Try our new research platform with insights from 80,000+ expert users

Cisco Identity Services Engine (ISE) vs Portnox vs Sophos Network Access Control comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of July 2025, in the Network Access Control (NAC) category, the mindshare of Cisco Identity Services Engine (ISE) is 25.1%, down from 30.7% compared to the previous year. The mindshare of Portnox is 3.9%, up from 2.1% compared to the previous year. The mindshare of Sophos Network Access Control is 1.7%, up from 1.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Access Control (NAC)
 

Featured Reviews

SunilkumarNaganuri - PeerSpot reviewer
Enhanced device administration hindered by complex deployment and security limitations
Cisco Identity Services Engine (ISE) needs to improve the profiling preauthentication. They are very poor in asset classification and should focus on improving the preauthentication profiling, especially for NAC use cases. This will give them a roadmap for software-defined access (SDA) use cases and network segmentation. Threat detection capabilities are very weak. Additionally, the product is vulnerable and has many bugs.
Scott Kerr - PeerSpot reviewer
It is seamless and integrates well with our Azure setup
We use devices like PLCs and controllers, and when we receive a request to allow one on the network, we bypass typical authentication, associate it with a group account, and push it to a firewalled VLAN. However, problems arise when the same MAC address is requested for a different project. Our current system only finds authenticated MAC addresses, making it difficult to troubleshoot when the same device is used for multiple purposes. Ideally, we should be able to search for any MAC address in the database, regardless of its authentication status, to see all its associated groups and potential conflicts.
Vishal Deshwal - PeerSpot reviewer
Technical support excels but hardware enhancements are needed for faster processing
The best features in Sophos Network Access Control are fewer than FortiNAC and Cisco ISE, but when discussing budget and customer support, different vendors have different perspectives. Cisco is better in support, FortiNAC is better in security, and different vendors maintain different perspectives. I utilized the device quarantine feature around eight months ago. It is specifically for when any malicious or harmful file comes to the system. Through NAC, we can put it in quarantine, and if anything comes or goes from this system, it will be monitored continuously. We can define these parameters as needed. The role-based access controls feature of Sophos Network Access Control allows persons at different positions in an organization to have different types of roles. We can give them full access as an administrator, provide some network access, or give users only read-only access. This depends on the user's requirements and the position they hold within the organization, allowing us to grant roles according to their post. The integration capabilities of Sophos Network Access Control are good, as it can easily integrate with other solutions and vendors.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For me, the TACACS feature is the most valuable. I have also used Cisco ISE with LDAP, not with Active Directory. That works for me because I prefer LDAP versus Active Directory."
"The best features are the scalability and the license structure."
"The posture assessment is a valuable feature because of the ability to do assessments on the clients before they connect to the network."
"The most valuable features are authentication, we have more granular control on the access policies for the administrators. The solution is easy to use, has a center point administration, and has a good GUI."
"At the moment, ISE seems to integrate very well with a number of other technologies."
"Cisco ISE now competes with any other product in the space because of its centralized and unified highly secure access control with ISE."
"The initial setup was easy. It took around one month. We did the installation part within half an hour to two hours but we found a couple of issues so we raised a case and once everything was resolved it was a month in total."
"The most valuable feature of Cisco ISE is its seamless integration with the switches and the entire suite, enabling wireless access and smooth client information retrieval."
"The technical support is top-notch."
"It's a stable product."
"I like the fact that you can take your device anywhere and still have that visibility from anywhere because it's agent-based."
"The Vidahost feature is currently in action, and it appears to be providing valuable data insights."
"Previous to the deployment we didn't have complete visibility of all the endpoints, all the devices that are connected to the network. But with the deployment of portnox, we could see all the devices and where they're connecting. We can equally segregate and apply different rules, policies to each location that we didn't monitor specifically."
"This is a self-sufficient network monitoring and security product that saves time and employee resources."
"Portnox helped to free up staff time and resources for other IT security priorities and IT work."
"The cloud-based feature is very nice. We use Meraki for our switching, and it is simple to point all of our networks and offices to Portnox. It is pretty seamless."
"The user interface makes it easy to configure and use."
"What Sophos has done is integrate almost the entire OSI layer infrastructure. It gives me visibility across my infrastructure. It gives me visibility into all the mobile devices that are on my network and into the security I have on those mobile devices."
"The most valuable features of Sophos Network Access Control are the quick response times to threats and reliable security."
"The solution offers very good visibility."
"The initial setup is very easy."
"There is really good visibility for the appliance."
"The pricing is very reasonable and you can negotiate on the price."
"The installation is very straightforward."
 

Cons

"Segmentation can be improved."
"Third-party integration is important, as well as the continuous adaptation feature which is the AIOps. It would be helpful to include the AIOps."
"The support could be faster and the pricing could be reduced."
"The product is expensive. It would also be a good add-on to have some machine learning."
"The initial setup was a little bit complex. It's not that simple because it requires a lot of prerequisites for the solution to get a hold on."
"If you have someone taking care of it, it can be quite easy to manage the solution. Otherwise, if you don't look after it and take care of it day-to-day, then it will become more complex to run."
"The user interface could be improved to make it more user-friendly."
"There should be a single button that can be pressed to dismiss all of the alarms at once."
"The Wi-Fi integration could be done better from their end. If there is an improvement, it should be around having more functions on the integration with the Wi-Fi controller I used, which was a UniFi controller, also on-prem."
"Allowing for a search of MAC addresses in the interface, whether they are authenticated on the network or not, would be beneficial. Currently, it only finds authenticated MAC addresses, which complicates troubleshooting when the same MAC address is used for different requests."
"We have been having some issues with it. That's why we're considering migrating to Portnox Clear due to some limitations with CORE."
"The integration between Portnox CORE and Portnox CLEAR can be better. These are two different systems, and there is no unique console for both devices. Portnox CORE is agentless, whereas Portnox CLEAR is not agentless."
"Their filtering system tends to lag quite a bit, so when I'm doing filtering at times, it doesn't filter the items properly."
"Now, the way security is viewed, maybe including something like AI, to automate some of the things that are required to be done would be great."
"In terms of operational efficiency, things are more complicated now. It takes more time to get devices on the network, but we increased security quite a bit."
"One of the things for the on-premise is that sometimes you click on it and it takes a while for it to respond."
"I would like to be able to fully customize the reports."
"The difficult thing was finding the metrics."
"One area in which the product could be improved is the user interface. While functional, it can be somewhat cluttered and unintuitive, especially for new users."
"It would be beneficial to consider some improvements regarding the dashboard."
"I would like more details on the incoming connection, like what is the download speed and how it fluctuates. If Sophos can give that information, it would be really good."
"The solution can improve the for applying policies. They can be complex depending don't the group they are applied to."
"What needs to be improved on is the fact that Sophos consumes a lot of processor resources and, once it starts scanning, the RAM utilization is very high."
"There is room for improvement in pricing."
 

Pricing and Cost Advice

"The pricing is good. The last time we purchased four new appliances the price was doable for any organization of our size."
"It costs around 50,000 baht in the first year, but I'm unsure about the second year."
"Being fully honest, the Cisco licensing model right now is really confusing. We don't know what licenses we have where. We have Smart licensing, but the different levels are way confusing."
"I think licensing costs roughly $2,000 a year. ISE is more expensive than Network Access Control."
"Cisco is expensive, but it's the cost for all the functions and value it brings. Functions like internet solutions, integrations, security, and many more features are important, but it's expensive for some clients."
"I don't know too much about the actual pricing on it. The licensing part is pretty straightforward. It's a lot more simple than some of the other Cisco licensing models. In that aspect, it's great."
"Cybersecurity resilience has been very important to our organization and has been a big factor. We've had issues in the past, but one of the things I like about ISE is its logging features. Security wise or information wise, it really has been a powerful tool."
"Over the years, licensing has been confusing and complicated because there are so many different licenses for each different product and each different iteration of the product."
"The users are not very happy with the new licensing option where there is only a subscription license. There is no perpetual license."
"The vendor price is fair."
"We pay for port licensing and support on a yearly basis, and it's not cheap."
"Pricing is quite reasonable."
"Pricing is not cheap. It is based on licenses per port. After licensing is purchased, you only pay for support."
"It's not cheap. It's not expensive. It's in the middle."
"The pricing is a bit high, possibly due to the cloud features and running instances across regions like the US, Asia, and Europe."
"The solution is very expensive and I would rate it 10 out of 10."
"It is quite expensive."
"I rate the price of Sophos Network Access Control a five out of ten."
"It provides a moderate pricing option for all of its features and benefits."
"Sophos Network Access Control is an expensive solution."
"Sophos Network Access Control is very cheap compared to other solutions like Cisco, Barracuda, and Palo Alto."
"Sophos Network Access Control is costly but has a similar price range as CrowdStrike and Check Point. The product can get more market share if Sophos can play around with Sophos Network Access Control pricing and improve it."
report
Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
862,077 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Educational Organization
10%
Financial Services Firm
10%
Government
9%
Manufacturing Company
15%
Financial Services Firm
12%
Computer Software Company
11%
Healthcare Company
7%
Computer Software Company
14%
Government
7%
Construction Company
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is better - Aruba Clearpass or Cisco ISE?
Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can...
What are the main differences between Cisco ISE and Forescout Platform?
OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cann...
How does Cisco ISE compare with Fortinet FortiNAC?
Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if some...
What do you like most about Portnox CORE?
It's easy to manage and troubleshoot thanks to the lightweight components.
What is your experience regarding pricing and costs for Portnox CORE?
It's not cheap. It's not expensive. It's in the middle, so I'll probably give it a seven out of ten, where one is che...
What needs improvement with Portnox CORE?
We have been having some issues with it. That's why we're considering migrating to Portnox Clear due to some limitati...
What do you like most about Sophos Network Access Control?
Sophos Network Access Control has a useful interface, and I like its dashboard, which is very useful for us to check ...
What is your experience regarding pricing and costs for Sophos Network Access Control?
I am not able to say much on the financial specifics as it pertains to the sales unit.
What needs improvement with Sophos Network Access Control?
Sophos Network Access Control could be improved by having an ASIC chip similar to FortiNAC, as this would provide bet...
 

Also Known As

Cisco ISE
Access Layers Portnox, Portnox CLEAR
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Aegean Motorway, BC Hydro, Beachbody, Bucks County Intermediate Unit , Cisco IT, Derby City Council, Global Banking Customer, Gobierno de Castilla-La Mancha, Houston Methodist, Linz AG, London Hydro, Ministry of Foreign Affairs, Molina Healthcare, MST Systems, New South Wales Rural Fire Service, Reykjavik University, Wildau University
Data Realty, Royal London, Wales Millennium Centre, McLaren Construction Group, EL AL Israeli Airlines, 
Rushmoor Borough Council
Find out what your peers are saying about Cisco, Hewlett Packard Enterprise, Fortinet and others in Network Access Control (NAC). Updated: June 2025.
862,077 professionals have used our research since 2012.