CCNA & CCNP practice labs — hands-on Cisco CML scenarios
Hands-on CCNA and CCNP practice labs — OSPF, VLANs, ACLs, routing, NAT and more, each a real Cisco Modeling Labs scenario you build and grade against the answer key.
Troubleshoot a branch network where an ACL intended to block Telnet ended up blocking everything because it was never applied, and the branch router also lacks a route to the server. Diagnose from the client’s perspective, verify hop-by-hop reachability, and then place the ACL where it will see the traffic while preserving the intended deny. Finish by restoring end-to-end connectivity for all traffic except Telnet to the server.
Daily CCNA troubleshooting lab (repair-focused). Inside clients cannot reach an external destination even though PAT appears configured. Diagnose by reading the NAT table and interface roles, discover that translation isn’t triggering because the NAT boundary is undefined, and restore outbound reachability by correctly marking both sides.
A branch LAN’s clients can’t obtain IP addresses even though the DHCP server at the hub is up and reachable. Diagnose where the broadcast-to-unicast relay path breaks and restore end-to-end DHCP lease delivery while preserving the rest of the clean, working design.
Daily CCNA troubleshooting repair lab. Two routers share a /30 transit link and both run OSPF process 1 with explicit router-ids. IP connectivity over the transit is fine, but the OSPF adjacency never forms and remote routes are missing. Your job: work the neighbour state without changing working addressing or adding static routes. Bring the OSPF peering to FULL so the branch LAN appears on the core router.
Daily CCNA troubleshooting lab focused on Spanning Tree root bridge selection. A fully working campus access/distribution triangle forwards traffic, but the wrong switch is root for VLAN 10 and VLAN 20, forcing an inefficient path. Diagnose with show commands and repair by influencing the election without creating a loop.
A compact two-switch, two-host CML lab focused on troubleshooting an 802.1Q trunk. One VLAN traverses the trunk, another does not. Learners must read trunk state on both ends, compare against the intended design, and correct the mismatch without disrupting the working VLAN. Includes a second subtle trunk hygiene fault (native VLAN mismatch) that must be standardized.
Build an enterprise-clean dual-stack site end-to-end. IPv4 is complete and forwarding on day start; you will deploy IPv6 across the same topology. Enable IPv6 routing, assign prefixes, bring up OSPFv3 with explicit router-ids, keep the access LAN autoconfiguring via SLAAC with stateless DHCPv6 for DNS, and enforce an IPv6 ACL to allow one client flow to the server while denying another. Verify from the hosts and troubleshoot like a real operator.
A dual-stack enterprise tri-router line with two LANs and end hosts. IPv4 routing is healthy and end-to-end; IPv6 addressing is present but end-to-end IPv6 fails. Work from operational state only to isolate and correct the broken IPv6 control/forwarding plane without changing what already works. The graded end-state requires IPv6 forwarding enabled on all routers, OSPFv3 process 10 in area 0 with an explicit unique router-id on every router, and per-interface activation on all required links so the hosts can ping6 across the WAN.
Harden a dual-stack access segment with IPv6 RA Guard so only the legitimate router can advertise a default gateway. You will start from a working IPv4 baseline with IPv6 SLAAC enabled, then implement and verify RA Guard on the access switch. The solution must keep end-to-end IPv4/IPv6 reachability while blocking rogue Router Advertisements from a malicious host.
Build a dual-stack branch-to-datacenter topology with IPv6 static routing in place. Implement a named IPv6 ACL on the server-facing interface that permits an approved client while denying an unapproved source, and explicitly permits Neighbor Discovery (ND) so the LAN continues to function. Verify that the allowed source can reach the server over IPv6 while the unapproved source fails, without disrupting IPv6 neighbor resolution.
Deploy a stateless DHCPv6 service on a remote router and relay client Information-Requests from a branch LAN across a routed core to that server. IPv4 is already fully functional; your job is to build the IPv6 DHCPv6 relay path and confirm clients receive DNS/domain options while keeping IPv6 addressing via SLAAC.
Build a compact branch LAN where IPv6 hosts already form SLAAC addresses from router advertisements, then add stateless DHCPv6 to supply DNS server and domain-name. You will keep SLAAC for addressing, flip the RA 'other-config' flag so hosts know to ask, and bind an IPv6 DHCP pool with DNS options to the user LAN. IPv4 is prebuilt as a baseline and must keep forwarding. Verify from hosts and the router’s IPv6 DHCP/ND views.
A subscription unlocks every lab on this page for as long as it's active — the whole daily back catalogue, not just the labs published after you join, plus every series lab. Bundles and study paths aren't sold separately any more; anything bought before that change stays yours permanently, subscription or not.
Free labs need no subscription at all: every lab you can build and grade without one is the sample, plus the opening lab of each series.