randomuser17 wrote: » Hi, I can share my experience on NAC. Both Cisco and Forescout are leading vendors in NAC space. I personally have tested both vendors in our POC environment and can share my experience. With Cisco ISE, 1) you will need to configure all your access layer switches with 802.1x configuration as well as will require Cisco AnyConnect client on your laptops. Deployment and configuration can take a long time if it is an enterprise network. 2) It is a layer 2 solution which is fine but from operations standpoint, it will be a nightmare. 3) You will have to create separate policies for non.1x endpoints. 4) Cannot scale for the cloud endpoint especially without the supplicant With Forescout 1) It is an agentless solution. Doesn't require any 802.1x configuration on the switches. Uses service accounts to login to the endpoints or has dissolvable agents for BYOD type of devices. 2) it is a layer 3 deployment hence only cares for DHCP type of traffic to classify, clarify the traffic. 3) Policy management is also very simple. 4) Since it is an agentless solution, it can be leverage in public cloud as well. After testing both the vendor, i picked Forescout for the reasons i mentioned above. Very easy to deploy, manage and support. Supporting a 802.1x deployment will be a nightmare if it is a medium to large network so definitely consider that factor. Thanks.