# Policy sets: first match, then authc, then authz

Source: https://ai.techclick.in/blog_cisco_ise_policy_sets_first_match
Markdown: https://ai.techclick.in/blog_cisco_ise_policy_sets_first_match.md
Publisher: Techclick Infosec Pvt Ltd

Policy sets are first-match containers. Authentication then Authorization. Dummy Wired_Lab set.

## The ticket

 Wired rule never hits. Live Logs show Policy Set = Default. Your shiny  Wired_Lab  set is below Default and Default matches everything.

  Quick interview answer

 Policy sets are an ordered list. First set whose condition matches wins — the rest never run. Inside the set, Authentication decides  who  (or Continue/Reject). Authorization decides  what they get  (VLAN, dACL, SGT, redirect). Official default Dot1X: reject on fail / user not found. Official default MAB: if user not found, push to authorization (so profiling can still run).

  Hero · first set wins

 A wide Default set above Wired_Lab makes Wired_Lab dead ink.
  Lab data · dummy only
 PAN  ise-pan   10.10.10.20  · PSN  ise-psn1   10.10.10.21  · MnT  ise-mnt   10.10.10.22  · NAD  sw-access-01   10.10.10.2  · AD  dc01   10.20.30.10  · Priya  10.20.30.80   TECHCLICK\priya.hr  · printer  10.20.30.60 . Not a live customer.

## Three layers of first match

- Which policy set ?

- Which authentication rule (Dot1X vs MAB vs Guest)?

- Which authorization rule (HR dACL vs quarantine)?

  Request walk

 Set then authc then authz
  Policy set  Wired_Lab first
  Authentication  who / Continue

- Authorization VLAN / dACL Access-Accept If step 1 is wrong, you will tune the wrong rules forever. ## One set vs many Design Use Risk Default only Tiny lab Wireless change breaks wired Wired / Wireless / VPN sets Production Forgot to put Wired above Default Monitor-mode set (NAD attribute) Safe rollout NAD not tagged, hits enforce set https://ise-pan.techclick-lab.in/admin Training mock · not live ISE Admin Context Visibility Operations Policy Administration Policy → Policy Sets ### Wired_Lab Condition DEVICE:Device Type EQUALS Cisco Catalyst OR Wired_802.1X Allowed protocols Default Network Access Authc Dot1X → AD ; MAB → Internal Endpoints (Continue if not found) Authz HR → dACL_HR ; Default → Quarantine Cancel Save ISE 3.3 segmentation / policy sets. Training mock. ## How you write a set #### Side A — place it Policy → Policy Sets → insert above Default.

- #### Side B — authc Dot1X → AD. MAB → Internal Endpoints, Continue if not found (lab/monitor). Allowed protocols include PEAP/EAP-TLS/MAB.

- #### Side C — authz + prove HR group → permit dACL. Default → limited. Live Logs must show set name Wired_Lab .

## Four set failures

### 1 · Shadowed set

 Default above you. Move Wired_Lab up.

### 2 · Authc Reject before Authz

 MAB unknown MAC Reject — never reaches profiling-friendly authorization. Use Continue in monitor mode.

### 3 · Allowed protocols missing PEAP

 Looks like AD is down. It is protocol.

### 4 · Tuned Authorization in the wrong set

 Live Logs tell you. Believe them.

## How to prove it

  Close the ticket only when

 1) Live Logs Policy Set = Wired_Lab. 2) Authentication rule name is the one you expect. 3) Authorization result matches. 4) A wireless test still hits the wireless set, not Wired_Lab.

## Traps

   Log field  Read it as

  Policy Set  Step 1
  Authentication Policy / Identity  Step 2
  Authorization Policy / Result  Step 3

## Knowledge check

   Judgment items. One best answer. Reasons send you back to the matching section.

       Q1
       Two policy sets match. Which runs?

           The more specific anywhere
           The first matching set from the top
           Both
           Only Default

       Correct:  b . First match.

       Q2
       Official default MAB when MAC is unknown?

           Always Reject
           Push to authorization (Continue-style)
           Reboot PSN
           Skip RADIUS

       Correct:  b . ISE 3.3 default MAB options.

       Q3
       Authentication vs Authorization?

           Authc = who; Authz = what they get
           They are the same
           Authz happens first
           Only Guest uses them

       Correct:  a . Concept.

       Q4
       Live Logs show Default, not Wired_Lab. First move?

           Move Wired_Lab above Default / fix set condition
           Delete AD
           Disable CoA
           Change MnT IP

       Correct:  a . Failure 1.

       Q5
       Allowed protocols without PEAP causes…

           Dot1X PEAP to fail before AD is really tested
           Faster MAB
           Better pxGrid
           Automatic CWA

       Correct:  a . Failure 3.

       Q6
       Why separate Wired and Wireless sets?

           Limit blast radius of a change
           ISE requires 12 sets
           MnT cannot log mixed
           PAN forbids Default

       Correct:  a . Choose table.

       Check answers
       Reset

  Cisco ISE class series:   Personas  ·  First day  ·  NAD + RADIUS  ·  Policy sets  ·  Wired 802.1X  ·  MAB  ·  CWA / guest  ·  Profiling  ·  dACL vs VLAN  ·  Live logs  ·  vs Forescout  ·  Interview

## Sources

- ISE 3.3 policy sets, default Dot1X/MAB options .
- Lab PDF — first-match policy thinking.

 Related:  ISE evidence desk  ·  session factory  ·  Forescout series .

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
