CCNA Complete Path
Every hands-on CCNA 200-301 topic, in one path — 17 bundles of auto-graded Cisco Modeling Labs, sequenced from IP addressing through switching, routing, IP services, and security. Build each on real Cisco IOS and grade your own config. Every bundle included with an active subscription.
How this path works
Work the milestones in order — each builds on the last: foundations (addressing) → switching (VLANs, trunking, inter-VLAN, STP, EtherChannel) → routing (static, OSPF, first-hop redundancy) → IP services (DHCP, NAT, NTP, discovery & monitoring) → security (ACLs, port security, layer-2 hardening, device hardening). Build every lab on real Cisco IOS in CML and grade your config against the answer key before advancing.
What you'll be able to do
Configure and troubleshoot every CLI-based CCNA 200-301 topic on real Cisco IOS. (Wireless and automation/programmability are exam domains best covered by supplementary study — the labs focus on the hands-on configuration the exam and the job demand.)
17 milestones, in order
Each milestone is a full graded bundle. Work them top to bottom — every stage builds on the last, and every lab runs on CML's free tier (5 nodes or fewer).
Foundations — IP Addressing & Subnetting
Ten hands-on addressing labs — IPv4 subnetting and VLSM, IPv6 addressing (SLAAC/EUI-64), and connectivity verification.
View bundle →10 labs in this milestone
- CCNA L1: Interface Addressing and Verification
- CCNA Lab 2: Subnet a /24 into Four /26s
- CCNA Lab: VLSM Right-Sizing from One /24
- Point-to-Point Links with /30 and /31
- Secondary IP on a LAN Interface
- IPv6 Global Unicast Addressing
- IPv6 Addressing with EUI-64
- IPv6 Link-Local Addressing
- Lab 9: Dual-Stack IPv4/IPv6 Addressing on IOS
- IP Addressing Troubleshooting Capstone
Switching — VLANs & Segmentation
Ten hands-on labs building VLAN segmentation from the ground up — access ports, VLAN databases, voice/data separation, and verification.
View bundle →10 labs in this milestone
- VLAN Fundamentals: Creating & Assigning Access Ports
- VLAN Segmentation: Broadcast-Domain Isolation
- Extending VLAN 10 Across Two Switches (802.1Q)
- CCNA: VLAN DB & Trunk Allow-List Drift Recovery
- Voice & Data VLANs: Access + Trunk Allowed Lists
- Native VLAN & Trunk Mismatch: Detection and Recovery
- Trunk Allowed-VLAN Pruning Across L2 Switches
- Port Membership & Trunking: VLAN Assignment + Verification
- Multi-VLAN Segmentation: 3 VLANs & Trunk Alignment
- VLAN Troubleshooting Capstone: Native Mismatch & VLAN Drift
Switching — Trunking (802.1Q)
Ten hands-on 802.1Q trunking labs — trunk configuration, allowed/native VLANs, DTP behavior, and trunk troubleshooting.
View bundle →10 labs in this milestone
- 802.1Q Trunk Fundamentals: Static Trunk and VLANs
- Trunking Basics: Access Ports vs Trunk Ports
- CCNA: Native VLAN & Untagged Traffic on 802.1Q
- Native VLAN Mismatch: Diagnosing a Broken Trunk with CDP
- CCNA: Pruning the Allowed VLAN List on Trunks
- VLAN Trunking 6: DTP and Trunk Hardening
- CCNA VLAN Trunking 7: Trunking Across Three Switches
- A Policy-Correct Multi-VLAN Trunk
- Trunk Verification & Diagnosing a Silent VLAN
- 802.1Q Trunking Troubleshooting Capstone
Switching — Inter-VLAN Routing
Ten hands-on labs routing between VLANs — router-on-a-stick, subinterfaces, SVIs on a layer-3 switch, and gateway verification.
View bundle →10 labs in this milestone
- Router-on-a-Stick Fundamentals: Two VLANs, One Trunk
- dot1Q Subinterfaces: The Router Side
- Switch Trunk and Access Ports for Router-on-a-Stick
- Scaling to Three VLANs: Adding a Department
- Native VLAN on a Router-on-a-Stick Trunk
- Multi-Dept Campus Inter-VLAN with Router-on-a-Stick
- Three-VLAN Router-on-a-Stick: Build, Harden & Verify
- Selective Inter-VLAN Reachability: Guest Isolation
- Diagnosing a Broken Router-on-a-Stick
- Router-on-a-Stick Troubleshooting Capstone
Switching — Spanning Tree (RSTP)
Ten progressive spanning-tree labs — root election, port roles/costs, PortFast/BPDU Guard, Rapid-PVST, and loop troubleshooting.
View bundle →10 labs in this milestone
- Spanning Tree Fundamentals: Root Election & Port Roles
- STP 2: Controlling the Root Bridge with Priority
- STP 3: Path Cost — Choose the Forwarding Link (VLAN 30)
- STP 4: Port Priority Tie-Break on Parallel Links
- STP 5: PortFast on Access Ports (VLAN 50 Triangle)
- STP Lab 6: BPDU Guard — Protecting the Edge
- STP Lab 7: Rapid-PVST+ Migration on Triangle Loop
- STP Lab 8: Per-VLAN Load Balancing Across Two Roots
- Root Guard on Designated Ports
- STP 10: Spanning Tree Troubleshooting Capstone
Switching — EtherChannel (LACP)
Ten hands-on EtherChannel labs — LACP/PAgP/static bundles, layer-2 and layer-3 port-channels, load balancing, and bundle troubleshooting.
View bundle →10 labs in this milestone
- Static EtherChannel: Bundling Two Links (mode on)
- LACP EtherChannel: Active/Passive Negotiation
- PAgP EtherChannel: Desirable/Auto Negotiation
- Layer-2 Trunk EtherChannel Carrying Multiple VLANs
- L3 Routed EtherChannel Between Two Routers (LACP)
- EtherChannel Load Balancing with LACP (VLAN 60)
- Lab 7: EtherChannel + Rapid-PVST — One Logical Link
- Lab 8: L3 EtherChannel + Static Routing
- EtherChannel Consistency: Repair a Mode Mismatch
- EtherChannel Troubleshooting Capstone (L2 LACP)
Routing — Static & Default Routes
Ten hands-on static-routing labs — directly-connected/recursive next-hops, default and floating static routes, IPv6 statics, and path verification.
View bundle →10 labs in this milestone
- CCNA Static Routing: Bidirectional End-to-End Connectivity
- CCNA Default Routes: Edge-to-Core Gateway of Last Resort
- CCNA Static Routes: Manual Summarization
- CCNA Static Routing: Floating Static Route as Backup Path
- CCNA Static Routing: Equal-Cost Load Sharing
- CCNA IPv6 Static & Default Routing End-to-End Practice
- CCNA Static Routing: Host vs Subnet (/32 vs /24)
- CCNA Static Routing: 3-Router Full-Mesh
- CCNA Static Routing: Redundant Branch Triangle
- CCNA Static Routing: Troubleshooting Broken Static Routes
Routing — OSPF (Single-Area)
Progressive hands-on OSPFv2 labs — from a first single-area adjacency through DR/BDR election, multi-area design, route summarization, stub areas, authentication, and a troubleshooting capstone.
View bundle →11 labs in this milestone
- OSPFv2 Single-Area Fundamentals: Adjacency and Area 0 Basics
- OSPFv2: Router IDs, Neighbor States, and Loopback Adjacency
- OSPF Cost & Path Selection: Deterministic Control (3 Routers)
- OSPF Network Types: DR/BDR, Broadcast vs P2P
- CCNA: OSPF Passive Interfaces & Default Origination
- OSPF Multi-Area: ABR Area Mismatch and Route Repair
- OSPF Inter-Area Summarization with ABR Area Range
- OSPF Stub vs Totally-Stubby: Fault & Recovery
- OSPF MD5 Authentication: Backbone Integrity and Area Mismatch
- OSPFv2 Multi-Area with ABR Summarization (Redundant Core)
- OSPFv2 Multi-Area Capstone: 3-Rtr Line, Auth, LAN Host Intact
Routing — First-Hop Redundancy (HSRP/VRRP)
Thirteen hands-on first-hop redundancy labs — HSRP virtual gateways, priority/preempt, interface tracking, MD5 authentication, timers, HSRPv2, multi-group load-sharing, and VRRP.
View bundle →13 labs in this milestone
- HSRP Fundamentals: A Virtual Default Gateway
- CCNA HSRP 2: Controlling the Active Router with Priority
- HSRP Preempt: Reclaiming the Active Role
- HSRP Interface Tracking for Uplink Failover
- Securing HSRP with MD5
- Tuning HSRP Timers for Faster Failover
- Moving to HSRP Version 2
- Load-Sharing with Two HSRP Groups
- VRRP — The Open-Standard Alternative
- VRRP Object Tracking for Uplink Failover
- VRRP Load-Sharing with Two Groups
- VRRP: Tune Advertisements to 3 Seconds
- First-Hop Redundancy Troubleshooting
IP Services — DHCP
Ten hands-on DHCP labs — server pools, exclusions, reservations, relay (ip helper-address), and lease troubleshooting.
View bundle →10 labs in this milestone
- DHCP Server Fundamentals: One Pool
- DHCP Exclusions: Reserved Statics on a Single LAN
- Lab 3: Full DHCP Pool — Gateway, DNS, Domain, Lease
- Lab 4: DHCP Relay with ip helper-address
- DHCP: Serving Two Subnets from Two Pools
- Router Interface as a DHCP Client (IOS-to-IOS)
- Lab 7: DHCP Manual Bindings (Reservations)
- DHCP: Verify Leases, Pools and Conflicts
- Lab 9: Centralized DHCP for Two Departments via Relay
- DHCP Troubleshooting Capstone: Branch Relay
IP Services — NAT & PAT
Ten hands-on NAT labs — static NAT, dynamic pools, PAT/overload, port forwarding, and translation troubleshooting.
View bundle →10 labs in this milestone
- CCNA NAT1: Static One-to-One NAT with ISP
- Inside, Outside & the Translation Table
- CCNA NAT3: Dynamic NAT with an Address Pool
- CCNA NAT4: PAT Overload onto a Pool
- PAT onto the Outside Interface (SOHO Edge)
- Static PAT: Port Forwarding to an Inside Server
- NAT Selection with an ACL: PAT a Single Host Only
- NAT at the Internet Edge with Default Routing
- CCNA NAT9: Verifying & Clearing NAT
- NAT Troubleshooting Capstone: Interface Role + ACL
IP Services — NTP
Ten hands-on NTP labs — master/client/peer, authentication, stratum behavior, and time-sync verification.
View bundle →10 labs in this milestone
- CCNA NTP Client: Sync to an Authoritative Server
- CCNA NTP: Authoritative Master and Stratum
- CCNA NTP: Symmetric Active Peers on a /30
- Securing NTP with MD5 Authentication
- Broadcast Time on a Shared LAN
- Restricting NTP with an access-group
- Redundant Time Sources with prefer
- Building a Multi-Level NTP Hierarchy
- Local Time with Timezones over NTP
- NTP Troubleshooting Capstone
IP Services — Discovery & Monitoring (CDP/LLDP, Syslog, SNMP)
Ten hands-on labs — CDP and LLDP discovery, Syslog, SNMPv2c/v3 monitoring and traps, and DNS on Cisco IOS — the network-assurance toolkit.
View bundle →10 labs in this milestone
- CDP Neighbor Discovery and Edge Suppression
- LLDP for Multi-Vendor Discovery
- Securing Discovery on Edge Ports
- Centralized Syslog with Timestamps
- Syslog Severity & Buffered Logging
- SNMPv2c Read-Only Monitoring
- SNMP Trap Notifications to the NMS
- SNMPv3 AuthPriv Monitoring
- DNS Name Resolution on IOS
- Discovery & Monitoring Troubleshooting Capstone
Security — Access Control Lists
Progressive ACL labs — standard/extended numbered and named ACLs, placement, logging, and filtering troubleshooting.
View bundle →11 labs in this milestone
- Standard ACL: Permit Host & Subnet, Deny Others
- Extended ACL Fundamentals: Permit HTTP, Deny Others
- CCNA: Named ACLs & Editing by Sequence Number
- ACL Wildcard Masks: Match Host, Subnet, and Range
- CCNA: ACL Placement – Std Near Dest, Ext Near Source
- ACL App Filter: Permit SSH/HTTP, Block Telnet/ICMP
- Secure Router VTY with ACL: Only Management Host Allowed
- ACL Logging & Order: Correct Permit/Deny Sequencing
- ACL Segmentation Policy on Multi-LAN Router
- Extended ACL: Application Filtering at a Hardened Edge
- ACL Troubleshooting Capstone: Classic Faults, NAT, Placement
Security — Port Security
Ten hands-on switchport-security labs — static/sticky MAC, violation modes, err-disable recovery, and access-port hardening.
View bundle →10 labs in this milestone
- CCNA Port Security 1: Enable & Verify on Access Ports
- CCNA Port Security 2: Sticky Secure MAC Learning
- CCNA Port Security: Maximum Secure MACs on Access Ports
- CCNA Port Security: Violation Protect vs Restrict
- Port Security: Violation Shutdown & Manual Recovery
- Port Security: Err-Disable Auto Recovery
- Port Security: Static Secure MAC Binding
- Port Security: Voice + Data on One Access Port
- CCNA Port-Sec 9: Multi-Port Sticky Restrict Policy
- CCNA Capstone: Port Security Troubleshooting
Security — Layer 2 Hardening (DHCP Snooping, DAI)
Eight hands-on labs — DHCP snooping, Dynamic ARP Inspection, protected ports, and errdisable recovery — defending the switch access edge.
View bundle →8 labs in this milestone
Security — Device Hardening (SSH, AAA)
Ten hands-on device-security labs — SSH, local/AAA authentication, privilege levels, login hardening, and secure management.
View bundle →9 labs in this milestone
- CCNA: SSH Access Fundamentals on R1
- SSH-Only Management: Disabling Telnet on R1
- Enable Secret and Password Encryption on R1
- Privilege Levels for Tiered CLI Access
- CCNA: Console and VTY Line Hardening
- Blocking Brute-Force Logins and Adding a Banner on R1
- AAA Authentication with a Local User Database
- AAA Named Method Lists with Fallback (VTY vs Console)
- Secure-Access Troubleshooting Capstone: SSH VTY Fix
Questions about the CCNA Complete Path
What's included in the CCNA Complete Path?
17 hands-on lab bundles — 172 auto-graded CCNA labs in all — sequenced into one progression from fundamentals through to exam-ready troubleshooting. Each lab is a real Cisco Modeling Labs scenario you build on Cisco IOS, then grade your own config against the answer key.
Is this a subscription or a one-time purchase?
A subscription — the only plan we sell, and it includes every lab in this path. Study paths and bundles are no longer sold separately; anything bought before that change stays owned permanently, with no subscription needed.
Do I need my own Cisco CML to run these labs?
Yes — each lab is a Cisco Modeling Labs (CML) topology you import and build on real Cisco IOS, and the CML free tier (5 nodes) is enough. You download the topology and lab guide, then build it yourself.
How does the grading work?
Every lab ships as a problem to solve, not a walkthrough to copy. You build it in CML, submit your config, and get pass/fail on each objective against the answer key — so you know exactly what's right and what to fix instead of guessing.
Does this cover the whole CCNA exam?
It covers every hands-on, CLI-configurable CCNA topic — the routing, switching, IP-services, and security configuration the exam and the job actually test on real gear. The wireless and automation/programmability domains are best studied through reading rather than CLI labs, so pair the path with those for full exam coverage.
Start practicing on real Cisco IOS
172 graded labs across 17 bundles — build each one in CML and grade your own config.