Practice labs

CCNA & CCNP practice labs — hands-on Cisco CML scenarios

Hands-on CCNA and CCNP practice labs — OSPF, VLANs, ACLs, routing, NAT and more, each a real Cisco Modeling Labs scenario you build and grade against the answer key.

Browse by theme: all practice topics or certification tracks.

65 labs match your filters.

IntermediateLocked

Secure Router VTY with ACL: Only Management Host Allowed

Configure a standard IPv4 ACL and bind it to the VTY lines on the HQ router so only the dedicated management host can SSH to it. Confirm that regular routed traffic between sites is unaffected, and prove both a permitted and a denied management attempt.

CCNA45 min5 objectives

IntermediateLocked

CCNA: Named ACLs & Editing by Sequence Number

Hands-on ACL practice using named standard and extended ACLs, applied with correct placement and direction, edited by sequence number, and verified with counters and end-host tests. The lab adds a realistic NAT edge to expose order-of-operations pitfalls without obscuring data-plane ACL effects.

CCNA75 min6 objectives

AdvancedLocked

ACL Segmentation Policy on Multi-LAN Router

Deploy and verify multiple IPv4 ACLs on a single router that terminates three distinct LANs (Client, Server, and Management). You will place an extended ACL inbound on the Client interface to allow only specific services to the Server and block access to Management, a standard ACL outbound on the Management interface to enforce destination-side protection by source, and a VTY access-class to restrict router SSH to the Management subnet only. Validate with end-host tests that permitted flows succeed while denied flows are provably blocked, and use ACL hit counts and logs to troubleshoot.

CCNA70 min5 objectives

IntermediateLocked

ACL App Filter: Permit SSH/HTTP, Block Telnet/ICMP

Build a two-router, one-access-switch lab with a client and a server. Establish basic IP connectivity with static routing, then implement an extended IPv4 ACL inbound on the client-facing interface to permit SSH and HTTP to the server while denying Telnet and ICMP echo. Validate from the client and review ACL hit counters for proof.

CCNA55 min5 objectives

IntermediateLocked

ACL Wildcard Masks: Match Host, Subnet, and Range

Hands-on CCNA ACL practice using standard ACLs and wildcard masks to allow a single host, a contiguous range, and an entire subnet while proving a deny. You will place the ACL near the destination, order statements correctly, verify with end-host pings and ACL counters, and troubleshoot common mistakes.

CCNA55 min5 objectives

IntermediateLocked

ACL Logging & Order: Correct Permit/Deny Sequencing

Three-router static-routing lab with two Linux endpoints. An extended IPv4 ACL is intentionally misordered inbound near the source, causing Telnet to be permitted unexpectedly. Learners must observe first-match behavior via hit counters, enable buffered logging to see ACL log entries, and then correct the ACL sequence so Telnet is blocked while SSH and ICMP are permitted. All routers include a complete SSH management plane. The final solution forwards end-to-end and is enterprise-clean.

CCNA55 min5 objectives

IntermediateLocked

CCNA: ACL Placement – Std Near Dest, Ext Near Source

Dual-router Branch/HQ lab with a branch client and an HQ server. You will apply an extended IPv4 ACL inbound near the source on the Branch LAN to block specific traffic (TCP/80) while permitting others (ICMP), and a standard IPv4 ACL outbound near the destination on the HQ LAN to admit only the approved source. Validate from real hosts, confirm ACL hitcounts, and keep inter-site connectivity via static routes over a /30 transit.

CCNA55 min4 objectives

IntermediateLocked

Voice & Data VLANs: Access + Trunk Allowed Lists

Configure a two-switch access layer with data and voice VLANs on access ports and an 802.1Q trunk between switches. Add a router-on-a-stick gateway for VLAN 10/20. Verify VLAN placement, trunk status, and observe a connectivity failure caused by an allow-list misconfiguration on the inter-switch trunk—then correct it to restore intra-VLAN reachability.

CCNA65 min6 objectives

AdvancedLocked

Multi-VLAN Segmentation: 3 VLANs & Trunk Alignment

Hands-on CCNA campus switching lab with two Layer-2 switches and three VLANs (Users 10, Servers 20, Management 99) extended over a single 802.1Q trunk. Learners deploy VLANs and access ports, harden the trunk (native VLAN 999, explicit allow-list, nonegotiate), and validate isolation. The lab ships with a trunk-carried outage: VLAN 10 traffic reaches its gateway successfully, but VLAN 20 traffic does not. You will diagnose from end hosts, confirm switch states, and correct the trunk so that same-VLAN traffic to the gateway SVI succeeds while inter-VLAN forwarding remains absent.

CCNA75 min5 objectives

IntermediateLocked

CCNA: VLAN DB & Trunk Allow-List Drift Recovery

Hands-on CCNA VLAN lab: build VLANs with names, assign access ports, harden and verify 802.1Q trunks, and troubleshoot a broken allow-list that prevents a VLAN from traversing the SW1–SW2 trunk. Includes router-on-a-stick gateways, management VLAN, and end-host validation.

CCNA65 min7 objectives

IntermediateLocked

Extending VLAN 10 Across Two Switches (802.1Q)

Build and verify an 802.1Q trunk between two access switches that cleanly transports VLAN 10 end-to-end while intentionally pruning VLAN 20. You will configure access ports, create VLANs, set a hardened dot1Q trunk with a non-default native VLAN, and validate host reachability and isolation from endpoints.

CCNA55 min5 objectives

BeginnerLocked

VLAN Segmentation: Broadcast-Domain Isolation

Build VLANs across two access switches with an 802.1Q trunk and a router uplink. Verify that hosts in the same VLAN can communicate (even across switches) while hosts in different VLANs cannot. Then troubleshoot a failure caused by a trunk allow-list misconfiguration.

CCNA55 min5 objectives

What's unlocked, and what's free

Subscription access, and the labs that need none.

A subscription unlocks every lab on this page for as long as it's active — the whole daily back catalogue, not just the labs published after you join, plus every series lab. Bundles and study paths aren't sold separately; the subscription is the only plan.

Free labs need no subscription at all: every lab you can build and grade without one is the sample, plus the opening lab of each series.