Build a two-link LACP EtherChannel between two layer-2 switches as an access port for VLAN 60, then tune the global load-balancing algorithm to src-dst-ip so traffic distributes more evenly. Verify Po6 status, the hashing method, and end-to-end host reachability.
CCNA & CCNP35 min5 objectives
View details
Build a two-link LACP EtherChannel between SW1 and SW2 using an active/passive pairing. The logical Port-channel2 carries VLAN 20 as an access link so two hosts on opposite switches can communicate. Verify with show etherchannel summary, show lacp neighbor, and host-to-host pings.
CCNA35 min4 objectives
View details
BeginnerFree2026-07-02
Beginner CCNA lab on a redundant two-switch Layer-2 loop with two parallel uplinks. You will enable Rapid-PVST+, set a deterministic root-bridge priority so SW1 becomes the root for VLAN 1, and verify port roles (root/designated/alternate) and loop prevention. Two Alpine hosts in VLAN 1 validate end-to-end connectivity without any routing or SVIs.
CCNA45 min5 objectives
View details
Free with an account
Migrate a three-switch triangle from legacy PVST to Rapid-PVST+ without changing the existing root or blocked port. SW1 remains the deterministic root for VLAN 70 (priority 4096). Verify protocol mode, link types (point-to-point vs edge), and end-to-end host reachability, then observe the faster reconvergence behavior of Rapid-PVST+.
CCNA & CCNP45 min5 objectives
View details
Engineer which trunk forwards by tuning STP path cost in a 3-switch triangle. Force SW1 as the VLAN 30 root at a deterministic priority, enable Rapid-PVST+, harden edge ports with PortFast and BPDU Guard, and raise the STP cost on SW3’s direct uplink to SW1 so SW3 prefers the longer, indirect path via SW2. Verify the resulting root port, alternate (blocked) port, and host reachability across the chosen path.
CCNA55 min5 objectives
View details
Advanced Rapid-PVST+ troubleshooting on a 3-switch triangle with a real Layer-2 loop. Two deliberate faults are seeded: an unintended root bridge wins VLAN 100 due to a mis-set/default priority, and PortFast/BPDU Guard are mistakenly applied on an inter-switch trunk. Two Alpine hosts in VLAN 100 verify user impact. Your job: use show commands to diagnose, then restore the correct root and remove edge features from the trunk while preserving them on access ports.
CCNA & CCNP70 min5 objectives
View details
Advanced Rapid-PVST+ and Root Guard implementation on a three-switch triangle with a real loop. SW1 is the intentional root for VLAN 90 and protects its designated ports with Root Guard to prevent root re-parenting. Two Alpine hosts on VLAN 90 verify end-to-end forwarding remains stable even if a superior BPDU appears downstream.
CCNA & CCNP50 min7 objectives
View details
Guide Rapid-PVST+ to prefer a specific parallel trunk by tuning the sender’s port priority on the root bridge. Two ioll2-xe switches (SW1, SW2) form a physical loop via two equal-speed trunks. A third L2 switch (SW3) extends the user VLAN to a second closet. One Alpine host attaches to SW1 and another to SW3 in VLAN 40 (10.1.40.0/24). You will: force SW1 to be the root for VLAN 40, lower the port priority on SW1’s Gi0/2 (Ethernet0/1) to break the tie so SW2 selects its Gi0/2 as the Root Port, enable PortFast and BPDU Guard on host-facing ports, and verify with show spanning-tree outputs and host pings.
CCNA55 min6 objectives
View details
Continue the STP series on a three-switch triangle with a real loop. SW1 is the deterministic root for VLAN 60, and access ports already use PortFast. In this lab you will harden the edge by enabling BPDU Guard on the two host-facing access ports on SW2 and SW3, while leaving the inter-switch trunks untouched. Verify with show commands that BPDU Guard is active only on the edge and that hosts still communicate normally.
CCNA35 min5 objectives
View details
Beginner CCNA STP lab on a three-switch triangle with two hosts in VLAN 20. You will deliberately control the Spanning Tree root election using the root primary/secondary macros so SW1 is the active root and SW2 is the standby. The baseline already provides VLANs and trunks; your job is to set root priorities deterministically and verify the resulting roles and port states without introducing any Layer-3.
CCNA35 min5 objectives
View details
Use Rapid-PVST+ to elect different root bridges per VLAN across two parallel trunks, spreading VLAN 80 and VLAN 81 across distinct physical links without modifying path cost or port priority. Validate independent per-VLAN trees and confirm hosts in VLAN 80 can communicate over the surviving path. Includes a drift-check to diagnose/restore trunk allow-lists.
CCNA & CCNP65 min6 objectives
View details
Configure PortFast correctly on access ports in a triangle switch loop while maintaining normal STP protection on inter-switch trunks. Force SW1 as the root for VLAN 50 and verify that only edge ports are fast-tracked. Observe the difference in host convergence with and without PortFast.
CCNA45 min5 objectives
View details
Deploy router-on-a-stick inter-VLAN routing across a compact branch topology with a distribution and access switch, a hardened 802.1Q trunk, and two user VLANs. Configure VLANs and access/trunk ports, build router subinterfaces, verify end-to-end user reachability, and troubleshoot trunk/native-VLAN/subinterface mismatches.
CCNA55 min5 objectives
View details
Configure the Layer-2 switch side of a router-on-a-stick design. A single IOS router already provides inter-VLAN routing on Ethernet0/0.10 (10.0.10.1/24) and Ethernet0/0.20 (10.0.20.1/24). Bring up VLAN transport by creating VLANs on the switch, assigning host access ports, and converting the router-facing link into an 802.1Q trunk that carries VLANs 10 and 20. Validate with show commands on the switch and with cross-VLAN pings from the hosts.
CCNA30 min4 objectives
View details
Design and implement a three-department campus edge using a single router-on-a-stick to provide inter-VLAN routing for Sales (VLAN 10), Engineering (VLAN 20), and Servers (VLAN 30). Map the addressing plan directly to router subinterfaces and build an 802.1Q trunk on the access switch. Verify end-to-end reachability and troubleshoot an allow-list drift scenario.
CCNA55 min5 objectives
View details
Build and verify inter-VLAN routing using router-on-a-stick with a native (untagged) VLAN on the trunk. Configure one router (subinterfaces only), one Layer-2 access switch (VLANs, access ports, and a single 802.1Q trunk), and two end hosts in different VLANs. The management VLAN 99 rides untagged as the trunk's native VLAN, so the router subinterface must use 'encapsulation dot1Q 99 native' and the switch trunk must match 'switchport trunk native vlan 99'. Verify from Linux hosts and IOS 'show' commands, then practice troubleshooting common native-VLAN faults.
CCNA50 min4 objectives
View details
BeginnerFree2026-06-30
Hands-on fundamentals with Cisco port security on host-facing access ports. Build a small two-switch campus with a trunk, place two Linux hosts in the same user VLAN, then enable port security with the explicit defaults (maximum 1, violation shutdown) on both host ports. Verify secure-up state and baseline host connectivity.
CCNA40 min4 objectives
View details
Free with an account
Advanced CCNA switching capstone centered on restoring end-to-end VLAN 20 transport across three Layer-2 switches using 802.1Q trunks. The starter ships intentionally broken: after a simulated maintenance window, two Alpine hosts in VLAN 20 can no longer reach each other across the inter-switch trunks. Learners diagnose with show interfaces trunk, show interfaces switchport, and show vlan brief, then identify and correct the trunking faults in the right order and verify with host pings.
CCNA55 min5 objectives
View details
Build a single 802.1Q trunk between two Layer-2 switches that correctly carries three VLANs with an explicit allow-list and a dedicated non-default native VLAN. Place hosts in Users (VLAN 10) across both switches and a server in Servers (VLAN 20). Verify that the trunk allows VLANs 10, 20, and 99, that the native VLAN matches on both ends, and that same-VLAN hosts communicate across the trunk. Then intentionally break and restore the configuration to practice troubleshooting trunk allow-lists, native VLAN alignment, and host VLAN placement.
CCNA47 min5 objectives
View details
Advanced CCNA port-security troubleshooting on a pure Layer-2 design. Two access switches linked by an 802.1Q trunk carry a Users VLAN across closets. Three Alpine Linux hosts are pre-addressed. The lab is intentionally shipped with multiple classic faults: one access port is err-disabled due to a prior port-security shutdown, one user-facing port lacks port-security altogether, another has the wrong violation mode and an overly restrictive maximum, and one port has an incorrect static secure-MAC configured. Your job is to diagnose using show commands, restore connectivity, and implement the intended security posture with sticky MACs, the correct maximum, the proper violation mode, and errdisable auto-recovery—without placing port-security on the trunk.
CCNA55 min6 objectives
View details
Deploy and verify port security maximum settings on host-facing access ports in a pure Layer-2 campus with two access switches uplinked to a distribution switch. You will raise the allowed secure MAC count to 2 on each user port to support a PC and a potential downstream device (e.g., a dock), then verify with show commands. No Layer-3, SVIs, or routing are used; focus purely on access VLANs, trunks, and the port-security maximum behavior.
CCNA45 min4 objectives
View details
Deploy and compare the two non-disabling port-security violation modes on host-facing access ports. Build a small Layer-2 topology with a trunk between two switches and same-VLAN hosts. Configure violation protect on one access port and restrict on another using deterministic sticky MAC entries. Validate baseline reachability, then observe the different behaviors: protect silently drops with no counter/logs; restrict drops and increments the violation counter.
CCNA45 min4 objectives
View details
Configure port security in shutdown mode on host-facing access ports and enable automatic errdisable recovery for psecure-violation. The lab uses two Layer-2 switches connected by a trunk and three Linux hosts in the same VLAN to validate baseline L2 connectivity. You will deploy and verify the global errdisable recovery timer and cause while keeping the trunk healthy. Focus is on deterministic configuration and verification via show commands rather than attempting to trigger live violations.
CCNA45 min4 objectives
View details
BeginnerFree2026-06-30
Build a static 802.1Q trunk between two Layer-2 switches to carry VLANs 10 and 20. Map hosts to access ports, verify trunk encapsulation and allowed VLANs, demonstrate same-VLAN reachability across the trunk, and confirm inter-VLAN isolation. Then simulate an allow-list drift fault, diagnose with show commands, and restore service.
CCNA45 min5 objectives
View details
Free with an account