Product updates
Changelog
New features, fixes, and announcements.
Latest updates
The guide inside your CML topology is now rebuilt from the real guide
Every lab topology carries a copy of the guide in its notes, so you can read the tasks inside CML without switching windows. That copy was written once when the lab was created and never updated — so it drifted. It was not a small drift. One lab's guide told you the topology "arrives already configured — and already broken" while its notes still promised a deliberately unconfigured one. Three others were still printing summary routes and subnet masks in the notes that had just been removed from the guide for giving away the answer. That copy is now rebuilt from the guide every time a lab is packaged, so the two cannot disagree. Every lab in the catalogue has been repackaged. The surrounding sections — learning objectives, the verification checklist, the troubleshooting notes — are untouched; those are generated fresh already. A small number of labs whose notes use a different text format are skipped rather than reformatted, because rewriting them would reflow the text into an unreadable block.CCNP removed from the labs themselves, not just their web addresses
Details
Last week's change renamed 25 CCNA-path labs whose web address began `ccnp-`. It moved the address and the filenames and left every readable reference in place — so importing the topology into CML still put "CCNP Lab 6: IPv6 Global Unicast Addressing" on your screen, in the one place you were guaranteed to look, and a "CCNP" topic chip was still showing on the lab page. That is now swept properly: 69 references across topic tags, lab summaries, topology titles and topology descriptions, on 25 labs — including several that never had a `ccnp-` address at all but still carried the tag. Each topology's title is now taken from the lab's own title, so the two cannot disagree again. Re-download any of these to get a topology that names itself correctly on import.Labs in the CCNA path no longer have CCNP in their address
Details
Twenty-five labs sitting in the CCNA Complete Path had a URL beginning `ccnp-` — for example `ccnp-lab-6-ipv6-global-unicast-addressing`. The certification badge on each lab page was already correct; the address was a leftover from how the labs were generated. But the address is what you see in the browser and in the name of the zip you download, and the reasonable conclusion is "this is above the CCNA blueprint, I can skip it" — on material that is squarely CCNA. The prefix has been removed rather than swapped for `ccna-`: several of these labs are genuinely on both blueprints, and the address should not be re-stating something the page already says properly. Affected labs include point-to-point /30 and /31 links, secondary addressing, the IPv6 addressing series, the IP addressing capstone, HSRP/VRRP labs, the NTP series, AAA, SSH hardening and SNMPv3. Old links, bookmarks and search results still work — every previous address permanently redirects to the new one.No more "optional" tasks that the grader charges you for
Details
Two labs described work as optional and then scored it. Because a lab score is a weighted fraction of every check, a learner who took the guide at its word lost marks and was never told which word cost them. On IPv6 Global Unicast Addressing, task 5 was headed "(Optional practice)" and had a live rubric check — skipping it cost 5%. It is now simply task 5, stated the same way in the guide, the checklist and the notes attached to the topology. On OSPF Day 6, the guide already required setting `ip ospf network point-to-point` on the four loopbacks and listed it in the completion checklist — but four rubric labels still read "(optional)", so anyone who missed them saw the word "optional" next to the checks that failed them. The wording is gone. Nothing about how these labs are scored changed, and no existing result was recalculated.Fixed: 13 labs whose routers came up misconfigured
Details
Thirteen labs shipped a starter config whose first two commands were collapsed onto one line: hostname RTR-SITEA-EDGE no ip domain lookup IOS takes one argument for `hostname`, so the device either rejected the line or took a wrong hostname — and `no ip domain lookup` never ran with it, which is also why a typo at those consoles hung for half a minute trying to resolve it. Reported as "the routers don't configure properly", which is exactly what it was. Affected: IPv6 Global Unicast Addressing, Static NAT with an ISP, two port-security labs, Router-on-a-Stick (both the day-4 lab and the multi-department campus one), DHCP from two pools, EtherChannel load balancing on VLAN 60, the SSH/VTY troubleshooting capstone, EIGRP manual summarization, protected ports, trunk-and-access ports, and SSH access fundamentals. On the IPv6 lab this was costing marks twice over: its rubric checks for `hostname` and `no ip domain lookup`, and both failed on a config we shipped broken. Re-download any of these to get the corrected topology.Badge unlock no longer sits crooked on the grade result
Details
When a lab pass earned you a badge, the unlock card was pressed flush against the submit button above it while keeping a full gap below — so the one moment the site is supposed to celebrate looked wedged in. It now uses the same spacing above and below as the rest of the grading card, and the card's own internal spacing runs on a single step instead of three slightly different ones.Six labs no longer print the answer they ask you to work out
Details
If a lab asks you to subnet a /24, size a VLSM plan, or calculate a summary route, the guide should not then print the result. On six labs it did. The clearest example was CCNA Lab 2. Its addressing plan says "you must derive the /26 mask and every interface address" — and the Tasks section directly below listed all five host addresses the grader looks for. The VLSM lab did the same thing, which was worse for being deliberate: that lab uses loopbacks instead of hosts specifically to avoid revealing the answer, and a later change printed all four addresses anyway. Fixed on: - CCNA Lab 2: Subnet a /24 into Four /26s - CCNA Lab: VLSM Right-Sizing from One /24 - CCNA Static Routes: Manual Summarization - CCNA Foundations: OSPF Day 6 — Route Summarization at the ABR - Static Routing Capstone: Two Sites Over a /30 WAN - ACL Wildcard Masks: Match Host, Subnet, and Range The answers are gone from all four places they were living: the guide, the PDF, the notes attached to the CML topology, and — on two labs — the topology diagram itself, which had the summary route printed on it as a label. What replaced them is the requirement rather than the result. The wildcard lab's checklist used to read `permit 10.10.10.64 0.0.0.15`; it now reads "a permit whose wildcard matches those 16 addresses exactly — nothing above .79, nothing below .64". You can still check your own work against it. You just can't copy it. Nothing about grading changed. Every one of these labs has a deterministic allocation rule — lowest usable host per link, largest-to-smallest VLSM, the aggregate that exactly covers the listed networks — so following the rule still lands on the value the grader wants. Labs where the addressing is given to you as a specification are untouched: those numbers are the requirement, not the answer, and removing them would fail people for no reason. Scores already earned are unaffected. If you downloaded any of these six before today, re-download to get the corrected guide.Labs now carry a version, so a changed lab can't quietly cost you marks
Details
The file you import now carries a version — a short code like `gf-527bf0c8` — and the guide prints it next to the submit link. When you grade, we read the version out of your upload and compare it against the current one. If they differ, your result says so: you built one version, the lab is now on another. Your score still stands and still counts — this is not a rejection, and you are not blocked. It exists because the alternative is worse. A lab gets a rubric correction while you are part-way through it, you upload, you lose a mark against a check your download never described, and nothing on the page explains why. That reads like your mistake, and it isn't one. The version only moves when something that can actually change your score changes: a graded check, the pass threshold, or the configuration the lab starts you with. Rewriting a sentence in a guide, retitling a lab or redrawing a topology leaves it alone. A warning that fires for cosmetic edits is one you would learn to ignore, and this week alone the guides were rewritten across the catalogue without a single rubric moving. One gap worth knowing about. The version can only be read from packages downloaded from today onward — an older download carries no version, so the grader treats it as unknown rather than stale and says nothing. If a lab has been sitting in your downloads folder for a while, download it again before you grade it. Everything published is already re-stamped, so a fresh download is all it takes.
August 2026
13 updates
Printable checklists have a box you can actually tick
Details
In the PDF, every completion-checklist item began with the characters "[ ]". That is markdown's way of writing a checkbox, and it works in the markdown copy — but printed, it is just punctuation, and you cannot edit a PDF with a pen. The PDF now draws a real empty square for each item. The markdown guide keeps "- [ ]" so it still ticks in an editor.Diagram labels now tell you which VLANs a trunk carries
Details
Link labels on the topology were cut to fit, and the cut fell in the wrong place. "802.1Q trunk (VLANs 10,20,99)" arrived as "802.1Q trunk (VLANs 1…" — on 21 cables across the catalogue. The words "802.1Q trunk" are the least surprising thing on a link between two switches; the VLANs it allows are the reason to look at it. A trunk label now names the type once and spends the room on the numbers: "Trunk · VLANs 10,20,99". Other labels break on a word instead of mid-word, and a trailing aside is dropped cleanly — "VLAN 10 access (untagged, CLIENT-A)" now reads "VLAN 10 access" rather than "VLAN 10 access…". 89 shortened labels across 64 diagrams are down to 4, and those four are honest: the allow-list really is longer than the cable. One mislabel turned up while fixing this, on the EtherChannel lab. The spare third link — the one the lab asks you to add to the bundle — was drawn as "Po1 · trunk 1", claiming both that it was already in the port-channel and that it carried VLAN 1. Neither was true. It now reads "802.1Q trunk": a cable waiting to be bundled, which is where the lab starts.Topology diagrams: switches joined by a bundle now sit on the same row
Details
If a lab bundled two switches together — an EtherChannel, a port-channel, any pair of switches with more than one cable between them — the diagram could draw them on different rows. Today's daily lab was the clearest case: SW-DC-DIST1 sat in the distribution row while SW-DC-DIST2, its partner at the other end of a three-cable bundle, sat down in the access row beside the access switch. That is a hierarchy the topology does not have, and it made the bundle itself hard to follow. The three member links were drawn stretching across a tier boundary, so their labels piled onto one line — two of them reading identically and one cut short — and you could not tell which label belonged to which cable. The cause was a layout rule that asked each switch on its own whether it had a host hanging off it. A distribution switch that also serves a client was held down while its partner rose. Two switches cabled together more than once are a pair by definition, so they are now levelled onto the same row. 14 labs have a switch-to-switch bundle; 3 pairs were being split, and none are now. All 327 diagrams were re-rendered, so the copy in your downloaded package matches.Task steps read like instructions instead of a form
Details
Every step in every lab was labelled What / Why / Watch for, so a five-step section said "What:" and "Why:" five times each on the way down the page. It read like a form, and it made the steps wordier than they needed to be. The "What:" label is gone. A bullet under a numbered step is the instruction — announcing it added a word and no information, and it was also why a few steps ended up saying "What:" twice in a row. "Why:" and "Watch for:" are still there, at most once each, now set in bold so they read as notes attached to the step rather than as more prompts to answer. The steps you carry out are now marked differently from the notes you read. An action is a dash, a note is a bullet — in the printable PDF as well as the markdown — so you can see at a glance which lines are work and which are context, without reading them first. 921 labels came out across 197 labs and the guides got shorter. Nothing changed about what the steps ask you to do.Guides: commands look like commands, and troubleshooting starts with the symptom
Details
A pass over every guide for the small things that made a lab harder to work from than it needed to be. Commands in Verification and Troubleshooting were written as ordinary prose, so you had to read the sentence to find where the command started and stopped. 960 of them are now set as commands. Troubleshooting was filed under the cause — "Area mismatch:", "Passive interfaces:" — which is the answer you do not have yet. You arrive with a symptom. 151 sections now open with the thing you actually see: "No OSPF adjacency forms on a transit", "HOST-A-CLIENT cannot ping 10.20.1.10". Find your symptom, read one bullet. Verification steps that told you what to type but never what you should see now say both. A step you cannot fail cannot tell you anything. And 141 bullets that had grown past 45 words — one of them to 98 — were split or cut.The completion checklist now matches the grader, item for item
Details
The checklist at the end of each guide used to restate the lab's objectives — "Enable Rapid-PVST+ on all switches and verify RSTP operation". You cannot tick that off a device: it describes the lesson, not something you can look at and confirm. Two thirds of every checklist item in the catalogue was that shape, and none of them mapped to anything the grader scored. All 241 checklists have been rebuilt from the grader itself. Each item now names the device, the value, and what you should see — "SW1 has `spanning-tree vlan 30 priority 4096`, and `show spanning-tree vlan 30` reports SW1 as root". Tick every box and you pass. The standalone checklist inside the downloadable package was rebuilt too. It had been generated from a different source and was still shipping the old list next to the new one.Labs now grade the whole build — and finished labs keep their scores
Details
Some labs only scored part of what they asked you to configure. The clearest example was Blocking Brute-Force Logins and Adding a Banner: it checked four lines and ignored the other seventeen, including the banner and the SSH hardening the lab is named after. You could skip most of the work and still finish on 100%. Every lab was measured the same way — the starter topology compared against the finished solution, line by line, asking whether anything in the grader actually checks it. 360 new checks went in across 68 labs. If you have already completed a lab, nothing changes. Your score, your pass and your badges stay exactly as they were: a result is recorded when you submit and is never recalculated afterwards. The fuller grading applies to new submissions. Two rules decided what could be added. A check only counts work the starter does not already do, so nothing was added that you would get for free. And a check is never added for a value the guide does not give you — where grading needed a name, a domain or a password the guide had left out, the guide was corrected first (64 values across 34 labs) rather than expecting you to guess. Losing a mark for something nobody told you is the one failure worth more than the mark. The completion checklist in each affected guide was extended to match, so ticking every box still means you are finished.Browse by topic: fewer pages, more on each
Details
The topic pages were spread too thin. There were 55 of them, most a bare list of labs, and several covered the same ground from different angles — standard ACL and extended ACL as separate pages from ACL, router-on-a-stick separate from inter-VLAN routing, PAT separate from NAT. They are now 28 hubs, each with real material on what the topic is, what the labs cover, and how it maps to the exams. Every old link still works and lands on the page the subject was merged into. Labs that suit both CCNA and CCNP now appear on both track pages, instead of sitting on a third page of their own where neither track could find them.STP 4: the guide now names the right ports on both trunks
Details
Task 6 asked you to lower the port priority on "SW1's second parallel trunk" so that SW2 would select its Gi0/2 as the root port. Those switches do not have a Gi0/2 — their ports are Ethernet0/0 and Ethernet0/1 — and "second parallel trunk" never said which of the two identical links it meant. Both trunks are now named everywhere they appear: Trunk-A on Ethernet0/0 and Trunk-B on Ethernet0/1, matching the descriptions already in the answer key. We swept every other guide for the same problem and found one more — a solution guide labelling an uplink after a router port that did not exist. Both are fixed, and a lab can no longer be published if its guide names an interface the devices in it do not have.Lab guide PDFs: arrows and numbered lists no longer overlap
Details
In the cabling section of some guides, the arrow in a line like "SW1 Et0/0 <-> SW2 Et0/0" was being drawn wider than the space reserved for it, so it ran into the text beside it. The same thing happened in numbered lists from item 10 onward, where the wider two-digit marker overlapped the first word of its own line. Both are fixed, and all 240 guide PDFs have been regenerated. Re-download any lab package to get the clean copy. Thanks to the member who reported it — it was easy to see once pointed at and invisible until then.VLAN name checks now grade the name the lab asks for
Details
46 checks across 6 labs displayed something like "VLAN 10 named USERS" and then accepted any name at all. You could call the VLAN anything and still pass a check that claimed to be verifying its name. They now check the name the lab actually specifies. Capitalisation does not matter, and a trailing "s" is accepted either way — USER and USERS both pass — so the only thing that fails is a genuinely different name. If you previously passed one of these on a name we should not have accepted, your score stands. Retries are free if you would rather run it again properly.Every lab guide now tells you how to log in
Details
If you ever consoled into a router and were asked for a password the guide never gave you, this was why. 109 labs ship a starter configuration that already sets an enable secret or a local username. Exactly one guide in the catalogue stated every credential its lab required. 95 stated none of them. Separately, the Alpine hosts have no password of their own — they use the CML image default — and we documented that nowhere at all. Every guide now carries an "Access & credentials" section listing the exact username, password and enable password for each device, plus the Alpine host login. It is written into the CML lab notes as well, so it is in front of you inside the lab rather than only in the PDF you may not have open. Two labs were worse than undocumented: they stored placeholder password hashes that no password could ever match, which made those routers impossible to log into at all. Both are fixed. Going forward, a lab cannot be published if its guide fails to state a credential the lab requires.Every bundle now opens with a free lab
Details
You can now take the first lab of every bundle without paying for anything. All 19 bundles open with a free lab — the same package, the same answer key, and the same per-requirement grading as the paid ones. You need a free account to download it, exactly like the sample lab, and that is the whole ask. The archive has a new Access filter: choose "Free labs" to see every one of them in one place, or "Labs I own" to find what you have already bought. The home page now leads with three of them instead of the bundle sales cards. If you have been wondering whether the grading is worth paying for, this is the honest way to find out — build one in CML and upload your config.
July 2026
16 updates
Port-security labs no longer mark you down for a setting Cisco hides
Details
If a port-security lab scored you lower than your work deserved, this was probably why — and it was our fault, not yours. A maximum of 1 secure MAC address is Cisco's default, and IOS doesn't write its defaults into the running-config. So when you set it correctly, the line simply isn't in your export — and our grader was looking for that exact line. Configure it perfectly, still lose the mark. Grading now checks what it actually cares about: that port security is enabled, and that nothing has moved the maximum off 1. That passes whether you typed the command explicitly or left it at the default, and it still catches a maximum set to the wrong value. Applied to 26 checks across 13 labs. Re-run any port-security lab that scored you unfairly — retries are free and your best score stands. Thanks to the members who reported it.Port-security labs now warn about the mistake that fails them
Details
If you've configured a port's security options — sticky learning, a violation mode, a maximum — and grading still marked the port down, this one is worth reading. IOS accepts all of those options on an interface even when port security itself is switched off. The interface looks fully configured, the lines are all in your config, and the port isn't actually protected. It's a genuinely easy one to miss, and it's the single most common reason a port-security lab scores lower than expected. Every lab that grades port security now has a troubleshooting note explaining how to catch it: check `show port-security interface <interface>` and confirm it reports Port Security: Enabled. If it says Disabled, the feature was never turned on — and the checks for it will fail even though your other port-security lines are present. Re-download any port-security lab package to get the updated guide.No more price tags on labs and bundles you already own
Details
If you'd bought a bundle or the CCNA path, the site kept quoting you the price for it — on the bundle page, the bundles list, the study-path page and the home page. Owned content now shows that you own it and takes you straight in, instead of trying to sell it to you again. One case was worse than cosmetic: buying the complete study path gives you every lab in every bundle inside it, but the individual bundle pages only checked whether you'd bought that bundle on its own. So a path owner could download every lab in a bundle while the page still offered to sell them that same bundle. Ownership through a path is now recognised everywhere. Subscription plans are unchanged and still shown — a subscription and a bundle purchase are separate things, and owning bundles doesn't mean you have one.Every guide now opens with what you need and ends with a checklist
Details
Two additions to every lab guide. Before you start: the level and rough time, how many nodes the topology needs — and whether that fits the 5-node limit on CML Free, so you know before you download rather than after — and which lab to work first when a lab builds on an earlier one. Completion checklist: a tick-list at the end of the guide covering everything the lab set out to teach, so you can check your work before you submit for grading. Each item maps to something the grader actually looks at. The same checklist has always shipped as a separate file inside the package; now it's in the guide you're already reading. Applied to 245 labs. Re-download a lab package to pick up the updated guide and PDF.Grading no longer marks you down for the names you chose
Details
If a lab asked you to create VLAN 999 as a "native/parking" VLAN, the grader was quietly checking that you had named it Native-Parking — a spelling the guide never actually gave you. Some guides even said outright that names are up to you and only the VLAN IDs matter, and then deducted for the name anyway. From your side that looked like a config mistake you could not find, on work that was correct. Nothing in a switch config refers to a VLAN by its name — a port joins VLAN 999 by its number — so the name was never the skill being tested. Grading now checks that you named the VLAN, not which name you picked. The same applies to interface descriptions. This has been applied to 66 labs. Where a name genuinely has to match, because another line points at it — an ACL applied with access-class, a NAT pool referenced by a translation rule — it is still graded exactly, and the guide now states it. If a lab scored you lower than your work deserved, re-submit it; your best score stands.Your subscription now includes the entire lab archive
Details
A subscription used to unlock only the daily labs published after you joined, which left hundreds of earlier labs locked. That has changed: an active subscription now opens the whole archive — every lab published so far, plus each new one as it drops. Bundles and study paths are unchanged and still worth buying: those you own permanently, including after a subscription ends. Subscribing is access while you pay; buying is yours to keep.IPv6 grading now recognises every way an address can be written
Details
IPv6 grading could still mark a correct line wrong. Case was fixed previously, but that only reconciled 2001:db8::1 against 2001:DB8::1 — and the same address has several equally valid spellings, with the choice made by the device that exported your config rather than by us: 2001:db8:12::1, 2001:0db8:0012::0001 and 2001:db8:12:0:0:0:0:1 are all the same address. A lab written against one of those marked the others "not found", for a line you could plainly see configured. The grader now compares IPv6 by address rather than by spelling, so whichever rendering your device produces grades the same. A genuinely different address still fails, as it should. Thanks to the member who reported it — re-run any IPv6 lab that scored you unfairly.Free download: the CCNA Command Cheat Sheet (PDF)
Details
Every essential Cisco IOS command for the CCNA — device setup, interfaces, VLANs, routing, ACLs, NAT, DHCP and SSH, plus a CIDR / subnet-mask / wildcard reference chart — on one printable PDF. It's free and you don't need an account: drop your email into the form on any guide, concept page, cheat sheet or calculator and the download link comes back straight away. It's generated from the same fact-checked command reference the site publishes, so it stays current on its own.New daily series: Resilient Campus — STP, EtherChannel & FHRP
Details
Fourteen new daily labs run from 27 July to 9 August, covering the redundancy side of the CCNA blueprint: spanning-tree root control, port cost and PVST+ load sharing, Rapid-PVST+, PortFast and BPDU Guard, Root Guard, LACP and PAgP EtherChannel, growing and troubleshooting a bundle, HSRP with preemption and interface tracking, VRRP, and an advanced capstone that ties all three together. Every lab is auto-graded, and each builds on the one before — work them in order.Every lab package links straight to its grading page
Details
Finished building a lab in CML? The lab guide and the package README now both include a direct link to that lab's grading form — one click from the guide to the page where you submit your CML export and get scored against the answer key. In the PDF guide the link is clickable. It has been added to every existing lab, and every new lab ships with it from now on.Lab guide PDFs: addresses no longer run into the next word
Details
In the PDF guides an IP address or subnet mask could end up touching the word after it — "255.255.255.0to Ethernet0/1" where the guide reads "255.255.255.0 to Ethernet0/1". The wording was always correct; the spacing on the page was not, and because it came down to how digits were measured it affected every address and mask in every guide. The PDF renderer now uses the font's real character widths, so words sit properly apart and text you copy out of a guide comes across clean. Re-download a lab package to get the corrected PDF.Every lab guide now includes its IP addressing plan
Details
Thirty-five guides were missing their addressing table, which meant digging through the topology to work out which interface takes which address. Every lab guide now carries an IP Addressing Plan built from that lab's own devices — interfaces and masks, the VLANs in play, and each host's address and default gateway. Guide formatting is consistent across the whole library too: the same section order, the same task labels, and the same numbering in every lab. Re-download a lab package to get the updated guide.Ranks now map to real certifications
Details
Your engineer rank now reflects real certification levels. Completing the CCNA study path at a 75–80% average earns Network Engineer, and the skill radar now grows with every graded lab and practice drill — not just the protocols you've touched once. Deeper, CCNP-level work carries you toward Architect and Principal. Because the milestones are now larger, some ranks re-based. Keep practicing and you'll climb steadily.See the solution configs after you submit
Details
Stuck on a lab? Once you submit your own work for grading, you can now open “Show the solution configs” on the grading card to see the solved configuration for each device and compare it against yours. The full solution guide still unlocks when you pass.VLAN labs now export their VLANs correctly
Details
We fixed a grading issue where an access switch's VLANs weren't captured in the exported configuration, which could mark correct VLAN work as wrong. Switches now keep their VLANs in the running-config so extraction and grading see them. Re-download an affected lab package to get the fix.IPv6 lab grading is now case-insensitive
IPv6 addresses are now graded case-insensitively, so a correct answer is no longer marked wrong just because the hex digits differ in case (for example 2001:DB8 vs 2001:db8).
See it in practice
Every change here exists to make one thing better — building a real config and getting it graded.