party to manage their guest Wi-Fi. Cisco ISE presents the ability to bring that in-house so that customers can have full control over it, change the branding, and get extra telemetry from it and the user data. It works really well for our customers."
"We have multiple metal devices from different places that use management, so we need to know who would be accessing all those devices and what changes are being done to those metal devices. With Cisco ISE we have visibility of all the changes happening on those devices."
"Cisco ISE now competes with any other product in the space because of its centralized and unified highly secure access control with ISE."
"Cisco ISE's integration with other external identity servers like Duende is very simple and easy."
"Our clients like Cisco ISE because they already use various Cisco solutions. It's easy for them to use this solution because they have an engineer with Cisco certifications."
"The most valuable part is that Stealthwatch is part of a portfolio of security devices from Cisco. Cisco literally can touch every single end point, every single ingress and egress point in the network. Nobody else has that."
"It works efficiently for encrypted traffic analysis."
"Most valuable features are the network maps and server and network response time."
"StealthWatch lets me see the ports running in and out and the country. It has excellent reporting, telemetry, and artificial intelligence features. With the telemetry, I can set thresholds to detect sudden changes and the alarms go through the PLC parts. I can see all the ports running on that trunk."
"The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
"There are already many functionalities, so I don't think there is anything to improve."
"The solution allowed us to not only get gain insight but also start collaborating with other tools."
"If you are using Darktrace or NAC solutions you can integrate Stealthwatch."
 

Cons

"Cisco ISE can become quite complex, especially with policy sets, the entire authentication process, and everything involved."
"The price here in Brazil is very expensive."
"I don't see as many customers as I should adopting the onboarding feature. I think Cisco should make that process a lot easier and less intrusive on the end users' devices."
"It could be more intuitive in terms of how to configure the policies."
"The intuitiveness of the user interface could be improved."
"They should improve the documentation. There tends to be a lot of old text, or the new things aren't always up to what's been released on the code, and sometimes the documentation is inconsistent."
"Troubleshooting and multi-ISE can be challenging with the solution."
"They could incorporate some AI features."
"The initial setup was complex."
"Complexity on integration is not so straightforward and you really need an expert to help build it out."
"Reliance on Java. Get away from that."
"It hasn't really improved our direct detection rate but it has definitely reduced our incident response time as we wouldn't have been able to detect threats or immediate risks without this solution."
"The reporting of day-to-day metrics still has room for improvement."
"We would like the solution to make more advances in the way that Extreme Networks has been doing."
"The overall visibility into the actual device itself would be helpful. I don't just want support-specific data, but also to be able to see information such as CPU and other internal components or usage of the devices."
"If they can make this product more web-based, that would be amazing."
 

Pricing and Cost Advice

"It has a fair price. It is better than it was before."
"The price for Cisco ISE itself is very low, however, Cisco professional services are quite expensive. Subscription amount is dependent on number of users."
"It costs around 50,000 baht in the first year, but I'm unsure about the second year."
"The recent changes in the licensing model have caused some issues with the team."
"The price can be lower, especially for subscriptions. It should be a lot cheaper to have a wide range of customers. The price should be comparable to competitive products like Forescout or Fortinet FortiNAC. Forescout is cheaper for customers looking for a cloud solution."
"The price for Cisco ISE is high."
"It is difficult to measure security breaches, but since we have not been attacked so far, it has paid for itself over the years."
"Pricing is not a problem for Cisco because it has a lot of features and not much competition, although it's more expensive than other products. But if I do a cost-benefit analysis, Cisco provides high quality."
"​Licensing is done by flows per second, not including outside (in traffic)."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"We pay for support costs on a yearly basis."
"Licensing is done by flows per second, not including outside>in traffic."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"NetFlow is very expensive."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
report
Use our free recommendation engine to learn which Cisco Security Portfolio solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
16%
Government
8%
Financial Services Firm
7%
Computer Software Company
30%
Financial Services Firm
11%
Government
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can adapt the policies to VPN access, wired, or wireless access. You can securely ...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, ...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone plugs in with a device that is not allowed and will block it. The user exper...
What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
I would rate Cisco SNA as a nine out of ten in terms of costliness.
What needs improvement with Cisco Stealthwatch?
One area that could be improved in SNA is the integration with Cisco ISE for user and session details, which currently requires additional setup.
 

Also Known As

Cisco ISE
Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
 

Learn More

Video not available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Find out what your peers are saying about Cisco ISE (Identity Services Engine) vs. Cisco Secure Network Analytics and other solutions. Updated: May 2024.
793,295 professionals have used our research since 2012.