CiscoIdentity & Zero Trust

    Identity Services Engine (ISE)

    The industry’s complete NAC solution and the bedrock for network zero trust.

    Cisco Identity Services Engine (ISE) is the industry’s complete Network Access Control solution and the bedrock for zero trust — enabling secure access for users and devices across wired, wireless, VPN, and 5G. It builds an all-encompassing contextual identity (user, device, posture, location, threat) to enforce precise, role-based access and micro/macro segmentation. Faltrox designs, deploys, and operates it as the network access-control foundation.

    Overview

    What Identity Services Engine (ISE) is

    Cisco ISE sees and controls who and what is on the network — users, devices, and application workloads from data centre and cloud — and controls their access across wired, wireless, VPN, and 5G connections. It is the industry’s complete NAC solution and, Cisco argues, the bedrock of zero trust: without it, cracks form that attackers exploit.

    ISE creates a contextual identity from attributes like user, time, device, device posture, location, threat, and vulnerability, then uses that identity to enforce access policy that matches the endpoint’s business role — with precise control over who, what, when, where, and how devices connect. It enforces both micro- and macro-segmentation (the foundation of TrustSec and Software-Defined Access), supports zero-touch provisioning, and can be hosted on-premises or as workloads across multiple clouds. Faltrox designs the policy and segmentation, deploys ISE, and operates it as the network access-control layer of zero trust.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Wired, Wireless, VPN & 5G

    Controls access across every connection type into the corporate network.

    02

    Users & Devices

    Sees and controls users, devices, and IoT with a full contextual identity.

    03

    Application Workloads

    Extends visibility and control to workloads from data centre and cloud.

    04

    Segmentation

    Enforces micro- and macro-segmentation as the foundation of TrustSec and SD-Access.

    05

    Zero Trust Access

    The bedrock for network zero trust — secure access for every user and device.

    06

    Cloud or On-Prem

    Hosted on-premises or as software workloads across multiple clouds.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Discover

      ISE profiles every user and device connecting to the network and builds a contextual identity from many attributes.

    2. 02

      Authenticate

      It authenticates and authorises access via 802.1X, MAB, or other mechanisms, integrating with identity providers.

    3. 03

      Assess Posture

      It evaluates device posture — patch level, security agents, compliance — as part of the access decision.

    4. 04

      Enforce

      It applies role-based access and micro/macro segmentation (TrustSec) so endpoints reach only what their role permits.

    5. 05

      Operate

      Faltrox designs the policy and segmentation, deploys ISE, and operates it as the network access-control layer.

    Capabilities

    Key capabilities

    Complete NAC

    The industry’s complete Network Access Control solution across wired, wireless, VPN, and 5G.

    Contextual Identity

    Builds identity from user, time, device, posture, location, threat, and vulnerability attributes.

    Role-Based Access

    Enforces precise access matching each identity’s business role — who, what, when, where, and how.

    TrustSec Segmentation

    Micro- and macro-segmentation form the foundation of TrustSec and Software-Defined Access.

    Device Posture

    Assesses endpoint compliance and health as part of every access decision.

    Profiling & Visibility

    Profiles and inventories every device, including unmanaged and IoT endpoints.

    Zero-Touch Provisioning

    Automates deployment and lifecycle management for agility and flexibility.

    Cloud-Hostable

    Runs on-premises or as software workloads across multiple clouds via Infrastructure-as-Code.

    Works with

    Part of the platform

    Cisco products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Cisco Identity Services Engine (ISE) for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What does ISE actually do?

    It is Network Access Control — it decides who and what is allowed onto the network and what they can reach. It builds a contextual identity for every user and device and enforces role-based access and segmentation across wired, wireless, VPN, and 5G, making it the foundation of network zero trust.

    02How does it relate to TrustSec and SD-Access?

    ISE is the policy engine behind them. It enforces the micro- and macro-segmentation that TrustSec and Software-Defined Access rely on, assigning endpoints to security groups and controlling their reachability by identity rather than IP address or VLAN.

    03How is ISE different from Duo?

    Duo verifies user and device identity at the application layer (MFA and device trust); ISE controls access at the network layer (NAC and segmentation). They are complementary — Duo secures who gets into apps, ISE secures what gets onto the network. Faltrox deploys them together in a zero-trust design.

    04Can it run in the cloud?

    Yes — ISE can be hosted on-premises or as software workloads across multiple clouds using Infrastructure-as-Code, giving flexibility to deploy NAC from the cloud and maintain business continuity.

    05How does Faltrox operate it?

    We design the access policy and segmentation model, deploy ISE, integrate it with your network devices and identity providers, and operate it — delivering network access control and segmentation as the foundation of the zero-trust architecture we build for you.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us