Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs Portnox vs Sophos Network Access Control comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of October 2025, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 24.2%, down from 29.5% compared to the previous year. The mindshare of Portnox is 4.7%, up from 2.2% compared to the previous year. The mindshare of Sophos Network Access Control is 1.8%, up from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC) Market Share Distribution
ProductMarket Share (%)
Cisco Identity Services Engine (ISE)24.2%
Portnox4.7%
Sophos Network Access Control1.8%
Other69.3%
Network Access Control (NAC)
 

Featured Reviews

SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.
Scott Kerr - PeerSpot reviewer
It is seamless and integrates well with our Azure setup
We use devices like PLCs and controllers, and when we receive a request to allow one on the network, we bypass typical authentication, associate it with a group account, and push it to a firewalled VLAN. However, problems arise when the same MAC address is requested for a different project. Our current system only finds authenticated MAC addresses, making it difficult to troubleshoot when the same device is used for multiple purposes. Ideally, we should be able to search for any MAC address in the database, regardless of its authentication status, to see all its associated groups and potential conflicts.
HirenPatel2 - PeerSpot reviewer
Have faced delays in support despite strong multi-layer policy configuration
I have observed some disadvantages as we have experienced one particular problem. We were facing an issue of synchronization of the endpoint with our firewall with help on a cloud for heartbeat syncing. However, it was not syncing as per our requirement. The user has to connect our firewall with the help of VPN. We were supposed to assume a solution on a cloud, which has good synchronization on a cloud with Sophos Central. It will sync with our firewall as well with the help of Sophos Central. Endpoint and firewall synchronization is not as smooth as we are expecting from Sophos Network Access Control. We have to connect with VPN. We are expecting that if we have already installed an endpoint on our system and it is connected to the internet, then it must be synchronized on a cloud with Sophos Central. Through Sophos Central, it must connect with our firewall. If the endpoint is configured on Sophos Central and the firewall is also configured in Sophos Central, then there should be no need to connect to VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With NAC, the profiling feature is valuable. We're able to see what we have out there in the network and dynamically assign policies to it. We can then use that to enforce TrustSec policy or anything else with NAC."
"[One of the most valuable features] is just the ease of use. It's pretty simple to set up certs that we can add to our clients to make sure that they connect properly, [as is] whitelisting Mac addresses."
"Cisco ISE's profiling and posturing features ensure that all devices are compliant with regulatory authorities."
"The biggest value of ISE is that it can get so granular with gaming systems, versus IoT and BYOD."
"Typically, the installation is pretty simple."
"The features that do work, work well, and we use it on a daily basis."
"It provides client provisions and profiling as well as guest access."
"For device administration, all devices have multifactor authentication in collaboration with IT, so it secures access to all of our devices. For guest and wireless access, it's a matter of a lowly manager who we give access to the portal and he can assign access to the guests, so it's a very simple process now. It keeps the IT focusing on their work, and gives the business people the right access."
"It's so easy to set up, you don't need outside assistance."
"The product is a valuable solution within zero-trust architecture, enhancing network security and visibility."
"The technical support is top-notch."
"The product's initial setup phase was straightforward."
"The minute people have issues on their network, we can see what is happening right away."
"With Portnox, you have a large-scale view of the systems on your estate, and you can use the ID of that user to search and get substantial information about a user."
"The simplicity of the product is commendable."
"It's easy to manage and troubleshoot thanks to the lightweight components."
"I found all Sophos Network Access Control features valuable, but IP blocking is the most useful."
"The pricing is very reasonable and you can negotiate on the price."
"The installation is very straightforward."
"The wifi control is fantastic and makes it very easy to administer."
"The user interface makes it easy to configure and use."
"The role-based access controls feature of Sophos Network Access Control allows persons at different positions in an organization to have different types of roles."
"The biggest advantage of Sophos Network Access Control is that it is very synchronized with the security on both the endpoint and the firewall on a single platform, and it is easy to maintain."
"I am very satisfied with this solution overall. All of the features that we use have been working successfully."
 

Cons

"There should be an easier way to do the upgrades. There are a lot of steps to get to the next version from the previous version which ends up being a bit of the headache with the upgrade."
"The licensing documentation needs to be better."
"I'm frustrated by the resource consumption and how many resources it needs to run. It takes a lot of RAM. It takes a lot of space and a lot of IO power. It's frustrating to do upgrades because it takes a long time."
"The installation is not straightforward, it took us approximately one month."
"With the recent release of the solution, we had a bunch of bugs and we had to delay our deployment. Other than that, the solution is good."
"The admin interface is really slow. It's horrible."
"I would definitely improve the deployment and maybe a little bit of the support. Our first exposure to ISE had a lot of issues."
"There should be more visibility into TrustSec policy actions. When TrustSec blocks something or makes any kind of changes to the network, we don't always see that. We have to log into the switch itself, or we have to get some type of Syslog parsing to do that."
"However, problems arise when the same MAC address is requested for a different project. Our current system only finds authenticated MAC addresses, making it difficult to troubleshoot when the same device is used for multiple purposes."
"From a resource perspective, the OEM can do better in terms of resource utilization."
"As there are no agents in Portnox Clear, the customers of the product cannot download any agents on their devices, making them unsure if the product offers proper security."
"The product should consider more integration with vendors like Huawei. It should also improve visibility. The solution should offer a partner portal that can provide customers training on the in and out of the solution."
"In terms of operational efficiency, things are more complicated now. It takes more time to get devices on the network, but we increased security quite a bit."
"Their filtering system tends to lag quite a bit, so when I'm doing filtering at times, it doesn't filter the items properly."
"Now, the way security is viewed, maybe including something like AI, to automate some of the things that are required to be done would be great."
"Allowing for a search of MAC addresses in the interface, whether they are authenticated on the network or not, would be beneficial. Currently, it only finds authenticated MAC addresses, which complicates troubleshooting when the same MAC address is used for different requests."
"It would be beneficial to consider some improvements regarding the dashboard."
"Continuous development in specific areas might be required."
"One area in which the product could be improved is the user interface. While functional, it can be somewhat cluttered and unintuitive, especially for new users."
"There is room for improvement in pricing."
"An area that could be improved is the information about licensing, which is fairly confusing at present."
"I would like to be able to fully customize the reports."
"I would like to see mobile administration capabilities in the next release so that we can administer the device from a mobile device."
"The solution could increase the integration with other platforms or other systems. This would be very useful."
 

Pricing and Cost Advice

"Cisco is expensive, but it's the cost for all the functions and value it brings. Functions like internet solutions, integrations, security, and many more features are important, but it's expensive for some clients."
"According to my sales and account team, the prices we're getting are pretty good."
"Pricing and licensing are not my expertise. As far as budgeting is concerned, we run an ELA with Cisco. It's a part of our ELA."
"Its licensing could be improved. It used to be perpetual, but now they are moving away from that."
"I believe I have paid around $1,000 in licensing fees. The license is annual."
"Cisco is moving towards a subscription service, which would mean additional costs."
"The price of Cisco ISE (Identity Services Engine) is expensive and we are thinking about changing to FortiGate."
"There are other cheaper options available."
"It's not cheap. It's not expensive. It's in the middle."
"The cost of Portnox Clear is reasonable."
"It is not bad. It is a bit on the high side, but considering the cloud features and how much it costs to run the instance in the cloud, it is not unreasonable. We do have RADIUS servers for the US, Asia, and Europe."
"Portnox CORE's pricing is adequate and cheaper compared to other complex solutions. Its licensing costs are yearly and include support. Cost is calculated per device."
"The tool is more expensive than Fortinet."
"Pricing is not cheap. It is based on licenses per port. After licensing is purchased, you only pay for support."
"The vendor price is fair."
"The users are not very happy with the new licensing option where there is only a subscription license. There is no perpetual license."
"Sophos Network Access Control is very cheap compared to other solutions like Cisco, Barracuda, and Palo Alto."
"It provides a moderate pricing option for all of its features and benefits."
"Sophos Network Access Control is costly but has a similar price range as CrowdStrike and Check Point. The product can get more market share if Sophos can play around with Sophos Network Access Control pricing and improve it."
"I rate the price of Sophos Network Access Control a five out of ten."
"Sophos Network Access Control is an expensive solution."
"It is quite expensive."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
869,513 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
9%
Manufacturing Company
9%
Government
9%
Manufacturing Company
16%
Financial Services Firm
11%
Computer Software Company
9%
Healthcare Company
8%
Computer Software Company
12%
Government
10%
Manufacturing Company
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise31
Large Enterprise91
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise7
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cann...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if some...
What do you like most about Portnox CORE?
It's easy to manage and troubleshoot thanks to the lightweight components.
What is your experience regarding pricing and costs for Portnox CORE?
It's not cheap. It's not expensive. It's in the middle, so I'll probably give it a seven out of ten, where one is che...
What needs improvement with Portnox CORE?
We have been having some issues with it. That's why we're considering migrating to Portnox Clear due to some limitati...
What do you like most about Sophos Network Access Control?
Sophos Network Access Control has a useful interface, and I like its dashboard, which is very useful for us to check ...
What is your experience regarding pricing and costs for Sophos Network Access Control?
I am not able to say much on the financial specifics as it pertains to the sales unit.
What needs improvement with Sophos Network Access Control?
A point for improvement for Sophos Network Access Control would be to implement a SIEM tool functionality. For exampl...
 

Also Known As

Cisco ISE
Access Layers Portnox, Portnox CLEAR
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Data Realty, Royal London, Wales Millennium Centre, McLaren Construction Group, EL AL Israeli Airlines, 
Rushmoor Borough Council
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Access Control (NAC). Updated: October 2025.
869,513 professionals have used our research since 2012.