Blog

Replacing Cisco ISE while keeping 802.1X, policy, and fallback intact

Author(s): 
 ()
, 
 ()
Cloud NAC, Zero Trust
Back to previous
Engineer using a laptop beside network equipment, with a blue connection illustrating cloud authentication.
October 9, 2026
  |  
Last updated: 
October 9, 2026
  |  
  5 min

Enterprises moving network access control off a legacy on-premise Cisco Identity Services Engine (ISE) deployment need to preserve the controls their environment already depends on. Those controls center on three requirements: certificate-based authentication, access policy enforcement, and fallback authentication for devices that cannot run 802.1X. This page describes how Cloudi-Fi Cloud NAC fits into an existing network to preserve all three.

What a Cisco ISE replacement must preserve

Network access control migrations carry risk because the incumbent enforces authentication and policy across many sites at once. A replacement platform must reproduce certificate-based authentication using the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS). With EAP-TLS, a Remote Authentication Dial-In User Service (RADIUS) server validates device certificates signed by the corporate Certificate Authority (CA).

If certificate validation, revocation checks, or attribute-based decisions are not carried over, authenticated devices lose access.

Policy enforcement adds a second dependency. Access decisions in an 802.1X environment often map identity, directory group, and certificate attributes to dynamic VLAN assignment or access control. Those mappings must remain intact through a cutover.

A third requirement is fallback: many networks include devices that cannot run an 802.1X supplicant and rely on credential-based flows or MAC Authentication Bypass (MAB).

Multi-region enterprises face these dependencies simultaneously across every site, and each site must continue to meet local and regional compliance requirements during the transition. A migration approach that requires replacing network hardware, or running two controllers on a single enforcement point, increases operational risk.

‍

Cisco ISE enforcing certificate authentication, access policy, and fallback authentication across multiple sites
Cisco ISE enforcing certificate authentication, access policy, and fallback authentication across multiple sites

‍

How Cloudi-Fi fits into an existing Cisco ISE environment

Cloudi-Fi Cloud NAC is a cloud-native, infrastructure-agnostic platform that fits into the existing environment rather than replacing the surrounding infrastructure. The identity provider (IdP), corporate directory, CA, and network hardware stay in place. Cloudi-Fi Cloud RADIUS implements 802.1X for both wired and wireless access, so switches and controllers re-point their RADIUS target instead of being swapped out.

For certificate-based authentication, Cloud RADIUS validates the device certificate signed by the corporate CA. It applies policies based on certificate attributes such as common name (CN) and organizational unit (OU). This is passwordless via EAP-TLS.

Cloud PKI can issue, deploy, and manage certificates without maintaining a separate on-prem public key infrastructure.

Policy enforcement fits into the same model. Cloudi-Fi applies granular, role-based access policies based on identity and directory information. It drives dynamic VLAN assignment or access control from certificate or identity attributes.

Fallback methods are preserved through credential-based flows against existing directories — Active Directory, OpenLDAP, and Microsoft Entra ID. MAB covers headless and IoT devices. IdP integration covers SAML corporate IdPs, Microsoft Entra ID, and Okta.

Cloudi-Fi Cloud NAC connecting existing switches, wireless controllers, and identity sources through Cloud RADIUS
Cloudi-Fi Cloud NAC connecting existing switches, wireless controllers, and identity sources through Cloud RADIUS

‍

Migration is a phased, re-pointing exercise. A switch points its 802.1X and MAB traffic at one RADIUS server at a time. Cloudi-Fi therefore does not run in parallel with another NAC on the same enforcement point.

Instead, it supports phased cutover site by site, Service Set Identifier (SSID) by SSID, or VLAN by VLAN. The incumbent is decommissioned after the last site moves.

‍

Phased cutover moving sites from Cisco ISE to Cloudi-Fi Cloud RADIUS one at a time
Phased cutover moving sites from Cisco ISE to Cloudi-Fi Cloud RADIUS one at a time

Organizations that want to start smaller can move guest access first and keep ISE for corporate 802.1X and device administration. See replacing ISE guest access while retaining 802.1X and TACACS+.

‍

Outcome: controls preserved through migration

  • Certificate-based authentication is preserved through EAP-TLS validation against the existing corporate CA, including revocation checks and attribute-based policy.
  • Access policy enforcement continues with role-based rules and dynamic VLAN assignment driven by identity and certificate attributes.
  • Fallback authentication remains available through directory credential flows and MAB for devices that cannot run 802.1X.
  • No local RADIUS or added hardware is required, and existing network vendors such as Cisco WLC and HPE Aruba Networking stay in place.
  • Migration proceeds site by site, SSID by SSID, or VLAN by VLAN, keeping the IdP, directory, and CA unchanged.
  • Policy and governance stay consistent across sites, supporting multi-region compliance for organizations. Cloudi-fi operates in 90+ countries and 100K+ secured sites.

See how Cloudi-Fi Cloud NAC re-points existing switches and controllers, keeps 802.1X, policy, and fallback intact, and moves sites one at a time.

Request a demo

Cloudi-Fi white logo

Start your Journey with Cloudi-Fi

Cloudi-Fi white logo
Cloudi-Fi white logo

Start your Journey with Cloudi-Fi