Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Senior Security Engineer with 51-200 employees
Vendor
The NAC engine is flexible since it doesn’t need the use of 802.1x. We use the solution to test or troubleshoot customer configurations.

What is most valuable?

The main feature, the NAC engine, is very flexible since ForeScout CounterACT doesn’t need the use of 802.1x and can work with almost all switch vendors.

How has it helped my organization?

Since my company is a systems integrator, we have ForeScout CounterACT in our lab just to test or troubleshoot customer configurations.

What needs improvement?

There isn’t a specific area to improve. It’s a good product from my point of view. Maybe the licensing and cost can be improved.

What was my experience with deployment of the solution?

No issues with deployment.

Buyer's Guide
Forescout Platform
June 2025
Learn what your peers think about Forescout Platform. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.

What do I think about the stability of the solution?

Haven't had issues with stability.

What do I think about the scalability of the solution?

Haven't had to scale it.

What other advice do I have?

Maybe test the configuration very well before enabling actions (like VLAN moving, Captive Portal), because they can cause many problems in production environments if there are configuration mistakes.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user347157 - PeerSpot reviewer
Security Analyst at a retailer with 1,001-5,000 employees
Vendor
We're able to defend against unauthorized access to the network, thus distinguishing between corporate users and guests. But, detection and control of dual-homed devices needs improvement.

What is most valuable?

This product provided a really good effect in terms of network access control. With the ForeScout NAC, distinguishing guests and corporate staff was easier.

This was very easy to achieve since the product integrates really well with Active Directory and the NMAP feature discovers all endpoints within the network.

How has it helped my organization?

With the use of the NAC solution from ForeScout, the company was able to defend against unauthorized access to the network, thereby thoroughly distinguishing who is a Corporate user and who is a Guest. Process for Guest Registration (if implemented properly) was also easy.

What needs improvement?

Detection and control of Dual-Homed devices needs to be improved, as the product sometimes gives false positives. Also, more custom policies should be made available.

For how long have I used the solution?

I used this solution for 14 months.

What was my experience with deployment of the solution?

There were issues of false positives whenever a new hotfix was installed even with the GA release. There was actually an issue where an upgrade to a new version of the hotfix plugin increased the CPU optimization and network bandwidth usage.

What do I think about the scalability of the solution?

ForeScout is scalable since a management device is available to manage other CT boxes.

How are customer service and technical support?

Technical support from ForeScout is pretty good, with escalations made promptly when needed.

Which solution did I use previously and why did I switch?

No previous solution.

How was the initial setup?

The initial setup was straightforward, as the steps were simple to understand. It only got complex when creating policies that are not simple.

What about the implementation team?

I worked for a vendor team, and for any client ready to implement this product, I would recommend that the necessary requirements for deployment should be done before the team arrives to start implementation. This makes deployment less stressful.

Which other solutions did I evaluate?

No other options were evaluated.

What other advice do I have?

If you are looking for a NAC solution which works without the use of agents, I would say ForeScout is the one to go for.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Forescout Platform
June 2025
Learn what your peers think about Forescout Platform. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
it_user342609 - PeerSpot reviewer
Network and Security Engineer at a financial services firm with 1,001-5,000 employees
Vendor
It provides us with real-time visibility and control of devices accessing our network, although false positives should be reduced.

Valuable Features

  • Rogue detection and blocking
  • Guest registration
  • Full visibility of network hosts
  • Threat protection

Improvements to My Organization

We are provided with real-time visibility and control of devices accessing our network.

Room for Improvement

  • Reduce false positives
  • Reduce bugs
  • Improve on host classification
  • Increase the Nigerian partner base

Use of Solution

We've been using it for over two years.

Deployment Issues

No major issues.

Stability Issues

No major issues.

Scalability Issues

No major issues.

Customer Service and Technical Support

It's good, but certainly it needs improvement especially on the side of the partners.

Initial Setup

Initial setup was straightforward. All it required was to integrate traffic sniffing/monitoring and management ports into our core switch, and instruct the core switch to mirror every traffic to the device through the sniffing port. The rest was simply to define all our network segments on the device and integrate all access switches via SNMP.

Implementation Team

We implemented it through ForeScout's only Nigerian partner, and this is what I would advise everyone interested in the solution to do.

Pricing, Setup Cost and Licensing

It is quite expensive, but there are specs for small companies as well.

Other Solutions Considered

Cisco ISE was also evaluated, but the CT10000 was easier to implement and integrate into our environment.

Other Advice

You can go ahead, but you will need good network skills to get the maximum benefits from it.

I would also advise that you don't activate all the add-on features, but use it solely for its primary function - visibility and rogue detection/blocking.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user371547 - PeerSpot reviewer
it_user371547CEO at a consultancy with 51-200 employees
Real User

Thanks :).. your points are well noted and taken.. i know who you are but i wanna keep it anonymous and i wish you the best in your new place..

PeerSpot user
Network Access Control Security at a government with 10,001+ employees
Real User
Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP

What is most valuable?

Endpoint visibility, policy flexibility, compatibility and integration with other products.

How has it helped my organization?

Automation! One broad example is that we can now stop network threats right away and without intervention.

What needs improvement?

Forescout is constantly adding new features, so this may change as of this writing, but sometimes the switch management interface doesn't display accurate information which relates to false positives on individual switch access errors.

For how long have I used the solution?

1 year

What was my experience with deployment of the solution?

None that were Forescout related. CounterACT always opens a bunch of little IP sessions with endpoints, ake sure you have a large enough connection table on your firewall if you plan to put it behind one.

What do I think about the stability of the solution?

Minor. Had to reinstall one virtual appliance, which is painless when you have an Enterprise Manager.

What do I think about the scalability of the solution?

No, this is one of the products strengths.

How are customer service and technical support?

Customer Service:

10 out of 10. Very responsive and address concerns quickly.

Technical Support:

9 out of 10. Really fast response, high level of competency.

Which solution did I use previously and why did I switch?

I switched from Cisco NAC because it is reliant on 802.1X, and has no other function than to ensure endpoints have authenticated via your method of choice.

How was the initial setup?

Straightforward. Setup is simple with a solid, pre-defined set of policies that you build on and customize as you learn.

What about the implementation team?

In house.

What was our ROI?

Without access specific numbers, we now have the ability to instantly shut down internal malicious hosts or traffic, refuse or restrict access to non-compliant hosts, discover risks on the network we didn't know were there, and automate the remediation of a multitude of security risks. As I work for an organization that spends a lot on security administration, at a minimum, the cost savings must have already paid for the product.

Which other solutions did I evaluate?

Palo Alto

What other advice do I have?

Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP address. For example, a busy core switch can have 20+ IP addresses, and each one goes against your license count. Also, if you plan to have it behind a firewall, take into consideration your firewall's connection limitations. Although CounterACT isn't really a heavy bandwidth user, it does open a ton of short connections on a constant basis. The more you tune these down, the less accurate your real time host information becomes.

Disclosure: My company has a business relationship with this vendor other than being a customer. I currently work as a Solution Architect for ForeScout, but I wrote this review when I was a customer.
PeerSpot user
it_user203397 - PeerSpot reviewer
it_user203397Technical Support Manager at a financial services firm
Vendor

Technology improved network security via access layer L2.

MuhammadNadeem - PeerSpot reviewer
Sr. Network Engineer at a tech services company with 1-10 employees
Reseller
Top 10
Implements compliance on our client's systems and assists us in securing our servers
Pros and Cons
  • "The threat prevention feature provides complete visibility."
  • "The system controls could be better."

What is our primary use case?

We use this solution to implement compliance on our client's systems and prevent access from outside the organization.

What is most valuable?

The virtual firewall available on this solution is great and assists us in securing our servers. Additionally, the threat prevention feature provides complete visibility. It is very helpful in detecting, blocking and monitoring heavy scanning on the system.

What needs improvement?

The security features can be improved because we use it for sensitive information, such as compliance. Additionally, the system controls could be better.

For how long have I used the solution?

We have been using this solution for approximately one year.

What do I think about the stability of the solution?

The solution is stable and provides real-time monitoring for users, switches and other available features.

What do I think about the scalability of the solution?

The solution is scalable. We recommend it for all companies. It can be installed in enterprise, and we currently have it for over 4000 users.

How was the initial setup?

The initial setup was easy to integrate with the customer's environment. It doesn't have any downtime. I rate the setup process an eight out of ten.

What about the implementation team?

We implemented this solution through an in-house team.

What's my experience with pricing, setup cost, and licensing?

I don't have details on the licensing costs or pricing because it changes frequently, and a different department deals with it.

What other advice do I have?

I rate this solution an eight out of ten. The solution is good, but the systems control and security features could be better.

Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator Reseller
PeerSpot user
Buyer's Guide
Download our free Forescout Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Forescout Platform Report and get advice and tips from experienced pros sharing their opinions.