Enterprises moving network access control off a legacy on-premise Cisco Identity Services Engine (ISE) deployment need to preserve the controls their environment already depends on. Those controls center on three requirements: certificate-based authentication, access policy enforcement, and fallback authentication for devices that cannot run 802.1X. This page describes how Cloudi-Fi Cloud NAC fits into an existing network to preserve all three.
What a Cisco ISE replacement must preserve
Network access control migrations carry risk because the incumbent enforces authentication and policy across many sites at once. A replacement platform must reproduce certificate-based authentication using the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS). With EAP-TLS, a Remote Authentication Dial-In User Service (RADIUS) server validates device certificates signed by the corporate Certificate Authority (CA).
If certificate validation, revocation checks, or attribute-based decisions are not carried over, authenticated devices lose access.
Policy enforcement adds a second dependency. Access decisions in an 802.1X environment often map identity, directory group, and certificate attributes to dynamic VLAN assignment or access control. Those mappings must remain intact through a cutover.
A third requirement is fallback: many networks include devices that cannot run an 802.1X supplicant and rely on credential-based flows or MAC Authentication Bypass (MAB).
Multi-region enterprises face these dependencies simultaneously across every site, and each site must continue to meet local and regional compliance requirements during the transition. A migration approach that requires replacing network hardware, or running two controllers on a single enforcement point, increases operational risk.

How Cloudi-Fi fits into an existing Cisco ISE environment
Cloudi-Fi Cloud NAC is a cloud-native, infrastructure-agnostic platform that fits into the existing environment rather than replacing the surrounding infrastructure. The identity provider (IdP), corporate directory, CA, and network hardware stay in place. Cloudi-Fi Cloud RADIUS implements 802.1X for both wired and wireless access, so switches and controllers re-point their RADIUS target instead of being swapped out.
For certificate-based authentication, Cloud RADIUS validates the device certificate signed by the corporate CA. It applies policies based on certificate attributes such as common name (CN) and organizational unit (OU). This is passwordless via EAP-TLS.
Cloud PKI can issue, deploy, and manage certificates without maintaining a separate on-prem public key infrastructure.
Policy enforcement fits into the same model. Cloudi-Fi applies granular, role-based access policies based on identity and directory information. It drives dynamic VLAN assignment or access control from certificate or identity attributes.
Fallback methods are preserved through credential-based flows against existing directories — Active Directory, OpenLDAP, and Microsoft Entra ID. MAB covers headless and IoT devices. IdP integration covers SAML corporate IdPs, Microsoft Entra ID, and Okta.

Migration is a phased, re-pointing exercise. A switch points its 802.1X and MAB traffic at one RADIUS server at a time. Cloudi-Fi therefore does not run in parallel with another NAC on the same enforcement point.
Instead, it supports phased cutover site by site, Service Set Identifier (SSID) by SSID, or VLAN by VLAN. The incumbent is decommissioned after the last site moves.

Organizations that want to start smaller can move guest access first and keep ISE for corporate 802.1X and device administration. See replacing ISE guest access while retaining 802.1X and TACACS+.
Outcome: controls preserved through migration
- Certificate-based authentication is preserved through EAP-TLS validation against the existing corporate CA, including revocation checks and attribute-based policy.
- Access policy enforcement continues with role-based rules and dynamic VLAN assignment driven by identity and certificate attributes.
- Fallback authentication remains available through directory credential flows and MAB for devices that cannot run 802.1X.
- No local RADIUS or added hardware is required, and existing network vendors such as Cisco WLC and HPE Aruba Networking stay in place.
- Migration proceeds site by site, SSID by SSID, or VLAN by VLAN, keeping the IdP, directory, and CA unchanged.
- Policy and governance stay consistent across sites, supporting multi-region compliance for organizations. Cloudi-fi operates in 90+ countries and 100K+ secured sites.
See how Cloudi-Fi Cloud NAC re-points existing switches and controllers, keeps 802.1X, policy, and fallback intact, and moves sites one at a time.






