cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3773
Views
15
Helpful
3
Replies

Alternatives to Cisco ISE?

chris.george
Level 1
Level 1

Has anyone out there got any good ideas or experiences with alternative NACs instead of ISE?

Has anyone wished they had never used ISE and used another solution instead?

I am starting from scratch in terms of finding a NAC solution and wonder if ISE is the best or maybe something like FortiNAC could be better?

 

3 Replies 3

Damien Miller
VIP Alumni
VIP Alumni

ISE is the best, and it's the market leader because of that. It may not be the simplest solution, but any feature rich product becomes more complicated and nuanced. 

I second what @Damien Miller said about ISE. It has a bit of a steep learning curve, but over time you learn to love it (warts and all). I have worked with other products too, but I always come back to ISE.

By comparison, Aruba Clearpass (CPPM) is completely different to ISE - it seems to require less resources than ISE but that's because CPPM doesn't have half the features ISE has. The config logic is quite different to ISE - I prefer ISE to CPPM. And BTW, both products are equally buggy ... sorry, they have equal amounts of "software defects"

FreeRADIUS sounds tempting - it's free and runs on raspberry pi - how nice - BUT - you will need to edit all the text files by hand and this might not appeal to you if all you want to do is learn RADIUS. There is apparently a GUI available but requires further hackery. I'd say FreeRADIUS is a labour of love and some people swear by it - but it's RADIUS only ... not much help if you have to integrate with DNAC etc. Again ... ISE is the best

Other products like Radiator and Cisco's own Prime Access Registrar are great products - (RADIUS only) and very hard working tools for hard core applications - but mostly editing text files. If you want simplicity (especially if you're a full-stack engineer) then you will love ISE.

I always recommend www.labminutes.com series to learn about things like ISE and other great Cisco stuff (SDA is also very good) - just watch and learn. And practise! Build a small lab and gain experience. You have to train that "ISE muscle" and you'll never look back.