Cisco ISE Policy SimulatorISE 3.3
Hub →
About this lab

Cisco ISE policy practice lab

This page is a Cisco ISE 3.3 style policy simulator. It is not a real ISE node and it does not answer live RADIUS from a switch. The left side shows one policy set named Default: authentication rules with a condition, an identity store, and an action, then authorization rules with a condition and an authorization profile. Profiles list VLAN, downloadable ACL, and SGT.

The right side is a set of canned RADIUS test requests. Pick one and the result pane walks the request through authentication and authorization. A matched step is marked, skipped steps stay visible, and the verdict is accept or reject with the profile that would be returned. Use Reset to restore the starter policy.

The point of the lab is rule order and conditions, not building a full ISE deployment. Guest mode needs no VM. You are not changing a production NAD. Sign-in only keeps the workspace.

Common questions

What does a test request show?

How that canned RADIUS request hits the authentication rules, then the authorization rules, and which VLAN, dACL, and SGT profile comes back.

Can I point a real switch at this page?

No. The requests are built into the lab. There is no RADIUS listener for network devices.

Which ISE version is the screen modelled on?

ISE 3.3 policy sets, authentication, authorization, and authorization profiles.

What should I look at when the result is reject?

The trace. Find the first rule that matched and the ones that were skipped. Order is the usual reason a canned request misses the profile you expected.

Policy Sets · Default

Authentication Rules

RuleConditionID StoreAction

Authorization Rules

RuleConditionAuthz Profile

Authorization Profiles

NameVLANdACLSGT

Test Requests

Pick a canned RADIUS request to see how it flows through the rules above.

Result

Select a test request to evaluate.