Practice labs

CCNA & CCNP practice labs — hands-on Cisco CML scenarios

Hands-on CCNA and CCNP practice labs — OSPF, VLANs, ACLs, routing, NAT and more, each a real Cisco Modeling Labs scenario you build and grade against the answer key.

Browse the 19 free labsBrowse by theme: all practice topics or certification tracks.

Browse by track & topic
IntermediateLocked

DHCP Snooping Rate Limiting

Harden the Layer-2 access edge by rate-limiting DHCP messages on untrusted ports. SW1 already has DHCP snooping enabled for VLAN 10 with the uplink trusted. Your task is to apply a per-interface rate limit on the host-facing access ports to blunt DHCP starvation attacks while leaving the trusted uplink unlimited.

CCNA30 min5 objectives

IntermediateLocked

Dynamic ARP Inspection

Harden the Layer-2 access edge by enabling Dynamic ARP Inspection (DAI) on a single access switch. DHCP Snooping is already in place and the uplink toward the DHCP server/gateway is trusted. Your job: enable DAI for VLAN 10 and trust the uplink so ARP on host-facing ports is validated against the DHCP Snooping bindings.

CCNA35 min4 objectives

IntermediateLocked

Protected Ports for Host Isolation

Harden the campus access edge by isolating same-switch hosts using protected ports. You will configure switchport protected on both host-facing access interfaces so PC1 and PC2 cannot communicate at Layer 2, while all endpoints still reach the default gateway R1. This is a deterministic Layer-2 security control that mimics lightweight private-VLAN isolation on a single switch. Focus is on SW1 only; R1 and hosts are pre-provisioned.

CCNA35 min5 objectives

BeginnerFree2026-07-04

DHCP Snooping Trust Boundary

Harden the Layer-2 access edge by enabling DHCP Snooping on a single access switch and placing the trust boundary only toward the legitimate DHCP server/gateway. Validate with show commands and end-host connectivity.

CCNA30 min4 objectives

Free with an account

AdvancedLocked

Defense in Depth: DHCP Snooping + DAI

Harden the Layer-2 access edge by deploying a unified trust boundary for DHCP Snooping and Dynamic ARP Inspection (DAI) on a single access switch. R1 is both the default gateway and DHCP server for VLAN 10. You will enable DHCP Snooping and DAI globally for VLAN 10 and set the same uplink interface as trusted for both features, leaving host-facing access ports untrusted. This lab emphasizes the dependency and synergy between DHCP Snooping and DAI for blocking rogue DHCP/ARP activity. Grade scope: SW1 config only.

CCNA40 min4 objectives

BeginnerFree2026-07-04

CDP Neighbor Discovery and Edge Suppression

Enable Cisco Discovery Protocol (CDP) on R1 to map directly-connected Cisco neighbors while suppressing CDP advertisements on the untrusted management-edge interface. Routers are directly cabled for true CDP adjacency and also share a common management LAN via SW1 alongside an Alpine MGMT host.

CCNA35 min5 objectives

Free with an account

BeginnerLocked

LLDP for Multi-Vendor Discovery

Enable the open-standard LLDP on adjacent Cisco IOS routers over direct point-to-point links while also attaching the devices to a shared management LAN. Learners configure deterministic LLDP behavior (global enable plus per-interface transmit/receive) and verify neighbor discovery without adding any routing protocols or static routes.

CCNA45 min4 objectives

IntermediateLocked

Syslog Severity & Buffered Logging

Tune which syslog messages go where on Cisco IOS using severity levels: keep detailed logs locally in a 16 KB buffer, reduce console noise to warnings, and send notifications to a central server. Single management LAN, no routing. Grading focuses on three R1 commands steering severity: logging buffered 16384 debugging, logging console warnings, and logging trap notifications.

CCNA35 min5 objectives

AdvancedLocked

Discovery & Monitoring Troubleshooting Capstone

Advanced discovery and monitoring capstone, run as a fault hunt. The NMS has stopped seeing this site: neighbours are missing from the topology map, no traps are arriving, and syslog went quiet — while every device is reachable and pingable. You get symptoms and the required end state — no fault list. Faults span both routers and the switch they all peer through, and more than one of them leaves the monitoring configuration looking complete.

CCNA45 min5 objectives

BeginnerLocked

Centralized Syslog with Timestamps

Configure a Cisco IOS router (R1) to forward its logs to a central syslog server with accurate date/time and millisecond timestamps. Validate the remote host and trap level in show logging. This is Lab 4 of 10 in the Network Discovery & Monitoring series.

CCNA28 min5 objectives

IntermediateLocked

SNMP Trap Notifications to the NMS

Configure a Cisco IOS router (R1) to proactively send SNMPv2c trap notifications to a centralized NMS host. Learners practice the difference between polling and traps, add the trap destination and enable device-initiated notifications, and verify deterministically with show commands. Flat L2-only management LAN; no routing, no VLAN/STP complexity.

CCNA35 min5 objectives

IntermediateLocked

SNMPv2c Read-Only Monitoring

Configure Cisco IOS SNMPv2c read-only access on R1 so an NMS on a trusted management LAN can poll device status. You will add a read-only community string and device identity (location/contact), validate from IOS show commands, and confirm basic reachability from the MGMT host. No routing protocols or static routes are used; all devices share a single management subnet bridged by an L2 switch.

CCNA35 min4 objectives

What's unlocked, and what's free

Subscription access, and the labs that need none.

A subscription unlocks every lab on this page for as long as it's active — the whole daily back catalogue, not just the labs published after you join, plus every series lab. Bundles and study paths aren't sold separately any more; anything bought before that change stays yours permanently, subscription or not.

Free labs need no subscription at all: every lab you can build and grade without one is the sample, plus the opening lab of each series.