Topic

CCNA practice labs — Page 8

220 hands-on CCNA scenarios you build in your own Cisco Modeling Labs instance and grade against the answer key. CCNA configuration and troubleshooting practice for CCNA and CCNP.

Included with a subscription

AdvancedLocked

CCNA Port-Sec 9: Multi-Port Sticky Restrict Policy

Advanced CCNA switchport port-security rollout on multiple access ports across two Layer-2 switches with a trunk. You will standardize a consistent edge policy (sticky MAC learning, maximum 1, violation restrict) on all host-facing access ports while leaving the uplink trunk exempt from port-security. Includes a realistic drift on the trunk allow-list and VLAN database to fix before validating end-to-end user VLAN transport. Pure Layer-2: no SVIs or routing.

CCNA58 min6 objectives

IntermediateLocked

Port Security: Violation Shutdown & Manual Recovery

Hands-on CCNA L2 switching lab: build a small campus with a distribution switch and two access switches carrying a shared user VLAN over 802.1Q trunks. Harden access ports with sticky port-security in violation shutdown mode. Intentionally seed and diagnose broken trunks/host VLANs, restore end-to-end host reachability, then trigger a port-security violation to observe err-disabled behavior and perform manual recovery.

CCNA65 min5 objectives

IntermediateLocked

Port Security: Static Secure MAC Binding

Troubleshoot a Layer-2 forwarding fault that breaks a user VLAN between access/distribution switches, then implement static secure MAC binding on the client-facing access port. You will restore end-to-end VLAN 20 reachability and enforce a single authorized MAC on the user port using port-security with violation restrict.

CCNA55 min5 objectives

IntermediateLocked

Port Security: Voice + Data on One Access Port

Harden a real desk port that carries both data (PC) and voice (IP phone) using switchport voice vlan and access vlan on a single access port. Apply port security with a maximum that accounts for two MAC addresses (phone + PC) so a third device is restricted. A deliberate trunk allow-list drift on the inter-switch link initially blocks the Voice VLAN; learners must repair the trunk and then verify port-security state on the desk port.

CCNA55 min6 objectives

BeginnerLocked

CCNA Port Security 2: Sticky Secure MAC Learning

Two access-layer switches have a VLAN 20 connectivity problem: users in one wiring closet cannot reach users in the other. Diagnose and repair the issue, then deploy sticky secure MAC learning on the host-facing access ports so each port dynamically learns and persists its connected host's MAC. Verify sticky entries in show commands and confirm same-VLAN host connectivity end-to-end.

CCNA45 min4 objectives

BeginnerLocked

Trunking Basics: Access Ports vs Trunk Ports

Hands-on CCNA switching lab contrasting single-VLAN access ports with 802.1Q trunks. You begin with the inter-switch link configured as a plain access port, so only one VLAN reaches the router-on-a-stick gateway while the other cannot. You will diagnose the connectivity problem, convert the link into a properly hardened 802.1Q trunk, and validate that both VLANs regain access to their gateway.

CCNA55 min5 objectives

IntermediateLocked

Native VLAN Mismatch: Diagnosing a Broken Trunk with CDP

Diagnose and remediate a trunk misconfiguration between an access switch and a distribution switch so that same-VLAN hosts across two access switches can communicate end-to-end. Use CDP and trunk verification commands to investigate the fault and restore proper trunk operation, without introducing any Layer-3 routing.

CCNA45 min5 objectives

IntermediateLocked

CCNA: Native VLAN & Untagged Traffic on 802.1Q

Hands-on CCNA switching lab focused on the native VLAN and tagging behavior on 802.1Q trunks. Users in one VLAN currently cannot reach their peers across a switch-to-switch trunk; you will standardize the native VLAN away from VLAN 1 to a dedicated parking VLAN, diagnose and correct the trunk configuration, verify the untagged VLAN on both ends, and confirm same-VLAN host reachability across the trunk.

CCNA55 min6 objectives

AdvancedLocked

Trunk Verification & Diagnosing a Silent VLAN

An advanced CCNA switching lab focused on verifying 802.1Q trunks and diagnosing a silent VLAN after a switch refresh. The topology uses three layer-2 switches (a distribution switch between two access closets) and two Alpine hosts, and users in VLAN 20 at one closet cannot reach their VLAN 20 peers at the other closet across the trunk path. Learners use show interfaces trunk, show interfaces switchport, and show vlan brief to locate the break and restore predictable Layer-2 forwarding without adding any Layer-3 configuration.

CCNA55 min5 objectives

IntermediateLocked

VLAN Trunking 6: DTP and Trunk Hardening

Hands-on DTP negotiation and trunk hardening across a 3-switch path. You will observe dynamic trunking behavior (auto vs desirable), fix an allow-list drift that blocks user VLAN transport, and then harden the trunks to static with nonegotiate and a non-default native VLAN. End-to-end host reachability in the same VLAN proves success.

CCNA55 min6 objectives

IntermediateLocked

CCNA VLAN Trunking 7: Trunking Across Three Switches

Build an end-to-end 802.1Q path across three Cisco IOS Layer-2 switches so VLAN 10 transports user traffic from an access port on the left switch to an access port on the right switch through a middle switch. Harden trunks (native VLAN 999, nonegotiate) and verify with show interfaces trunk. Then intentionally break the allow-list to see the outage and restore service.

CCNA45 min5 objectives

BeginnerDailyLocked

Default Routes & the Gateway of Last Resort

Build a small hub-and-branch network to master default static routes and the gateway of last resort. Each branch uses a default route toward the hub; the hub holds specific routes back to branch LANs. Verify routing tables and end-to-end host connectivity, then troubleshoot common misconfigurations.

CCNA55 min5 objectives

BeginnerDailyLocked

Static Routing Between Branches Through an HQ Hop

Deploy IP addressing and bidirectional static routing across a three-router topology to connect two branch LANs through an HQ hop. Practice verification from end hosts, analyze routing tables, and troubleshoot asymmetric reachability.

CCNA45 min5 objectives

BeginnerDailyLocked

IPv4 Addressing Fundamentals: Interfaces, Gateways & Reachability

Beginner CCNA lab focusing on IPv4 addressing and basic Layer 3 verification on a small branch network. You will assign IP addresses to router interfaces, confirm end-host default gateways, and verify connected reachability using host-based pings. You will also learn to read 'show ip interface brief' and 'show ip route' to confirm operational state before any routing beyond directly-connected networks is configured.

CCNA50 min5 objectives

AdvancedDailyLocked

Branch Layer 2 Capstone: Build, Verify & Fix VLANs and Trunks

Advanced Layer-2 capstone, run as a fault hunt. A branch was cut over last night: one user VLAN has no gateway, another user sits in the wrong subnet, the management VLAN is unreachable from the distribution switch, and a port that should lock to one MAC no longer does. Nothing was recorded. You get symptoms and the required end state — no fault list. Faults span the router and both switches, and more than one of them presents as 'the trunk is broken'.

CCNA75 min5 objectives

BeginnerDailyLocked

Troubleshoot a Branch ROAS: VLANs, Trunks & Port Security

Deploy and troubleshoot VLANs, 802.1Q trunks, and port security in a realistic small-branch ROAS design. You will stand up VLANs 10/20/99 with a hardened trunk native VLAN 999, configure sticky port security on access ports, correct a misassigned VLAN, and resolve an err-disabled port caused by a port security violation. Finish by verifying end-to-end host connectivity across VLANs.

CCNA55 min5 objectives

BeginnerFree2026-06-25

Standard ACL: Permit Host & Subnet, Deny Others

Beginner CCNA ACL lab on a compact 5-node CML-Free topology. You will configure static routing end-to-end, implement source NAT (PAT) at the source edge, and then build a standard numbered ACL near the destination to allow a single NATed host and a specific subnet while denying all others. You will validate with pings from end hosts, observe ACL hit counters and NAT translations, and troubleshoot common mistakes such as ACL placement, wildcard masks, and pre-/post-NAT address matching.

CCNA55 min7 objectives

Free with an account

IntermediateLocked

Secure Router VTY with ACL: Only Management Host Allowed

Configure a standard IPv4 ACL and bind it to the VTY lines on the HQ router so only the dedicated management host can SSH to it. Confirm that regular routed traffic between sites is unaffected, and prove both a permitted and a denied management attempt.

CCNA45 min5 objectives

IntermediateLocked

CCNA: Named ACLs & Editing by Sequence Number

Hands-on ACL practice using named standard and extended ACLs, applied with correct placement and direction, edited by sequence number, and verified with counters and end-host tests. The lab adds a realistic NAT edge to expose order-of-operations pitfalls without obscuring data-plane ACL effects.

CCNA75 min6 objectives

IntermediateLocked

ACL Wildcard Masks: Match Host, Subnet, and Range

Hands-on CCNA ACL practice using standard ACLs and wildcard masks to allow a single host, a contiguous range, and an entire subnet while proving a deny. You will place the ACL near the destination, order statements correctly, verify with end-host pings and ACL counters, and troubleshoot common mistakes.

CCNA55 min5 objectives

AdvancedLocked

ACL Segmentation Policy on Multi-LAN Router

Deploy and verify multiple IPv4 ACLs on a single router that terminates three distinct LANs (Client, Server, and Management). You will place an extended ACL inbound on the Client interface to allow only specific services to the Server and block access to Management, a standard ACL outbound on the Management interface to enforce destination-side protection by source, and a VTY access-class to restrict router SSH to the Management subnet only. Validate with end-host tests that permitted flows succeed while denied flows are provably blocked, and use ACL hit counts and logs to troubleshoot.

CCNA70 min5 objectives

IntermediateLocked

ACL Logging & Order: Correct Permit/Deny Sequencing

Three-router static-routing lab with two Linux endpoints. An extended IPv4 ACL is intentionally misordered inbound near the source, causing Telnet to be permitted unexpectedly. Learners must observe first-match behavior via hit counters, enable buffered logging to see ACL log entries, and then correct the ACL sequence so Telnet is blocked while SSH and ICMP are permitted. All routers include a complete SSH management plane. The final solution forwards end-to-end and is enterprise-clean.

CCNA55 min5 objectives

IntermediateLocked

CCNA: ACL Placement – Std Near Dest, Ext Near Source

Dual-router Branch/HQ lab with a branch client and an HQ server. You will apply an extended IPv4 ACL inbound near the source on the Branch LAN to block specific traffic (TCP/80) while permitting others (ICMP), and a standard IPv4 ACL outbound near the destination on the HQ LAN to admit only the approved source. Validate from real hosts, confirm ACL hitcounts, and keep inter-site connectivity via static routes over a /30 transit.

CCNA55 min4 objectives

IntermediateLocked

ACL App Filter: Permit SSH/HTTP, Block Telnet/ICMP

Build a two-router, one-access-switch lab with a client and a server. Establish basic IP connectivity with static routing, then implement an extended IPv4 ACL inbound on the client-facing interface to permit SSH and HTTP to the server while denying Telnet and ICMP echo. Validate from the client and review ACL hit counters for proof.

CCNA55 min5 objectives

Looking for something else? Browse the full lab archive, narrow it to self-standing labs, or see today's daily lab.