AdvancedPublished 2026-07-26
CCNA: Secure Branch Edge Capstone (ACL/PAT/DHCP/SSH)
Archive lab
One-branch edge capstone that unifies DHCP for the LAN, PAT overload to an Internet server, an extended ACL that permits HTTP but denies SSH, and SSH-only management. The starting lab intentionally contains multiple faults across DHCP, NAT, and SSH so you must diagnose and repair the edge to achieve full end-to-end verification from the client.
Learning objectives
- Deploy and verify a DHCP pool on the branch edge to serve the LAN
- Configure PAT (NAT overload) to reach an Internet web server
- Author and correctly place an extended ACL to permit HTTP while denying SSH from the LAN
- Harden remote access by enabling SSH-only local authentication on the edge
- Troubleshoot multiple, independent misconfigurations across NAT, ACL, DHCP, and SSH to restore end-to-end service
Troubleshooting focus
- Identify NAT inside/outside role reversals that prevent translations
- Detect a DHCP pool with an incorrect default gateway handed to clients
- Recognize an incomplete SSH management plane (missing RSA keys/domain) that blocks remote login
- Place the extended ACL inbound at the source LAN and order ACEs so required control/management (DHCP, SSH-to-edge) is not broken
- Prove resolution with translation table entries, ACL hit counters, and successful host-initiated tests
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.