Migrating from Cisco Secure ACS to Cisco ISE

Cisco ISE is the market-leading security policy administration platform. It amalgamates and systematizes access control to proactively impose role-based access to enterprise networks and resources. It doesn’t matter if a user connects via a wired or wireless network or a VPN. Cisco ISE provides improved user and device visibility to give simplified mobility capabilities. It shares important circumstantial information with incorporated technology partner solutions to hasten their capability to find, alleviate, and remediate threats.

The platform combines substantiation, approval, posture valuation, summarizing, and guest management services in an integrated appliance. A single management console for organizing and directing facilities provides you constancy and streamlined administration. Less hardware is needed as numerous services can now be run on a single node.

End-of-Sale and End-of-Life Announcement for the Cisco Secure Access Control System

NOTE: The Cisco ACS is not being sold anymore after August 30, 2017 and may not be supported. View the End-of-Life Notice to learn:

  • End-of-sale and end-of-life dates
  • Which replacement products are obtainable
  • Data about product support

Guarding Your Cisco Investment

The switch from Cisco Secure ACS to Cisco ISE is simple and cost-efficient. Cisco ISE runs on the same Secure Network Server (SNS) hardware platform as the Cisco Secure ACS. Migrate simply with current Cisco SNS 3515 and 3595 hardware. The Cisco ISE software is also supported on VMware.

Cisco Secure ACS capabilities are obtainable in the base software version of Cisco ISE, that now comprises most TACACS+-based network device management attributes.

All Cisco Secure ACS users with device management arrangements can move to the latest Cisco ISE software release.

Migration Tools and Cisco Services

Cisco ISE comes packaged with a tool to assist clients move from Cisco Secure ACS 5.5 or later to Cisco ISE Software 2.X. The tool will spontaneously move Cisco Secure ACS configuration information (like user and device data and policies) to Cisco ISE, but it will not move monitoring and troubleshooting information.

Cisco Secure ACS users who have installed the Cisco Network Admission Control (NAC) Guest Server and NAC Profiler will have to manually move guest and profiler configuration policies.

Migration tools from Cisco Secure ACS 5.x to Cisco ISE are inbuilt in the Cisco ISE Software Release Software Application Support and Upgrades (SASU) contract excluding those used for monitoring and troubleshooting. There is also a standalone version of this tool obtainable.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.