About this lab
Cisco ISE policy practice lab
This page is a Cisco ISE 3.3 style policy simulator. It is not a real ISE node and it does not answer live RADIUS from a switch. The left side shows one policy set named Default: authentication rules with a condition, an identity store, and an action, then authorization rules with a condition and an authorization profile. Profiles list VLAN, downloadable ACL, and SGT.
The right side is a set of canned RADIUS test requests. Pick one and the result pane walks the request through authentication and authorization. A matched step is marked, skipped steps stay visible, and the verdict is accept or reject with the profile that would be returned. Use Reset to restore the starter policy.
The point of the lab is rule order and conditions, not building a full ISE deployment. Guest mode needs no VM. You are not changing a production NAD. Sign-in only keeps the workspace.
Common questions
What does a test request show?
How that canned RADIUS request hits the authentication rules, then the authorization rules, and which VLAN, dACL, and SGT profile comes back.
Can I point a real switch at this page?
No. The requests are built into the lab. There is no RADIUS listener for network devices.
Which ISE version is the screen modelled on?
ISE 3.3 policy sets, authentication, authorization, and authorization profiles.
What should I look at when the result is reject?
The trace. Find the first rule that matched and the ones that were skipped. Order is the usual reason a canned request misses the profile you expected.
Policy Sets · Default
Authentication Rules
| Rule | Condition | ID Store | Action |
|---|
Authorization Rules
| Rule | Condition | Authz Profile |
|---|
Authorization Profiles
| Name | VLAN | dACL | SGT |
|---|
Test Requests
Pick a canned RADIUS request to see how it flows through the rules above.