Practice labs

CCNA & CCNP practice labs — hands-on Cisco CML scenarios

Hands-on CCNA and CCNP practice labs — OSPF, VLANs, ACLs, routing, NAT and more, each a real Cisco Modeling Labs scenario you build and grade against the answer key.

Browse the 19 free labsBrowse by theme: all practice topics or certification tracks.

Browse by track & topic
BeginnerFree2026-06-30

802.1Q Trunk Fundamentals: Static Trunk and VLANs

Build a static 802.1Q trunk between two Layer-2 switches to carry VLANs 10 and 20. Map hosts to access ports, verify trunk encapsulation and allowed VLANs, demonstrate same-VLAN reachability across the trunk, and confirm inter-VLAN isolation. Then simulate an allow-list drift fault, diagnose with show commands, and restore service.

CCNA45 min5 objectives

Free with an account

IntermediateLocked

Port Security: Violation Shutdown & Manual Recovery

Hands-on CCNA L2 switching lab: build a small campus with a distribution switch and two access switches carrying a shared user VLAN over 802.1Q trunks. Harden access ports with sticky port-security in violation shutdown mode. Intentionally seed and diagnose broken trunks/host VLANs, restore end-to-end host reachability, then trigger a port-security violation to observe err-disabled behavior and perform manual recovery.

CCNA65 min5 objectives

BeginnerLocked

CCNA Port Security 2: Sticky Secure MAC Learning

Two access-layer switches have a VLAN 20 connectivity problem: users in one wiring closet cannot reach users in the other. Diagnose and repair the issue, then deploy sticky secure MAC learning on the host-facing access ports so each port dynamically learns and persists its connected host's MAC. Verify sticky entries in show commands and confirm same-VLAN host connectivity end-to-end.

CCNA45 min4 objectives

IntermediateLocked

Port Security: Voice + Data on One Access Port

Harden a real desk port that carries both data (PC) and voice (IP phone) using switchport voice vlan and access vlan on a single access port. Apply port security with a maximum that accounts for two MAC addresses (phone + PC) so a third device is restricted. A deliberate trunk allow-list drift on the inter-switch link initially blocks the Voice VLAN; learners must repair the trunk and then verify port-security state on the desk port.

CCNA55 min6 objectives

IntermediateLocked

Port Security: Static Secure MAC Binding

Troubleshoot a Layer-2 forwarding fault that breaks a user VLAN between access/distribution switches, then implement static secure MAC binding on the client-facing access port. You will restore end-to-end VLAN 20 reachability and enforce a single authorized MAC on the user port using port-security with violation restrict.

CCNA55 min5 objectives

AdvancedLocked

CCNA Port-Sec 9: Multi-Port Sticky Restrict Policy

Advanced CCNA switchport port-security rollout on multiple access ports across two Layer-2 switches with a trunk. You will standardize a consistent edge policy (sticky MAC learning, maximum 1, violation restrict) on all host-facing access ports while leaving the uplink trunk exempt from port-security. Includes a realistic drift on the trunk allow-list and VLAN database to fix before validating end-to-end user VLAN transport. Pure Layer-2: no SVIs or routing.

CCNA58 min6 objectives

IntermediateLocked

Native VLAN Mismatch: Diagnosing a Broken Trunk with CDP

Diagnose and remediate a trunk misconfiguration between an access switch and a distribution switch so that same-VLAN hosts across two access switches can communicate end-to-end. Use CDP and trunk verification commands to investigate the fault and restore proper trunk operation, without introducing any Layer-3 routing.

CCNA45 min5 objectives

IntermediateLocked

VLAN Trunking 6: DTP and Trunk Hardening

Hands-on DTP negotiation and trunk hardening across a 3-switch path. You will observe dynamic trunking behavior (auto vs desirable), fix an allow-list drift that blocks user VLAN transport, and then harden the trunks to static with nonegotiate and a non-default native VLAN. End-to-end host reachability in the same VLAN proves success.

CCNA55 min6 objectives

IntermediateLocked

CCNA: Native VLAN & Untagged Traffic on 802.1Q

Hands-on CCNA switching lab focused on the native VLAN and tagging behavior on 802.1Q trunks. Users in one VLAN currently cannot reach their peers across a switch-to-switch trunk; you will standardize the native VLAN away from VLAN 1 to a dedicated parking VLAN, diagnose and correct the trunk configuration, verify the untagged VLAN on both ends, and confirm same-VLAN host reachability across the trunk.

CCNA55 min6 objectives

IntermediateLocked

CCNA VLAN Trunking 7: Trunking Across Three Switches

Build an end-to-end 802.1Q path across three Cisco IOS Layer-2 switches so VLAN 10 transports user traffic from an access port on the left switch to an access port on the right switch through a middle switch. Harden trunks (native VLAN 999, nonegotiate) and verify with show interfaces trunk. Then intentionally break the allow-list to see the outage and restore service.

CCNA45 min5 objectives

BeginnerLocked

Trunking Basics: Access Ports vs Trunk Ports

Hands-on CCNA switching lab contrasting single-VLAN access ports with 802.1Q trunks. You begin with the inter-switch link configured as a plain access port, so only one VLAN reaches the router-on-a-stick gateway while the other cannot. You will diagnose the connectivity problem, convert the link into a properly hardened 802.1Q trunk, and validate that both VLANs regain access to their gateway.

CCNA55 min5 objectives

AdvancedLocked

Trunk Verification & Diagnosing a Silent VLAN

An advanced CCNA switching lab focused on verifying 802.1Q trunks and diagnosing a silent VLAN after a switch refresh. The topology uses three layer-2 switches (a distribution switch between two access closets) and two Alpine hosts, and users in VLAN 20 at one closet cannot reach their VLAN 20 peers at the other closet across the trunk path. Learners use show interfaces trunk, show interfaces switchport, and show vlan brief to locate the break and restore predictable Layer-2 forwarding without adding any Layer-3 configuration.

CCNA55 min5 objectives

What's unlocked, and what's free

Subscription access, and the labs that need none.

A subscription unlocks every lab on this page for as long as it's active — the whole daily back catalogue, not just the labs published after you join, plus every series lab. Bundles and study paths aren't sold separately any more; anything bought before that change stays yours permanently, subscription or not.

Free labs need no subscription at all: every lab you can build and grade without one is the sample, plus the opening lab of each series.