This post is the first in a new series we’ll be featuring called Your Questions: Answered. In this series, we track down the answers to partners’ toughest technical questions. You can submit your questions here, post on the Cisco Channels Facebook page, or drop us a note on Twitter.
When Cisco recently introduced the Identity Services Engine (ISE), you likely started fielding questions, with many customers concerned about whether Cisco Network Admission Control (NAC) and Cisco Access Control System (ACS) will cease to be supported or become end-of-life. (Kind of like how I felt when the iPhone 4 came out and I was stuck with the iPhone 3G).
To help you address customer questions, I went out looking for answers on what’s up with ISE, NAC, and ACS. First up, a little about ISE: It has similar functionality to NAC and ACS, combining the functionality of those two existing products onto a new platform. Your customers can gather information from users, devices, infrastructure, and network services to enable organizations to enforce contextual-based business policies across the network, create and enforce consistent policy from the head office to the branch office, and combine authentication, authorization, and accounting (AAA), posture, profiling, and guest management with this single product. And that’s just the beginning--I’ll share details on how to find out more about ISE later in this blog.
Back to the issue at hand — I chatted with Brian Sak, Cisco’s Consulting Systems Engineer and expert on Borderless Networks Security products. He filled me in on the most frequently asked questions that he’s been getting from partners around ISE.
Are NAC and ACS being replaced by ISE?
No, both NAC and ACS have ongoing roadmaps, developments, and new releases planned. If ISE does not meet your customer’s current needs, your customers can still use NAC or ACS. Cisco will not stop innovations on NAC and ACS anytime in the near future.
Should I encourage my NAC and ACS customers to migrate to ISE now?
The answer varies based on your customers and their requirements. Check out this handy chart in the Partner Community Discussion Forum (log in required) to help you determine if ISE is the right fit, right now for your customers.
What is the migration path for NAC and ACS?
Migration SKUs are available for existing NAC and ACS customers. This means your customers can potentially be offered a reduced cost or free migration from one platform to another. You can get up to speed quickly on how to migrate to ISE using the Cisco ISE Migration At-a-Glance (PDF).
Is there a NAC roadmap available?
Yes, you can find the NAC roadmap along with other partner training information by logging into the Partner Community.
Who can sell ISE?
Initially, ISE will not be generally available for all partners to resell. Only Cisco Authorized Technology Provider (ATP) partners who meet a set of requirements and have been trained on the product will be able to position and sell ISE. For more information on the ATP program and process, check out the end of this Q&A (log in required).
Hopefully this FAQ has provided you with all of the information you need to answer your customer’s questions about ISE. For additional information, please visit these key links:
- Cisco Identity Services Engine
- Cisco Identity Services Engine (ISE) Partner Resources (log in required) – ATP literature coming soon
Got any other questions around ISE that you didn’t see covered in this blog post? Or do you have technical questions on another topic? Please share them in the comments below, on our Facebook page, or send us a tweet, we may answer your technical question in our next blog post.