The network access control is a valuable feature for us. It provides endpoint visibility of our network and controls who can access network resources. That's really powerful.
Network Security Manager at a tech services company with 501-1,000 employees
It provides endpoint visibility of our network and controls who can access network resources.
Pros and Cons
- "The network access control is a valuable feature for us, as it provides endpoint visibility of our network and controls who can access network resources, which is really powerful."
- "The integration with Sync can be improved. We would like to see better integration with some other popular vendors."
What is most valuable?
How has it helped my organization?
The problem with vendors like Cisco is that their solutions are limited their to own ecosystem, and in general they don't work well with other vendors. With virtual machines, it can actually collect data from a variety of different network solutions, such as Cisco, Bloomberg, etc. Any routing platform out there, you can import it today. It can basically integrate these products and you can use it for enforcement. You can use them to collect the data.
The other one is obviously that CounterACT can provide you with virtual ability to control who gets access to the network. It can act as a super-based machine and provide a level of security. It is integrated more easily than other vendors.
What needs improvement?
The integration with Sync can be improved. We would like to see better integration with some other popular vendors.
Also, the reporting needs improvement, as well as integration with PAL services. It also needs more options for different sizes of customers. It does really work well in the big departments. For smaller organizations it might be a little overkill of a solution.
What was my experience with deployment of the solution?
We've had no issues with deployment.
Buyer's Guide
Forescout Platform
May 2026
Learn what your peers think about Forescout Platform. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,942 professionals have used our research since 2012.
What do I think about the stability of the solution?
We've had no issues with stability.
What do I think about the scalability of the solution?
We've had no issues with scalability.
How was the initial setup?
It's a little bit too complex. A little bit of simplification when it comes to deployment might actually be better.
What other advice do I have?
I think it is a good product and definitely fills the gap. I don't think we have many competitors at this stage. The major competitor is Cisco, but the biggest advantage of CounterACT is vendor agnostic. It means that it can work with a variety of different products. That is the biggest advantage.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're partners.
Pre-Sales Engineer at a tech services company with 51-200 employees
For larger scale projects which includes multiple sites, CounterACT can be easily deployed in a centralized or decentralized manner. Its graphical user interface could use a revamp.
Pros and Cons
- "ForeScout CounterACT is like a Pandora's box, which contains a lot of functionalities that can be used to improve the customer's daily operation tasks and reduces manual workforce."
- "There are few issues with CounterACT that need more attention, mainly its ability to process and perform discovery faster."
Valuable Features
CounterACT is a very flexible product in terms of deployment where the users will have a Layer 2 or Layer 3 deployment depending on their network infrastructure while maintaining the product's features regardless of which deployment. For larger scale projects which includes multiple sites, CounterACT can be easily deployed in a centralized or decentralized manner. Besides that, deploying CounterACT introduces almost little-to-no network infrastructure changes.
Integration with third-party products is also an important feature of CounterACT. While many of their competitors' products can only be integrated within their own portfolio, CounterACT manages to integrate with today's top security products to cover the security gaps that many solutions may introduce. CounterACT also provides a ControlFabric platform which may allow the users to integrate all of their security and network solutions into CounterACT.
Improvements to My Organization
As a distributor's engineer working on CounterACT, there are a few vast changes that I have seen after deploying CounterACT for our customers. A few of our customers reportedly had an easier time with their auditors on endpoint compliance, where they would only need to generate and turn in CounterACT's report. This saves both the customer's and the auditor's time.
Another improvement that we can see is automated security, where the customers would not need to manually turn on and off the switch ports for their guests. CounterACT automatically recognizes these guest and provides a self-registration feature to their guest while still maintaining the customer's network security posture.
Room for Improvement
There are few areas which will need vast improvements. The CounterACT graphical user interface could use a revamp as it may not look appealing enough to the end users.
Another area which the CounterACT should improve is their ability to deliver a more precise error messages to their users. At times, the error messages are not clear enough and are too technical to understand. Some of their error messages are not generic, as they are only understandable by the ForeScout engineers.
Use of Solution
I've used it for three years.
Deployment Issues
There were no issues with deployment.
Stability Issues
There are few issues with CounterACT that need more attention, mainly it's ability to process and perform discovery faster. At times, CounterACT takes too long to determine the endpoints, which may cause delays to the end users.
CounterACT could also use a more stable management console interface. This is because there will be times where CounterACT takes too long to login to its management console.
Another issue with CounterACT is that it does not provide very meaningful error messages when some error occurs. The error messages are hidden and it does not show unless the users click on a specific button or mouse over to the problematic elements.
Scalability Issues
There have been no issues scaling it.
Customer Service and Technical Support
Customer Service:
The Customer Service is very responsive and helpful. They managed to resolve most of our issues with the products without much hassle.
Technical Support:The Technical Support is very responsive and helpful. They managed to resolve most of our issues with the products without much hassle.
Initial Setup
Initial setup is very straightforward because there are only a few network configurations needed to be done. It does not require any downtime and could be deployed at any time during production hour. There are a few endpoint configurations that need to be done, which users can do so through their Microsoft ActiveDirectory or desktop management tools or software.
Implementation Team
We implemented the solutions with our S.I. To ensure a smooth implementation, it is crucial to have all the endpoints and network requirements ready and configured before CounterACT is installed. It is recommended to start with the default policies and work on these policies to meet customers' requirements.
ROI
As we are an implementer, we do have an ROI for all our products.
Pricing, Setup Cost and Licensing
For pricing and licensing, CounterACT is not an overly expensive product. They can fit most of our customers' budgets.
Other Solutions Considered
We managed to evaluate Cisco ISE. Cisco ISE is a complex solutions to deploy where it only supports users who use Cisco switches.
ForeScout CounterACT is a much more appealing product because of the market here in Malaysia, where the users uses multiple brands of switches with complex network infrastructure. CounterACT could easily adapt to these environments without any changes made to the customer's network infrastructure.
Other Advice
ForeScout CounterACT is like a Pandora's box, which contains a lot of functionalities that can be used to improve the customer's daily operation tasks and reduces manual workforce. It is recommended that the implementer understand what CounterACT can be used to do as different customers' business functions could use different functions of CounterACT.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Forescout Platform
May 2026
Learn what your peers think about Forescout Platform. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,942 professionals have used our research since 2012.
Information Security Architect at a financial services firm with 1,001-5,000 employees
The most valuable features for us include antivirus compliance monitoring and guest management.
Pros and Cons
- "Customer service is above average and technical support is above average."
- "The patch management ability of the solution needs to be re-examined."
Valuable Features
- Guest management
- Antivirus compliance monitoring
- USB connection management
Improvements to My Organization
The bank has been able to manage host connection on the network, manage antivirus, and restrict the use of USB on the bank’s systems.
Room for Improvement
The patch management ability of the solution needs to be re-examined.
Use of Solution
We've used it for five years.
Deployment Issues
There have been no issues with the deployment.
Stability Issues
There have been no issues with the stability.
Scalability Issues
There have been no issues with scaling it.
Customer Service and Technical Support
Customer Service:
Customer service is above average.
Technical Support:Technical support is above average.
Initial Setup
It's straightforward to set up.
Implementation Team
We used a vendor team alongside an in-house one.
ROI
The ROI is commensurate with the price.
Pricing, Setup Cost and Licensing
The product is expensive.
Other Advice
To get the best out of the solution, the organization’s networks team must be willing to take ownership and provide assistance where required. Use tools like Gigamon during deployment and avoid spanning directly from Cisco switches.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Engineer with 51-200 employees
The NAC engine is flexible since it doesn’t need the use of 802.1x. We use the solution to test or troubleshoot customer configurations.
Pros and Cons
- "The main feature, the NAC engine, is very flexible since ForeScout CounterACT doesn’t need the use of 802.1x and can work with almost all switch vendors."
- "Maybe the licensing and cost can be improved."
Valuable Features:
The main feature, the NAC engine, is very flexible since ForeScout CounterACT doesn’t need the use of 802.1x and can work with almost all switch vendors.
Improvements to My Organization:
Since my company is a systems integrator, we have ForeScout CounterACT in our lab just to test or troubleshoot customer configurations.
Room for Improvement:
There isn’t a specific area to improve. It’s a good product from my point of view. Maybe the licensing and cost can be improved.
Deployment Issues:
No issues with deployment.
Stability Issues:
Haven't had issues with stability.
Scalability Issues:
Haven't had to scale it.
Other Advice:
Maybe test the configuration very well before enabling actions (like VLAN moving, Captive Portal), because they can cause many problems in production environments if there are configuration mistakes.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Analyst at a retailer with 1,001-5,000 employees
We're able to defend against unauthorized access to the network, thus distinguishing between corporate users and guests. But, detection and control of dual-homed devices needs improvement.
Pros and Cons
- "This product provided a really good effect in terms of network access control."
- "Detection and control of Dual-Homed devices needs to be improved, as the product sometimes gives false positives."
What is most valuable?
This product provided a really good effect in terms of network access control. With the ForeScout NAC, distinguishing guests and corporate staff was easier.
This was very easy to achieve since the product integrates really well with Active Directory and the NMAP feature discovers all endpoints within the network.
How has it helped my organization?
With the use of the NAC solution from ForeScout, the company was able to defend against unauthorized access to the network, thereby thoroughly distinguishing who is a Corporate user and who is a Guest. Process for Guest Registration (if implemented properly) was also easy.
What needs improvement?
Detection and control of Dual-Homed devices needs to be improved, as the product sometimes gives false positives. Also, more custom policies should be made available.
For how long have I used the solution?
I used this solution for 14 months.
What was my experience with deployment of the solution?
There were issues of false positives whenever a new hotfix was installed even with the GA release. There was actually an issue where an upgrade to a new version of the hotfix plugin increased the CPU optimization and network bandwidth usage.
What do I think about the scalability of the solution?
ForeScout is scalable since a management device is available to manage other CT boxes.
How are customer service and technical support?
Technical support from ForeScout is pretty good, with escalations made promptly when needed.
Which solution did I use previously and why did I switch?
No previous solution.
How was the initial setup?
The initial setup was straightforward, as the steps were simple to understand. It only got complex when creating policies that are not simple.
What about the implementation team?
I worked for a vendor team, and for any client ready to implement this product, I would recommend that the necessary requirements for deployment should be done before the team arrives to start implementation. This makes deployment less stressful.
Which other solutions did I evaluate?
No other options were evaluated.
What other advice do I have?
If you are looking for a NAC solution which works without the use of agents, I would say ForeScout is the one to go for.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security Engineer at a financial services firm with 1,001-5,000 employees
It provides us with real-time visibility and control of devices accessing our network, although false positives should be reduced.
Pros and Cons
- "We are provided with real-time visibility and control of devices accessing our network."
- "It is quite expensive, but there are specs for small companies as well."
Valuable Features
- Rogue detection and blocking
- Guest registration
- Full visibility of network hosts
- Threat protection
Improvements to My Organization
We are provided with real-time visibility and control of devices accessing our network.
Room for Improvement
- Reduce false positives
- Reduce bugs
- Improve on host classification
- Increase the Nigerian partner base
Use of Solution
We've been using it for over two years.
Deployment Issues
No major issues.
Stability Issues
No major issues.
Scalability Issues
No major issues.
Customer Service and Technical Support
It's good, but certainly it needs improvement especially on the side of the partners.
Initial Setup
Initial setup was straightforward. All it required was to integrate traffic sniffing/monitoring and management ports into our core switch, and instruct the core switch to mirror every traffic to the device through the sniffing port. The rest was simply to define all our network segments on the device and integrate all access switches via SNMP.
Implementation Team
We implemented it through ForeScout's only Nigerian partner, and this is what I would advise everyone interested in the solution to do.
Pricing, Setup Cost and Licensing
It is quite expensive, but there are specs for small companies as well.
Other Solutions Considered
Cisco ISE was also evaluated, but the CT10000 was easier to implement and integrate into our environment.
Other Advice
You can go ahead, but you will need good network skills to get the maximum benefits from it.
I would also advise that you don't activate all the add-on features, but use it solely for its primary function - visibility and rogue detection/blocking.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Access Control Security at a government with 10,001+ employees
Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP
Pros and Cons
- "Without access specific numbers, we now have the ability to instantly shut down internal malicious hosts or traffic, refuse or restrict access to non-compliant hosts, discover risks on the network we didn't know were there, and automate the remediation of a multitude of security risks."
- "Sometimes the switch management interface doesn't display accurate information which relates to false positives on individual switch access errors."
What is most valuable?
Endpoint visibility, policy flexibility, compatibility and integration with other products.
How has it helped my organization?
Automation! One broad example is that we can now stop network threats right away and without intervention.
What needs improvement?
Forescout is constantly adding new features, so this may change as of this writing, but sometimes the switch management interface doesn't display accurate information which relates to false positives on individual switch access errors.
For how long have I used the solution?
1 year
What was my experience with deployment of the solution?
None that were Forescout related. CounterACT always opens a bunch of little IP sessions with endpoints, ake sure you have a large enough connection table on your firewall if you plan to put it behind one.
What do I think about the stability of the solution?
Minor. Had to reinstall one virtual appliance, which is painless when you have an Enterprise Manager.
What do I think about the scalability of the solution?
No, this is one of the products strengths.
How are customer service and technical support?
Customer Service:
10 out of 10. Very responsive and address concerns quickly.
Technical Support:9 out of 10. Really fast response, high level of competency.
Which solution did I use previously and why did I switch?
I switched from Cisco NAC because it is reliant on 802.1X, and has no other function than to ensure endpoints have authenticated via your method of choice.
How was the initial setup?
Straightforward. Setup is simple with a solid, pre-defined set of policies that you build on and customize as you learn.
What about the implementation team?
In house.
What was our ROI?
Without access specific numbers, we now have the ability to instantly shut down internal malicious hosts or traffic, refuse or restrict access to non-compliant hosts, discover risks on the network we didn't know were there, and automate the remediation of a multitude of security risks. As I work for an organization that spends a lot on security administration, at a minimum, the cost savings must have already paid for the product.
Which other solutions did I evaluate?
Palo Alto
What other advice do I have?
Make sure to plan for all endpoints. If you want full coverage of your networks, account for anything that has an IP address. For example, a busy core switch can have 20+ IP addresses, and each one goes against your license count. Also, if you plan to have it behind a firewall, take into consideration your firewall's connection limitations. Although CounterACT isn't really a heavy bandwidth user, it does open a ton of short connections on a constant basis. The more you tune these down, the less accurate your real time host information becomes.
Disclosure: My company has a business relationship with this vendor other than being a customer. I currently work as a Solution Architect for ForeScout, but I wrote this review when I was a customer.
Buyer's Guide
Download our free Forescout Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Network Access Control (NAC) IoT Security Endpoint Compliance Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
SentinelOne Singularity Endpoint
Darktrace
Elastic Security
Cisco Identity Services Engine (ISE)
Trellix Endpoint Security Platform
TrendAI Vision One
Microsoft Defender XDR
Fortinet FortiClient
Aruba ClearPass
Kaspersky Next XDR Optimum
Vectra AI
TrendAI Vision One – Endpoint Security
Buyer's Guide
Download our free Forescout Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- PRICING FOR FORESCOUT CT10K APPLIANCE
- ForeScout vs. Cisco ISE
- What are the main differences between Cisco ISE and Forescout Platform?
- Comparison of Aruba Clearpass, Bradford Networks and Forescout NACs
- How would you compare Cisco ISE (Identity Services Engine) vs Forescout Platform?
- PRICING FOR FORESCOUT CT10K APPLIANCE
- When evaluating Network Access Control, what aspect do you think is the most important to look for?
- Which is the best choice of Zero Trust Network Access (ZTNA)?
- What is your recommended Network Access Control (NAC) solution for an enterprise?
- Cisco ISE (Identity Services Engine) vs Fortinet FortiNAC: which solution is better and why?
















Hi Michael, I think there was a typo on the report. I was using version 7.