Cisco Identity Services Engine (ISE) vs. Cisco Secure Firewall

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Identity Services Engine (ISE)
Score 8.9 out of 10
N/A
The Cisco Identity Services Engine (ISE) offers a network-based approach for adaptable, trusted access everywhere, based on context. It gives the user intelligent, integrated protection through intent-based policy and compliance solutions.N/A
Cisco Secure Firewall
Score 8.2 out of 10
N/A
Cisco Secure Firewall delivers comprehensive threat protection for modern, distributed networks. Built to support hybrid workforces and multicloud environments, it enables Zero Trust access, application visibility, and secure remote connectivity. With integration across the Cisco Secure portfolio, including SecureX and Talos threat intelligence, the firewall powers organizations to detect and stop more sophisticated threats. Centralized management simplifies policy enforcement, orchestration,…N/A
Pricing
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Considered Both Products
Cisco Identity Services Engine (ISE)
Chose Cisco Identity Services Engine (ISE)
we selected ISE to deploy with SGTs and manage network devices
Chose Cisco Identity Services Engine (ISE)
Cisco ISE Leads in Certain Areas of integration with Cisco infrastructure (switches, firewalls, routers).Strong support for Zero Trust and regulatory compliance segmentation & dynamic access
Chose Cisco Identity Services Engine (ISE)
Works and integrates really well with the secure firewall for RAVPN user authentication
Cisco Secure Firewall
Chose Cisco Secure Firewall
Well FWs are branch security things and major things so really not much similar device at Cisco portfolio.
Chose Cisco Secure Firewall
Cisco Secure Firewall is not so complicated to configure, especially as a Firewall manager where your main business is to create new rules or create site to site tunnels and so on. You can easily do this on the Cisco Secure Firewall, with CheckPoint this was a bit more …
Chose Cisco Secure Firewall
Integration with ISE to deploy identity based policy
Chose Cisco Secure Firewall
I believe Cisco firewalls are definitely on par with Palo Alto but the latest AI feature releasing in 2024 will certainly surpass all expectations. Fortinet is going to struggle after this and I can say that with certainty given we have removed all our FortiGate firewalls.
Chose Cisco Secure Firewall
Cisco Secure Firewall aka Firepower has a more visibility than the ASA, specially with use of FMC. The Secure Firewall also adds a lot of security features, with IPS, IDS, AVC, Security Intelligence, Identity Mapping and so on.
Chose Cisco Secure Firewall
Cisco FTD poc was more successful on our case
Features
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Firewall
Comparison of Firewall features of Product A and Product B
Cisco Identity Services Engine (ISE)
-
Ratings
Cisco Secure Firewall
8.0
139 Ratings
8% below category average
Identification Technologies00 Ratings8.2123 Ratings
Visualization Tools00 Ratings7.4125 Ratings
Content Inspection00 Ratings8.0122 Ratings
Policy-based Controls00 Ratings8.5130 Ratings
Active Directory and LDAP00 Ratings8.3113 Ratings
Firewall Management Console00 Ratings7.6129 Ratings
Reporting and Logging00 Ratings7.7131 Ratings
VPN00 Ratings8.0116 Ratings
High Availability00 Ratings8.6125 Ratings
Stateful Inspection00 Ratings8.5121 Ratings
Proxy Server00 Ratings7.369 Ratings
Best Alternatives
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Small Businesses
NinjaOne
NinjaOne
Score 9.1 out of 10
pfSense
pfSense
Score 8.8 out of 10
Medium-sized Companies
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.3 out of 10
Enterprises
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 9.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Likelihood to Recommend
8.8
(119 ratings)
7.9
(145 ratings)
Likelihood to Renew
9.6
(3 ratings)
8.5
(4 ratings)
Usability
7.0
(3 ratings)
6.4
(3 ratings)
Availability
9.3
(3 ratings)
8.7
(4 ratings)
Performance
9.0
(1 ratings)
5.0
(1 ratings)
Support Rating
7.0
(6 ratings)
7.3
(79 ratings)
Implementation Rating
9.3
(3 ratings)
8.8
(4 ratings)
Configurability
8.0
(1 ratings)
-
(0 ratings)
Contract Terms and Pricing Model
8.1
(2 ratings)
-
(0 ratings)
Ease of integration
5.6
(3 ratings)
7.9
(3 ratings)
Product Scalability
8.0
(1 ratings)
5.0
(1 ratings)
Vendor post-sale
10.0
(1 ratings)
-
(0 ratings)
Vendor pre-sale
9.0
(1 ratings)
-
(0 ratings)
User Testimonials
Cisco Identity Services Engine (ISE)Cisco Secure Firewall
Likelihood to Recommend
Cisco
Cisco ISE integrates will with a Cisco solution such as firewalls, network switches and routers. It does an incredible job of granting access based on the role that an individual or groups have, and the ability to remove access to that individual or group is also east. In our environment ISE is used to authenticate external users that have access by vpn, and also to manage access to the large network infrastructure
Read full review
Cisco
This security solution is well-suited for a complex environment that requires a scalable and secure solution with granular control. It is also recommended that it be implemented with other Cisco security solutions. Requirements are Security-First. It is less appropriate in a small business scenario where advanced configurations are not required. It should be well-trained on this solution.
Read full review
Pros
Cisco
  • The most beneficial thing that I love about it, there are tons of things that I love about ISE and that it does well, but the most fascinating that I feel about is its integration with DNA center or Catalyst Center using PX Grid as the protocol wherein ISE acts as a policy server for the entire campus hand in hand with Catalyst Center to make sure that the policy policy follows the user and also in the background hand in hand with DNA Center or Catalyst Center makes sure microsegmentation is implemented so that east west traffic is blocked and takes care of the campus.
Read full review
Cisco
  • It's good at segregating networks and ensuring that you only give the access that you need to give. Especially with medical devices, you want to only give the access that they need and keep them in their own separate areas so that they can't just communicate with the rest of the network. It's also good at the border for keeping attackers out of the network.
Read full review
Cons
Cisco
  • Trustsec needs more documentation and configuration best practice examples
  • The licensing model can be difficult to explain and understand for customers
  • Difficult to get an accurate benchmark to know exactly how many Cisco Identity Services Engine nodes and the size of the deployment should be
Read full review
Cisco
  • I wish that the deployment of the updates to the sensors from the FMC was faster.
  • Cisco ASA firewall did a great job of authentication and authorization on the local firewall. FTD does not authorize users well in terms that an AAA must be setup to provide the granular tools that the ASA did.
  • Cisco's method of licensing the firewall can be improved. The FMC and the FTD are licensed through the Cisco software manager and there are instances where the devices are licensed but the firewall still displays and error due to licensing.
Read full review
Likelihood to Renew
Cisco
We are so very reliant on Cisco Identity Services Engine at this point that finding another solution would be a big hassle for us.
Read full review
Cisco
It works really well. We can do most anything we want or need to with it, and you don’t have to have a doctorate or multiple certs to necessarily figure it out. The thing that would probably have to happen to make us switch would be if we just got priced out - Cisco’s more powerful and higher bandwidth models cost a pretty penny.
Read full review
Usability
Cisco
For us the solution is very easily useable on its own. Perhaps that has to do because we started using ISE in the 1.2 days and have seen it grow during the years. Policy creation, etc. is all very visible and thus easy to use. Deployment of multiple nodes is also incredibly easy and flexible. You can easily add or remove nodes as you wish.
Read full review
Cisco
i think overall after ALOT of tac cases it works allright now. But still have alot of issues if you use cloud based mangement. fx, if you open 2 windows of access policys, both of the pages, rules starte to jump form side to side. if you then open one more list, its start to jump even faster. if you close the 2 of them, its back to normal. ALSO the extended access lists for VPN, SUCKS. Its the tiniest window when opening the editor, and you are not able to give the rules names, Which means finding and editing rules SUCKS, its a horrible experience, and eveytime we have to we want to yell :P
Read full review
Reliability and Availability
Cisco
We do have to occasionally reboot the servers when they get low on memory, but we're also a few versions behind. Availability has generally been pretty good though with no major outages in the time that we've had it implemented.
Read full review
Cisco
would rate Cisco Secure Firewall’s availability a 9 out of 10.
In our production environments at Rackspace, the platform has been consistently reliable. We’ve deployed it in high-availability pairs, and failover works as expected with minimal disruption. Over the past several quarters, we’ve had no major unplanned outages directly attributable to the firewall itself.
The software has been stable
Read full review
Performance
Cisco
yes it does. depending on where you coming from. Logs are pretty busy same as report. it also depending on devices count and design.
Read full review
Cisco
no slowing down, vpn is working fast
Read full review
Support Rating
Cisco
Cisco support is second to none, both in terms of how you access support but also the knowledge of the individual support teams. If you focus on one technology and provide "manufacturer support" then you can rest assured that you are accessing Cisco's top individuals. I feel like this is a USP for Cisco support.
Read full review
Cisco
Firewall support is professional just like any other technology Cisco sells. From answering simple questions to bringing out outages affecting a large population of our workforce, Cisco support is always courteous, professional, and communicates with our team to keep our request on their radar. Some of the brightest people I've met are from Cisco support both in IQ and EQ which shows the talent Cisco is able to onboard to their team.
Read full review
In-Person Training
Cisco
No answers on this topic
Cisco
very good
Read full review
Online Training
Cisco
Training can only cover certain areas, there are a lot of areas training just can't cover. You have to learn by doing it.
Read full review
Cisco
was a good training but questions was answered not so good. Training was "Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention (SFWIPF)".
Read full review
Implementation Rating
Cisco
I did participate in the implementation of Cisco ISE and while there were times when it was confusing and we had a lot of trial and error, overall the experience was fine.
Read full review
Cisco
Our initial implementation was aided by Cisco's professional services and was excellent. The engineer was very knowledgeable and helped us work through issues while building out our new internet security edge Part of this involved tools to migrate the firewall configuration from old to new.
Read full review
Alternatives Considered
Cisco
I think all give some visibility of device monitoring and management, but Cisco Identity Services Engine gives a good way to manage more details about the device in a centralized way that gives a wider range of monitoring and control than the other softwares individually. I don't think Cisco Identity Services Engine eliminates the need for these other software as of now, but there is potential for Cisco Identity Services Engine to be able to take over more of these roles.
Read full review
Cisco
Cisco Secure Firewall works better with the Cisco ecosystem when we can utilize it and feels beefy enough when we utilize it in the data center. The Fortinet we have found are great, small cost boxes for remote offices with a better UI then Cisco Secure Firewalls. The feature set included with the firewalls feels similar from a security point of view.
Read full review
Contract Terms and Pricing Model
Cisco
Cisco ISE was competitively priced and Cisco was able to leverage some of our existing contracts to help ease the purchase.
Read full review
Cisco
was not involved
Read full review
Scalability
Cisco
It's fully customised and comprehensive. only thing is you need to know what you want. Proper research and planning would save lots of time and effort .
Read full review
Cisco
you can choose up to 50 devices i think thats enough for our organization
Read full review
Professional Services
Cisco
No answers on this topic
Cisco
was not involved
Read full review
Return on Investment
Cisco
  • I don't know about negatives because we haven't seen it right now, but positive impact is one is the roadmap we have. And now since we are going ahead with doing the deployment of Cisco ISE, we see that we are getting closure to, so at the end of the day, we have to make sure that operationally we stay excellent. So that's where operational excellence comes in. Cisco ISE is basically addressing that for us. Right now we are in a situation if there is a WIFI issue or if there is an authentication issue, it gets really difficult to isolate the problem. But with Cisco ISE , this functionality is going to come in. So we believe that it would be a good ROI.
Read full review
Cisco
  • Positive impact. Cisco is a big player in IT environment. It is future stuff, everything, what you learn today, maybe something can be tomorrow. And yes, it's quite important to learn the new stuff every day. And yes, that's it. Yes, I'm happy with Cisco.
Read full review
ScreenShots

Cisco Identity Services Engine (ISE) Screenshots

Screenshot of Cisco Identity Services Engine (ISE)

Cisco Secure Firewall Screenshots

Screenshot of Cisco Secure 1200 Series Firewall FamilyScreenshot of Cisco Secure 4200 SeriesScreenshot of Cisco Secure 4200 SeriesScreenshot of Cisco Secure Firewall 1200 Stack FamilyScreenshot of Cisco Secure Firewall 200 SeriesScreenshot of Cisco Secure Firewall 200 Series