Topic

VLAN practice labs — Page 3

60 hands-on VLAN scenarios you build in your own Cisco Modeling Labs instance and grade against the answer key. VLAN configuration and troubleshooting practice for CCNA and CCNP.

Included with a subscription

AdvancedLocked

VLAN Troubleshooting Capstone: Native Mismatch & VLAN Drift

Advanced CCNA L2 troubleshooting in a compact branch. Some PCs can't reach their default gateway or other departments across two switches and a router-on-a-stick gateway, and your monitoring system has flagged a switching/trunking problem on the path. Validation is performed from the endpoints (Alpine hosts) using pings and ARP, and trunks are hardened with a non-default native VLAN.

CCNA65 min6 objectives

AdvancedLocked

Multi-VLAN Segmentation: 3 VLANs & Trunk Alignment

Hands-on CCNA campus switching lab with two Layer-2 switches and three VLANs (Users 10, Servers 20, Management 99) extended over a single 802.1Q trunk. Learners deploy VLANs and access ports, harden the trunk (native VLAN 999, explicit allow-list, nonegotiate), and validate isolation. The lab ships with a trunk-carried outage: VLAN 10 traffic reaches its gateway successfully, but VLAN 20 traffic does not. You will diagnose from end hosts, confirm switch states, and correct the trunk so that same-VLAN traffic to the gateway SVI succeeds while inter-VLAN forwarding remains absent.

CCNA75 min5 objectives

IntermediateLocked

Voice & Data VLANs: Access + Trunk Allowed Lists

Configure a two-switch access layer with data and voice VLANs on access ports and an 802.1Q trunk between switches. Add a router-on-a-stick gateway for VLAN 10/20. Verify VLAN placement, trunk status, and observe a connectivity failure caused by an allow-list misconfiguration on the inter-switch trunk—then correct it to restore intra-VLAN reachability.

CCNA65 min6 objectives

BeginnerLocked

VLAN Segmentation: Broadcast-Domain Isolation

Build VLANs across two access switches with an 802.1Q trunk and a router uplink. Verify that hosts in the same VLAN can communicate (even across switches) while hosts in different VLANs cannot. Then troubleshoot a failure caused by a trunk allow-list misconfiguration.

CCNA55 min5 objectives

IntermediateLocked

Extending VLAN 10 Across Two Switches (802.1Q)

Build and verify an 802.1Q trunk between two access switches that cleanly transports VLAN 10 end-to-end while intentionally pruning VLAN 20. You will configure access ports, create VLANs, set a hardened dot1Q trunk with a non-default native VLAN, and validate host reachability and isolation from endpoints.

CCNA55 min5 objectives

BeginnerFree2026-06-25

VLAN Fundamentals: Creating & Assigning Access Ports

Hands-on CCNA lab to practice creating VLANs on a single Layer-2 switch and assigning access ports. You will segment a flat network into two VLANs, place hosts into the right VLAN, and verify that intra-VLAN pings succeed while inter-VLAN pings fail (no routing present). Includes realistic verification and troubleshooting.

CCNA45 min5 objectives

Free with an account

IntermediateLocked

Trunk Allowed-VLAN Pruning Across L2 Switches

Configure VLANs and access ports on two Layer-2 switches, build 802.1Q trunks (with hardened native VLAN and an explicit allowed list), validate end-to-end reachability, intentionally prune a VLAN from the inter-switch trunk to observe segmentation, then restore the correct allow-list. Includes realistic router-on-a-stick gateways for VLAN 10/20/99 and switch management on VLAN 99.

CCNA55 min6 objectives

IntermediateDailyLocked

Hardened Trunks & ROAS: Allowed VLAN Lists, Native VLAN 999

Implement VLANs, 802.1Q trunking, router-on-a-stick inter-VLAN routing, and access-layer port security on a compact branch network with two access switches and two endpoints. You will configure segmentation (VLANs 10, 20, 99), hardened trunks with a dedicated native VLAN 999, Layer 3 gateways on a core router, and sticky MAC port security on user-facing ports. Verify end-to-end reachability and remediate common misconfigurations like missing allowed VLANs, native VLAN mismatches, and unauthorized endpoint moves.

CCNA68 min6 objectives

BeginnerDailyLocked

Layer 2 Access Hardening: PortFast, BPDU Guard & Sticky MAC

Hands-on CCNA Layer 2 switching lab: build VLANs, access ports, hardened 802.1Q trunks, and basic port-security across two access switches and an L2 core. Verify segmentation end-to-end from real hosts and practice troubleshooting native-VLAN and port/VLAN mismatches.

CCNA55 min5 objectives

BeginnerDailyLocked

VLANs for Two Departments: Trunking & Sticky MAC Security

Hands-on CCNA lab: build VLANs for Sales and Engineering, implement 802.1Q trunks with a hardened native VLAN, assign access ports, and apply sticky MAC port-security on access interfaces. The design uses a compact, realistic branch topology with a router-on-a-stick gateway, a distribution L2 switch, one access L2 switch, and two end hosts. Students deploy, verify, and troubleshoot VLAN reachability, trunk integrity, and port-security violations.

CCNA70 min4 objectives

BeginnerDailyLocked

Compact Branch LAN: Two VLANs, ROAS & Sticky Port Security

Configure a compact branch LAN with router-on-a-stick inter-VLAN routing, two access switches, and two user VLANs. Implement VLANs, 802.1Q trunks with a hardened native VLAN, secure user-facing ports with port-security, and verify end-to-end reachability from the hosts. Includes realistic troubleshooting of VLAN assignment, trunk allow-lists, and port-security violations.

CCNA65 min4 objectives

BeginnerDailyLocked

Campus Layer 2: VLANs, a Management VLAN & Port Security

Build and harden a small branch campus Layer 2 network with a distribution switch and two access switches. Implement VLANs, trunking, and basic port security, then verify from the end hosts and troubleshoot common L2 mistakes.

CCNA75 min6 objectives

Learn VLAN

Study the theory behind these labs — the concept explainer and step-by-step guides.

Looking for something else? Browse the full lab archive, narrow it to self-standing labs, or see today's daily lab.