Find the scenario you want to
Choose a certification collection, then narrow by topic, difficulty, or format. Every lab begins with a real symptom and ends with a verified repair.
Cisco Catalyst Center
The controller almost no one can home-lab: Cisco's own appliance alone needs 32 vCPUs and 256GB of dedicated RAM just to boot. We are preparing it for launch so you can build SD-Access fabrics, explore Assurance telemetry, and automate with the Intent APIs.
- SD-Access fabric provisioning
- Assurance & telemetry
- Plug-and-Play onboarding
- REST / Intent API automation
Filter the catalog
Showing 94 labs
CCNA · 200-301
FreeSpanning Tree: Root Bridge Election
A free, ungated example lab: a misconfigured root bridge sends traffic the long way round. No email required to see the fix.
Start lab
CCNA · 200-301
CCNA Configuration Foundations
Build an end-to-end client path across a VLAN, trunk, router gateway, route, and access policy.
More details
CCNA · 200-301
CCNA Final Challenge Lab
Restore a client path, enforce its access policy, and prove the result across three simulated devices.
More details
CCNA · 200-301
VLANs, Trunking & Spanning Tree
802.1Q trunks and native VLANs, STP root election, and inter-VLAN routing on a switched campus.
More details
CCNP · ENARSI
OSPF Multi-Area & Redistribution
Areas and LSA types, route summarization, and controlled redistribution between OSPF and EIGRP.
More details
CCNP · ENARSI
Mutual Redistribution & Route Tagging
Two ASBRs mutually redistribute OSPF and EIGRP on the same ring. Learn why that creates route feedback, and how tagging and seed metrics keep it under control.
More details
CCNP · ENARSI
BGP Peering & Path Selection
eBGP and iBGP sessions, the best-path algorithm, and policy via local-preference, AS-path and communities.
More details
CCNA · 200-301
OSPF Neighbor Down: Area Mismatch
Two routers ping each other fine across a direct link, but their OSPF adjacency refuses to form. Work it from Layer 3 up to the routing protocol.
More details
CCNA · 200-301
Static Route: Wrong Next Hop
A static-route command names an unreachable next hop, so its prefix never reaches the routing table. Inspect the configuration, repair it, and prove the remote LAN is reachable.
More details
CCNA · 200-301
VLAN Access Port: Wrong VLAN
A user reaches the switch but lands in the wrong broadcast domain. Trace the access VLAN, correct it, and prove same-VLAN reachability.
More details
CCNA · 200-301
STP Edge Port: Missing BPDU Guard
An access port is configured for fast startup but has no loop protection. Apply the right edge safeguards and verify the operational state.
More details
CCNA · 200-301
Inter-VLAN Routing: SVI Down
VLANs exist and trunks are up, but hosts cannot reach their gateway. Find why the SVI is down and restore inter-VLAN routing.
More details
CCNA · 200-301
OSPF: Passive Interface Surprise
A router advertises a subnet but never forms the intended adjacency. Identify the passive-interface scope and restore only the required OSPF hello traffic.
More details
CCNP · ENARSI
EIGRP Neighbor Down: AS Mismatch
Two routers connect over a live link and ping fine, but their EIGRP neighbor adjacency never forms. The configuration looks right at first glance.
More details
CCNA · 200-301
Access Control Lists: Configuring & Verifying
PC1 can't reach a server through R1, and the router is sending back an explicit deny, not a timeout. The permit entry meant to allow it is right there in the ACL.
More details
Palo Alto · PCNSE
NGFW Zones, NAT & App-ID
Security zones, source/destination NAT, App-ID security policies and SSL decryption on PAN-OS.
More details
Fortinet · NSE 4
FortiGate Policy & IPsec VPN
Firewall policies, SD-WAN rules and a site-to-site IPsec tunnel between two FortiOS gateways.
More details
Check Point · CCSE
Security Policy & Identity Awareness
Ordered policy layers, NAT rules and Identity Awareness on a Gaia gateway managed from SmartConsole.
More details
Cisco SD-WAN · Viptela
Cisco SD-WAN (Viptela)
Stand up the vManage/vSmart/vBond control plane and bring a WAN edge under management over a live overlay.
More details
RHCSA · EX200
Linux Firewalld & iptables Policy
Zone-based firewalld policy, iptables/nftables rule chains, and troubleshooting a host that's silently dropping traffic.
More details
RedHat · RH294
Ansible Playbook Automation
Write and run real Ansible playbooks against multiple managed hosts: inventories, roles, idempotent tasks and ad-hoc modules.
More details
CCNP · DCINX9K
Nexus 9000 NX-OS Switching
vPC domains, peer-links and standalone NX-OS switching on real Nexus 9000 gear, not the ACI-mode UI.
More details
CCNP · ENARSI
BGP Route Reflector Scaling
Replace a full iBGP mesh with route reflectors and clusters: clients, non-clients, and cluster-ID loop prevention.
More details
Security · Zero Trust
Zero Trust: JWT Access & Token Expiry
Never trust, always verify: explicit auth, least-privilege endpoints and short-lived JWTs that fail closed the moment they expire.
More details
Cisco · SVPN
GRE VPN Endpoint Migration
Cut a live site-to-site GRE tunnel over to new ISP IPs with minimal downtime, keeping DNS, LDAP and web reachable across both sites.
More details
Linux · RHCSA
Linux Namespaces & veth Routing
veth pairs, network namespaces and inter-subnet routing, the primitives Docker and containerlab use to wire every container.
More details
Cisco · SPCOR
MPLS L3VPN: Customer Routes Missing
The MPLS core is up and MP-BGP is peering, but two sites in the same L3VPN still can't see each other's routes.
More details
Cisco · DEVASC
RESTCONF: Green Runs, No Change
A Python script pushes config over RESTCONF and reports success every run, yet the device never actually changes.
More details
Cisco · DEVCOR
Webhooks: Events Fire, Nothing Runs
The platform is sending webhook events and the receiver logs are clean, but the automation never triggers.
More details
Cisco · CBROPS
SOC Triage: The Alert That Didn't Fire
A host is beaconing out and the telemetry is in the SIEM, but the detection rule that should have caught it never triggered.
More details
Cisco · AIOps
Assurance: Red Score, Happy Users
Assurance flags a switch red while its users are fine, and a genuinely degraded uplink shows healthy. The model is only as good as its telemetry.
More details
CCNA · 200-301
EtherChannel: LACP Mode Mismatch
A two-link uplink should bundle, but each member remains individual. Compare both ends, correct the LACP mode, and verify the port channel.
More details
CCNA · 200-301
NAT Overload: ACL Selection Error
Inside users reach the router but never the internet. Trace the NAT ACL, correct its wildcard mask, and verify live translations.
More details
CCNA · 200-301
IPv6 SLAAC: Prefix Not Advertised for Autoconfiguration
Hosts generate link-local addresses but never receive global IPv6 connectivity. Find the missing RA configuration and validate SLAAC end to end.
More details
CCNA · 200-301
DHCP Relay: Missing Helper Address
A remote VLAN broadcasts DHCPDISCOVER but the centralized server never sees it. Configure and verify relay forwarding with ip helper-address.
More details
CCNA · 200-301
DHCP Snooping: Trust Boundary Misconfiguration
One access switch can't reach the DHCP server. Trace the trust setting on each uplink to find the port silently dropping server replies.
More details
CCNA · 200-301
IPv4 VLSM: Overlapping Subnets
A new subnet is added for growth but routing behaves unpredictably. Calculate the correct VLSM boundary and remove the overlap.
More details
CCNA · 200-301
Extended ACL: Direction and Placement
The ACL syntax is valid, yet return traffic fails. Determine the correct interface direction and placement for the policy.
More details
CCNA · 200-301
NTP: Wrong Source Interface
Clients can reach the time server, but authentication or ACL checks reject synchronization. Set a stable NTP source and verify stratum.
More details
CCNA · 200-301
IPv6 Static Route: Invalid Next Hop
An IPv6 prefix is configured but absent from the routing table. Inspect recursive resolution, correct the next hop, and verify the remote LAN.
More details
CCNA · 200-301
IPv6 Neighbor Discovery: Default Gateway Failure
Hosts have a global IPv6 address but cannot leave the LAN. Diagnose router advertisements and the default-router lifetime.
More details
CCNA · 200-301
HSRP: Priority and Preempt
The backup gateway is active after recovery even though the preferred router is healthy. Read HSRP state, priorities, and preempt behavior.
More details
CCNA · 200-301
HSRP: Missing Uplink Tracking
The active gateway remains reachable locally after its WAN fails, blackholing client traffic. Configure object tracking so HSRP fails over on the real fault.
More details
CCNA · 200-301
Port Security: Violation and Err-disabled Recovery
A replacement PC takes the desk offline instantly. Read the secure address table, find the MAC still pinned there from the last machine, and recover the port properly.
More details
CCNA · 200-301
Dynamic ARP Inspection: Untrusted Uplink
Turning on ARP inspection broke the very traffic it was meant to protect. Find the interface that should have been trusted and read the drop counters that prove it.
More details
CCNA · 200-301
VTP: VLANs That Never Reach the Other Switch
One switch has the VLANs, the other has never heard of them, and the trunk between them is perfectly healthy. Fix the domain, then work out why that alone changes nothing.
More details
CCNA · 200-301
DTP: The Trunk That Never Negotiated
Two switches, one cable, and no trunk. Both ends are perfectly willing to trunk and neither one will ask. Read both sides of the link before you change anything.
More details
CCNA · 200-301
STP Root Guard: One VLAN Blocked on a Healthy Trunk
A trunk is up, the port is up, and every VLAN crosses it except one. Find the root-inconsistent port, work out what root guard is protecting you from, and fix the cause instead of silencing the alarm.
More details
CCNA · 200-301
Trunk Allowed VLANs: A Silently Pruned VLAN
A newly created VLAN works on each switch but not between them. Read the trunk's allowed list and add the VLAN without wiping the ones already there.
More details
CCNA · 200-301
SSH Remote Access: Enabling It Properly
Telnet works, SSH is refused, and generating a key returns an error. Build the four prerequisites SSH actually needs, in the right order, then close Telnet off.
More details
CCNA · 200-301
Voice VLAN: Phone Has No Service
The PC works through the phone, but the phone never joins its voice network. Restore the tagged voice path without breaking the data VLAN.
More details
CCNA · 200-301
Floating Static Route: Wrong Administrative Distance
A backup path is load-sharing with the primary because both static routes have the same distance. Make the backup float until it is needed.
More details
CCNA · 200-301
Static NAT: Port Forward Has No Inside Interface
The translation exists, but inbound TCP 8080 never reaches the server. Trace the NAT roles and repair the server-facing path.
More details
CCNA · 200-301
DHCP Pool: Excluded Range Exhaustion
The binding table is empty, but a /24 pool has only four addresses available. Find the reservation that consumed the scope.
More details
CCNA · 200-301
SNMP: Community ACL Blocks the NMS
The community is configured, but the NMS times out. Follow its source ACL and correct the permitted management subnet.
More details
CCNA · 200-301
Syslog: Severity Threshold Hides Events
Interfaces changed and configurations were saved, but no one saw the messages. Interpret the threshold direction and restore event visibility.
More details
CCNA · 200-301
VTY Access Class: Locked Out of Management
The router is reachable, but every management session is refused. Trace both VTY admission controls and restore SSH from the correct subnet.
More details
CCNA · 200-301
Trunking: Native VLAN Mismatch
A trunk is up and passing most VLANs, but one VLAN's traffic lands in the wrong broadcast domain. Trace the untagged path across the link.
More details
CCNA · 200-301
Router on a Stick: Missing Encapsulation
Subinterfaces are addressed and up, yet one VLAN has no working gateway. Work out which half of the subinterface configuration is missing.
More details
CCNA · 200-301
OSPF: Hello and Dead Timer Mismatch
Two routers share a subnet and the same area, but no adjacency ever forms. Compare the per-interface timers that must agree.
More details
CCNA · 200-301
OSPF: Reference Bandwidth Mismatch
Every adjacency is FULL and every route is present, but traffic takes a slow path in one direction. Compare how each router costs the same links.
More details
CCNA · 200-301
OSPF: DR and BDR Election on a Shared Segment
The wrong router won the designated router role on a multi-access segment, and raising its priority afterward changed nothing. Find out why.
More details
CCNA · 200-301
Summarization: Invalid Block Boundary
A summary route was configured to replace four specific prefixes, but it covers the wrong range and blackholes traffic. Check where the block actually starts.
More details
CCNP · ENARSI
BGP Local Preference: Leaving by the Wrong ISP
Both sessions are up and both paths are valid, and all the production traffic is going out over the cheap backup circuit. Every earlier tiebreak is level, so the decision fell all the way to the bottom of the algorithm.
More details
CCNA · 200-301
CDP and LLDP: The Neighbour That Is Not There
Three devices are cabled in and only two appear in the neighbour table. The cable is fine, the port is fine, and no amount of CDP will ever reveal the third one.
More details
CCNA · 200-301
No Gateway of Last Resort
Every internal subnet is reachable and nothing at all on the internet is. The ISP link is up and pings fine, and the router is doing exactly what it was told to do.
More details
CCNA · 200-301
DTP: The One Negotiation Combination That Silently Does Nothing
Both switchports are up, but the link never becomes a trunk. Diagnose why VLAN 1 works while VLANs 10, 20, and 99 stop at the boundary, then fix the one passive DTP combination.
More details
CCNA · 200-301
Duplex Mismatch: The Link That Works Badly
The uplink is up, forwarding, and dreadful. No alarm has fired because nothing has failed, and only one of the two settings people reach for is actually to blame.
More details
CCNP · ENARSI
EIGRP Variance: The Second Path That Never Loads
A perfectly good backup path sits in the topology table and never reaches the routing table. Variance is the feature that admits it, and there is one condition it will never override.
More details
CCNA · 200-301
IOS DHCP Server: The Pool That Leased the Gateway
Most clients on the subnet are perfectly fine. One has an address conflict, and the reason is that the pool was allowed to hand out the router's own gateway address.
More details
CCNP · ENARSI
IP SLA Tracking: The Brownout a Floating Route Cannot See
The interface stays up, so the primary route never withdraws and the backup never installs. The site is offline while the routing table looks exactly as it was designed to look.
More details
CCNA · 200-301
IPv6 EUI-64: The Address Nobody Configured
The documented address does not answer and the interface is perfectly healthy. The router built its own address out of the hardware, and whoever wrote the record guessed.
More details
CCNA · 200-301
NAT Overload: A Perfect Mapping That Never Translates
A standard ACL and a correct PAT overload rule are already present. Find the missing interface role that leaves every LAN flow untranslated, then repair it in a live Cisco-style shell.
More details
CCNA · 200-301
OSPF DR Election: The Wrong Router Won
The least capable router on the segment is the Designated Router, and raising the intended router's priority changes nothing at all. There is a second half to this fix that most people miss.
More details
CCNA · 200-301
OSPF Stuck in EXSTART: IP MTU Mismatch
The neighbour appears, the link pings, and the adjacency never reaches FULL. Every parameter a Hello carries already matches, so the fault has to be somewhere Hellos never look.
More details
CCNA · 200-301
SSH Refused: VTY Transport, RSA Keys and Local Login
The router answers ping and refuses every SSH connection. Nothing is wrong with the network path, and three separate things are wrong with the management plane.
More details
Windows · Command Prompt
Windows CMD: Release and Renew a DHCP Lease
A laptop kept an address from the old office network. Inspect its lease, release it, renew it, and verify the new configuration.
More details
Windows · Command Prompt
Windows CMD: Diagnose DNS and Flush the Client Cache
An internal name still resolves to an old address. Compare cached and authoritative answers, clear the cache, and query again.
More details
Windows · Command Prompt
Windows CMD: Ping, Tracert, and Pathping
A remote app is slow. Test the local gateway, trace the path without DNS delays, then measure loss by hop.
More details
Windows · Command Prompt
Windows CMD: Read ARP and the Routing Table
The host can reach its subnet but not remote networks. Correlate the gateway's ARP entry with the default route.
More details
Windows · Command Prompt
Windows CMD: Find a Listening Port with Netstat
A local web service should listen on TCP 8080. Use netstat to find the listener and map its PID to a process.
More details
Windows · PowerShell
PowerShell: Inspect IP Configuration as Objects
A machine has several adapters. Use NetTCPIP cmdlets to isolate the connected interface and its IPv4 address.
More details
Windows · PowerShell
PowerShell: Test-NetConnection and TNC
Ping succeeds but HTTPS fails. Test the exact TCP port, inspect route diagnostics, and use the built-in tnc alias.
More details
Windows · PowerShell
PowerShell: Resolve-DnsName and Clear the Cache
Compare cache-only and server-specific DNS answers, clear the client cache, and confirm the current A record.
More details
Windows · PowerShell
PowerShell: Recover a Disabled Network Adapter
Ethernet is disabled. Inspect adapter state, enable only the affected interface, and verify link status.
More details
Windows · PowerShell
PowerShell: Inspect and Remove a Bad Route
A stale host route diverts one server through an offline VPN. Find the exact prefix and remove only that route.
More details
Windows · PowerShell
PowerShell: Trace a TCP Connection to Its Process
Find established HTTPS connections, select one owning PID, and identify the process object behind it.
More details
Linux · Networking
Linux: Inspect Addresses and Bring a Link Up
An Ethernet interface has the correct address but is administratively down. Read link and address state, then bring it up.
More details
Linux · Networking
Linux: Diagnose and Replace a Bad Default Route
Local traffic works, but the default route points to the wrong gateway. Inspect route selection and replace it.
More details
Linux · Networking
Linux: Ping and Trace the Network Path
A remote service is intermittent. Bound the ping count, test the gateway, then trace the path and MTU.
More details
Linux · Networking
Linux: Diagnose DNS with Dig and Resolvectl
The system resolver returns a stale record. Compare resolver state with a direct DNS query, flush caches, and verify.
More details
Linux · Networking
Linux: Find Listening Ports and Processes with ss
A web service is unreachable. Check whether anything listens on TCP 8080 and identify its process.
More details
Linux · Networking
Linux: Inspect and Refresh the Neighbour Cache
The gateway's cached MAC is stale. Inspect neighbour state, delete one entry, trigger resolution, and verify.
More details
Linux · Networking
Linux: Release and Renew a DHCP Lease
A dhclient-managed host kept an old lease. Inspect the live configuration, release the lease, request a new one, and verify.
More details