
As an implementer, centralized policy management is the biggest win — defining RADIUS, TACACS+, and 802.1x authorization rules in one place eliminates per-device configuration and makes policy audits straightforward. The deep Cisco ecosystem integration is equally valuable; pxGrid context sharing with Firepower means ISE pushes identity-aware decisions into the broader security stack automatically, something that would otherwise require significant manual correlation." Review collected by and hosted on G2.com.
The most frustrating pain point is interoperability with non-Cisco network access devices. CoA and VSA behaviour becomes inconsistent when working with third-party switches and wireless controllers, necessitating significant workarounds and increasing deployment complexity in mixed-vendor environments.
The admin GUI is noticeably sluggish, particularly when navigating policy sets or loading live authentication logs on larger deployments. This slows down day-to-day troubleshooting and makes what should be quick configuration changes feel unnecessarily tedious.
The upgrade process is also a significant operational burden. ISE upgrades require careful sequencing across PAN, PSN, and MnT nodes, demand long maintenance windows, and carry real risk of service disruption if anything goes wrong mid-process. A more streamlined, rolling upgrade mechanism would greatly reduce the operational overhead. Review collected by and hosted on G2.com.