2021-08-06T07:01:00Z

What are the main differences between Cisco ISE and Forescout Platform?

SR
  • 3
  • 1482
PeerSpot user
3

3 Answers

AS
Real User
2021-08-10T13:38:46Z
Aug 10, 2021

OK, so Cisco ISE uses 802.1X to secure switchports against unauthorized access. The drawback of this is that ISE cannot secure the port if a device does not support 802.1x. Cameras, badge readers, temp sensors, etc would fall into this category. Then you have to leave the port unsecured. Also, 802.1x requires you to drop config on every switchport, and have other infrastructure installed to support it. Also, Cisco ISE licensing is complicated and draconian. In some cases, the same endpoint might need to utilize 4 different licenses at the same time.


Forescout operates differently and does not rely on 802.1x. Forescout listens to a variety of sources. For one thing, Forescout can listen to the wire through SPAN. Forescout also uses SNMP to monitor and control switches, routers, and APs. So Forescout can hear when a connection is made to a switchport, discover the IP of the endpoint on that port, control the endpoint if possible through AD or an installed agent, place the switchport into a quarantine VLAN if needed, and if SPAN traffic is available, place a virtual firewall rule in front of the endpoint. It can query the endpoint for processes, apps, OS, AV, and many other things.

The main advantage of Forescout is it doesn't need 802.1x on every switchport to control access, which is quite burdensome to configure. It senses every device on the network instantly, can listen to the wire, has multiple ways of gathering data, and can control switches. Licensing is simple and is per IP address.


Cisco ISE may be required for certain Cisco technologies or environments - then you don't have a choice. ISE is expensive and has extensive licensing requirements. You will need to dedicate at least one person to become an ISE SME, and training will be mandatory. The main advantage of Cisco ISE over Forescout is it can be a TACACS server natively.

EB
Community Manager
Aug 10, 2021

@Avraham Sonenthal thanks a lot for such a detailed answer!

PeerSpot user
Product comparison that may be of interest to you
JD
User
2021-08-10T16:17:09Z
Aug 10, 2021

Both Cisco ISE and Forescout are highly regarded as both are at the very top of the Garner Magic Quadrant (if you follow Gartner). Looking at them both on their own the nod tends to go to Forescout as the Best of Breed. Best of Platform, however, the nod goes to Cisco ISE. 


So in simplest terms, Cisco ISE is a better solution when in a strong Cisco environment, and Forescout is the better solution if there are disparate security flows within your organization.  


Now I would also throw into the mix (not meant to overcomplicate your decision) HPE/Aruba Clearpath as well. In any case, they can all be a bear to implement so make sure you have a great organization to work with you on implementation that has a specialty with a particular vendor.

EB
Community Manager
2021-08-10T05:57:27Z
Aug 10, 2021

Hi @Sean Muller, @Nayef Hamzeh, @Chandra-Prakash, @Josept Conde, @Dilan Jayamantri, @Jonathan Soto, @Miguel Santiago ​and
@Avraham Sonenthal


It seems you should be able to share some professional advice in relation to this question.


Thanks in advance for helping other community members!

Find out what your peers are saying about Cisco ISE (Identity Services Engine) vs. Forescout Platform and other solutions. Updated: March 2024.
765,234 professionals have used our research since 2012.
Cisco ISE (Identity Services Engine) vs. Forescout Platform comparison
We performed a comparison between Cisco ISE and Forescout Platform based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below. Ease of Deployment: Cisco has a bit of a reputation for being complex across the board with all their offerings and Cisco ISE is no different. For those users that are heavily invested in the Cisco ecosystem, deployment is not a big challenge. For those that are novices or not so tech-savvy, the process...
Download Cisco ISE (Identity Services Engine) vs. Forescout Platform comparison ReportRead more

Related Q&As