Hands-On Network Labs for Every Engineer
From the full Cisco Catalyst Center to Palo Alto, Fortinet and Check Point, pre-configured and image-included. No hardware, no setup, no waiting.
→ First 20 registrants get 50% off their first session.
Three ways to get hands-on
Not sure where to start? Guided Labs teach you a concept, with free examples to try. Virtual Labs give you dedicated, self-directed time on the real gear. Exam Questions tests what you've learned with practice questions.
Guided Labs
Structured, step-by-step scenarios in a broken environment. Several are completely free to try end to end; the rest unlock with an email or a Learning Pass.
- Learn one concept at a time
- Real CLI output, worked solutions
- Several labs are free end to end, no email needed
Virtual Labs
Dedicated time on the real gear, from a single Cisco pod to the full Catalyst Center. You drive it yourself, for the window you book.
- Full certification-level pods
- Exclusive, dedicated access
- Book by the session or go persistent
Exam Questions
Multiple-choice practice questions covering every major CCNA 200-301 topic. Test yourself cold or get instant feedback on every answer.
- 279 questions across 30 topics
- Guided mode explains each answer
- Expert mode scores you at the end
What Would You Like to Practice?
Select all that apply. Your answers shape which labs we build first.
Cisco
Security Vendors
Other Platforms
Be First in the Lab
Register your interest and get early access when we go live. First 20 registrants receive 50% off their first session.
How It Works
From booking to CLI access in under 5 minutes.
1. Book Your Session
- Choose an available session on the schedule page
- Complete payment to confirm your reservation
- Instant booking confirmation sent to your email
2. Receive Access Details
- 5 minutes before your session starts, you receive an email
- Email contains your unique lab URL, username, and password
- Credentials are generated fresh for every session, never reused
3. Open the Lab Portal
- Click the link in your email, which opens directly in your browser
- Log in with the credentials provided. No software to install
- HTML5 EVE-NG console gives you full access to all lab nodes
4. Console In & Practice
- Power on your topology: Cisco Catalyst, Palo Alto, Fortinet, etc.
- Console directly into devices from the browser. No SSH client needed
- You get a 15-minute warning before your session ends
Technical access details
What you connect to
A dedicated EVE-NG web portal, tunnelled securely over HTTPS. No VPN required for browser-based console access.
Session security
Your credentials expire the moment your session ends. The lab is wiped and reset before the next user connects.
Optional: packet capture
Install the Cloudflare WARP client (Zero Trust) to route your session locally and capture live traffic with Wireshark.
Session extension
If the next session is free, extend by 6 hours with one click directly from the lab portal, charged at the standard rate.
Browser compatibility
Use Chrome, Firefox, or Safari. Brave blocks EVE-NG's drag-to-connect topology feature, so disable Brave Shields for the lab URL or switch browsers.
Starting with the lab you can't build at home.
Guided scenarios you learn by fixing. Each lab drops you into a broken environment with a clear objective and a worked solution, every device image pre-loaded so you start at the CLI, from the full Cisco Catalyst Center down to routing, switching and the major security vendors. Ready to book real time on the full certification pod? See Virtual Labs below.
Cisco Catalyst Center
The controller almost no one can home-lab: Cisco's own appliance alone needs 32 vCPUs and 256GB of dedicated RAM just to boot. We include it live and ready to launch: build SD-Access fabrics, explore Assurance telemetry, and automate with the Intent APIs.
- SD-Access fabric provisioning
- Assurance & telemetry
- Plug-and-Play onboarding
- REST / Intent API automation
CCNA · 200-301
FreeSpanning Tree: Root Bridge Election
A free, ungated example lab: a misconfigured root bridge sends traffic the long way round. No email required to see the fix.
More details
CCNA · 200-301
FreeVLANs, Trunking & Spanning Tree
802.1Q trunks and native VLANs, STP root election, and inter-VLAN routing on a switched campus.
More details
CCNA · 200-301
FreeOSPF Neighbor Down: Area Mismatch
Two routers ping each other fine across a direct link, but their OSPF adjacency refuses to form. Work it from Layer 3 up to the routing protocol.
More details
CCNA · 200-301
FreeAccess Control Lists: Configuring & Verifying
PC1 can't reach a server through R1, and the router is sending back an explicit deny, not a timeout. The permit entry meant to allow it is right there in the ACL.
More details
CCNA · 200-301
FreeDHCP Snooping: Trust Boundary Misconfiguration
One access switch can't reach the DHCP server. Trace the trust setting on each uplink to find the port silently dropping server replies.
More details
CCNP · ENARSI
OSPF Multi-Area & Redistribution
Areas and LSA types, route summarization, and controlled redistribution between OSPF and EIGRP.
More details
CCNP · ENARSI
BGP Peering & Path Selection
eBGP and iBGP sessions, the best-path algorithm, and policy via local-preference, AS-path and communities.
More details
CCNA · 200-301
EIGRP Neighbor Down: AS Mismatch
Two routers connect over a live link and ping fine, but their EIGRP neighbor adjacency never forms. The configuration looks right at first glance.
More details
Palo Alto · PCNSE
NGFW Zones, NAT & App-ID
Security zones, source/destination NAT, App-ID security policies and SSL decryption on PAN-OS.
More details
Fortinet · NSE 4
FortiGate Policy & IPsec VPN
Firewall policies, SD-WAN rules and a site-to-site IPsec tunnel between two FortiOS gateways.
More details
Check Point · CCSE
Security Policy & Identity Awareness
Ordered policy layers, NAT rules and Identity Awareness on a Gaia gateway managed from SmartConsole.
More details
Cisco SD-WAN · Viptela
Cisco SD-WAN (Viptela)
Stand up the vManage/vSmart/vBond control plane and bring a WAN edge under management over a live overlay.
More details
RHCSA · EX200
Linux Firewalld & iptables Policy
Zone-based firewalld policy, iptables/nftables rule chains, and troubleshooting a host that's silently dropping traffic.
More details
RedHat · RH294
Ansible Playbook Automation
Write and run real Ansible playbooks against multiple managed hosts: inventories, roles, idempotent tasks and ad-hoc modules.
More details
CCNP · DCACI
Cisco ACI EPGs & Contracts
Bridge domains, EPGs and contract-based policy on a real APIC-managed ACI fabric, not a slide deck.
More details
CCNP · DCINX9K
Nexus 9000 NX-OS Switching
vPC domains, peer-links and standalone NX-OS switching on real Nexus 9000 gear, not the ACI-mode UI.
More details
CCNP · ENARSI
BGP Route Reflector Scaling
Replace a full iBGP mesh with route reflectors and clusters: clients, non-clients, and cluster-ID loop prevention.
More details
CCNP · CLCOR
CUCM Dial Plan & Call Routing
Route patterns, partitions/calling search spaces and a working SIP trunk on a real Cisco Unified Communications Manager cluster.
More details
Security · Zero Trust
Zero Trust: JWT Access & Token Expiry
Never trust, always verify: explicit auth, least-privilege endpoints and short-lived JWTs that fail closed the moment they expire.
More details
Cisco · SVPN
GRE VPN Endpoint Migration
Cut a live site-to-site GRE tunnel over to new ISP IPs with minimal downtime, keeping DNS, LDAP and web reachable across both sites.
More details
Linux · RHCSA
Linux Namespaces & veth Routing
veth pairs, network namespaces and inter-subnet routing, the primitives Docker and containerlab use to wire every container.
More details
Cisco · SPCOR
MPLS L3VPN: Customer Routes Missing
The MPLS core is up and MP-BGP is peering, but two sites in the same L3VPN still can't see each other's routes.
More details
Cisco · DEVASC
RESTCONF: 2xx, But Nothing Changed
A Python script pushes config over RESTCONF and returns success every run, yet the device never actually changes.
More details
Cisco · DEVCOR
Webhooks: Events Fire, Nothing Runs
The platform is sending webhook events and the receiver logs are clean, but the automation never triggers.
More details
Cisco · CBROPS
SOC Triage: The Alert That Didn't Fire
A host is beaconing out and the telemetry is in the SIEM, but the detection rule that should have caught it never triggered.
More details
Cisco · AIOps
Assurance: Red Score, Happy Users
Assurance flags a switch red while its users are fine, and a genuinely degraded uplink shows healthy. The model is only as good as its telemetry.
More details
Virtual Labs
Pay for time on a specific lab and drive it yourself: real Cisco, RedHat and specialized gear, booked by the session, dedicated to you for the window you book. New to a topic? Start with a guided scenario in Guided Labs. All prices are in GBP.
Implementing Cisco Enterprise Network Core Technologies
More details£449.00 for a 5-session pack
Implementing Cisco Enterprise Advanced Routing and Services
More details£449.00 for a 5-session pack
Automating Cisco Enterprise Solutions
More details£468.00 for a 5-session pack
Designing Cisco Enterprise Networks
More details£468.00 for a 5-session pack
Deploying and Configuring Cisco SD-WAN
More details£476.00 for a 5-session pack
Deploying and Configuring Cisco SD-ACCESS
More details£396.00 for a 5-session pack
Cisco SD-ACCESS Advanced
More details£468.00 for a 5-session pack
Implementing and Administering Cisco Solutions
More details£341.00 for a 5-session pack
Global Infrastructure
We understand that latency matters when you're typing into a CLI. That's why we host our high-performance EVE-NG clusters in premium data centers.
EU Primary Region
Hosted in London, UK. Optimized for low-latency access across Europe and the Middle East.
US Availability
US-East availability zones are available upon request for enterprise teams.
Bare Metal Power
We don't oversubscribe. Each lab runs on dedicated compute resources to ensure smooth nested virtualization.
Book a Demo or Get in Touch
See Catalyst Center and the labs live, ask about enterprise licensing, or request a custom topology. We reply within 24 hours.