What a lab actually is
A topology of real network devices — not a simulator and not a video — racked in Navi Mumbai and reserved for you alone. You open it in a browser, get a console on every device, and break things without affecting anyone else. Each lab runs 91 minutes on average, across 5 devices.
Certifications these labs are aimed at
CCNA 200-301
Fortinet · 19 labs
2 free on the demo. More on the Fortinet labs page.
Associate · 3
- Firewall Policies and NAT
3-zone + DMZ6 devices · 90 min· free on demo - FortiGate Security Gateway
Cisco side pre-configured; paste the on-canvas FortiGate config block (60 seconds) and show live NGFW: NAT, policies, real-time session table.4 devices · 90 min - Initial Setup and Interfaces
edge4 devices · 90 min· free on demo
Professional · 9
- Antivirus and SSL Deep Inspection
malware scan5 devices · 90 min - Application Control and DPI
DPI classification6 devices · 90 min - Dual-WAN SD-WAN with Load Balancing
FGT native SD-WAN, dual WAN (port1=ISP-A, port2=ISP-B).5 devices · 90 min - Explicit Web Proxy
forward proxy5 devices · 90 min - FortiGate Policies and NAT
FortiGate NGFW: interface roles, LAN-to-WAN policy with SNAT, DMZ isolation, VIP port-forward.5 devices · 90 min - IPS Intrusion Prevention
attack + protect6 devices · 90 min - Site-to-Site IPsec VPN Cisco-FortiGate
IKEv2 tunnel between a Cisco HQ router and a FortiGate branch across a simulated internet.5 devices · 75 min - Traffic Shaping and QoS
traffic classes6 devices · 90 min - Web Filtering and DNS Filter
multi-user browsing6 devices · 90 min
Expert · 7
- Enterprise Build Capstone
Full mini-enterprise: WAN edge, FortiGate security layer, collapsed L3 core, user VLANs.7 devices · 240 min - Enterprise Edge Capstone
full edge6 devices · 90 min - FortiGate to Cisco IOS Site-to-Site VPN
Interop IPsec: FortiGate HQ to Cisco IOS branch. Cisco side + PCs pre-configured; paste the FGT block.6 devices · 90 min - High Availability Active-Passive
HA cluster6 devices · 90 min - SD-WAN SLA Health Checks and Steering
FGT native SD-WAN, dual WAN (port1=ISP-A, port2=ISP-B).5 devices · 90 min - Site-to-Site IPsec VPN FGT to FGT
two sites6 devices · 90 min - SSL VPN Remote Access
remote client5 devices · 90 min
Cisco · 17 labs
8 free on the demo. More on the Cisco labs page.
Associate · 13
- VLANs and Trunking
Two IOSv-L2 switches joined by an 802.1Q trunk carrying VLAN 10 and VLAN 20. Same-VLAN hosts must reach each other across both switches; different VLANs must not.6 devices · 90 min · CCNA 200-301· free on demo - VLANs and Trunking Fundamentals
Two switches carrying two VLANs over a trunk. Hosts in the same VLAN must reach each other across both switches; hosts in different VLANs must not.6 devices · 45 min · CCNA 200-301 - Spanning Tree
Three IOSv-L2 switches cabled in a physical loop. Configure Rapid-PVST, force a specific root bridge, and confirm one link goes to blocking so the loop is broken while hosts stay reachable.5 devices · 90 min · CCNA 200-301· free on demo - VLAN Segmentation Showcase
Fully pre-configured switching demo: same-VLAN traffic crosses the trunk, cross-VLAN traffic is isolated. The simplest 'aha moment' in networking.5 devices · 90 min · CCNA 200-301 - EtherChannel
Two IOSv-L2 switches with a two-link LACP EtherChannel between them. Bundle the links into a port-channel, trunk it, and confirm both member links are bundled and forwarding.4 devices · 90 min · CCNA 200-301· free on demo - Inter-VLAN Routing
Router-on-a-stick. One IOSv router trunked to an IOSv-L2 switch carrying two VLANs. Configure 802.1Q sub-interfaces so the VLANs route between each other, and set the host default gateways.4 devices · 90 min · CCNA 200-301· free on demo - Enterprise OSPF Live Failover
Fully pre-configured - just start all nodes and present. OSPF triangle with live failover: ping end-to-end, kill a link, watch OSPF reroute in seconds.5 devices · 90 min · CCNA 200-301 - Static Routing
Three IOSv routers in a chain. Give every network a reachable path using only static routes, then prove end-to-end connectivity from PC1 to PC2.5 devices · 90 min · CCNA 200-301· free on demo - OSPF Single Area
Three IOSv routers in a triangle. Bring up OSPF area 0 on every link so each router learns all networks dynamically, then verify PC1 can reach PC2.5 devices · 90 min · CCNA 200-301· free on demo - EIGRP Routing
Three IOSv routers in a chain running EIGRP AS 100. Advertise every connected network, confirm neighbour adjacencies form and prove edge-to-edge reachability.5 devices · 90 min · CCNA 200-301· free on demo - ACLs and NAT
An IOSv edge router between an inside LAN and a simulated ISP. Configure NAT overload for the inside network and an extended ACL that permits only the required outbound traffic. Prove the policy with pings.5 devices · 90 min · CCNA 200-301· free on demo - EtherChannel and Port Security
Bundle two links into an LACP EtherChannel and watch it survive a cable pull, then lock access ports to known MACs and trigger a violation on purpose.5 devices · 75 min - InterVLAN Routing and DHCP
Route between VLAN 10/20/30 with router-on-a-stick subinterfaces, then serve each VLAN from a central DHCP pool.5 devices · 60 min
Professional · 2
- OSPF Multi-Area Enterprise
Multi-area OSPF: Area 1 - ABR - Area 0 - ABR - Area 2 with summarization.4 devices · 90 min · CCNA 200-301 - EIGRP and Route Redistribution
EIGRP AS100 and OSPF two-way redistribution with route-maps and tags on R3.4 devices · 75 min · CCNA 200-301
Expert · 2
- BGP for the Enterprise Edge
Dual-homed eBGP edge: LOCAL_PREF outbound, AS-path prepend inbound, prefix-list filtering.5 devices · 120 min · CCNA 200-301 - SD-WAN Dual-Transport Data Plane
SCAFFOLD - upload /opt/unetlab/addons/qemu/ (vtedge - Viptela 18.4.x) to boot.6 devices · 120 min
Sophos · 7 labs
2 free on the demo. More on the Sophos labs page.
Associate · 3
- Sophos NAT and DNAT Publishing
+DMZ server5 devices · 90 min· free on demo - SOPHOS SDWAN
No description set on the topology.4 devices · 90 min - Sophos XG Initial Setup and Zones
edge4 devices · 90 min· free on demo
Professional · 2
- Sophos IPS and Advanced Threat Protection
attacker6 devices · 90 min - Sophos Web Protection and App Control
multi-user6 devices · 90 min
Expert · 2
- Sophos Site-to-Site IPsec VPN
two sites6 devices · 90 min - Sophos SSL VPN Remote Access
remote client5 devices · 90 min
Palo Alto · 6 labs
2 free on the demo. More on the Palo Alto labs page.
Associate · 3
- Palo Alto App-ID Policies
The same firewall, now with a server behind the DMZ. Write App-ID based rules that permit the required applications and nothing else.4 devices · 90 min· free on demo - Palo Alto Initial Config and Zones
A PA-VM with trust, untrust and DMZ interfaces. Complete first-boot configuration, create the zones, and assign interfaces before any policy is written.4 devices · 90 min· free on demo - Palo Alto-NW
No description set on the topology.1 devices · 90 min
Professional · 1
- Palo Alto Content-ID AV-IPS-URL
attacker6 devices · 90 min
Expert · 2
- Palo Alto Decryption SSL Forward Proxy
HTTPS inspect5 devices · 90 min - Palo Alto GlobalProtect VPN
remote client5 devices · 90 min
MikroTik · 5 labs
2 free on the demo. More on the MikroTik labs page.
Associate · 2
- MikroTik RouterOS Essentials
RouterOS basics: addressing, default route, masquerade NAT, DHCP server, WAN firewall.3 devices · 60 min· free on demo - RouterOS Firewall and NAT
A MikroTik edge router with a LAN behind it and an upstream link. Build the firewall chains and source-NAT the LAN, then prove inbound traffic is dropped.5 devices · 90 min· free on demo
Professional · 2
- QoS and Queue Trees
traffic classes6 devices · 90 min - Site-to-Site IPsec VPN
two sites6 devices · 90 min
Expert · 1
- PPPoE Server and Client Isolation
access concentrator5 devices · 90 min
Mixed · 1 lab
Associate · 1
- START HERE - Firewall Lab Guide
START HERE. A visual guide to all 32 firewall & SD-WAN labs on this server - what each folder covers, logins, difficulty, and a suggested learning path. Includes a 4-vendor sandbox row (unconnected) to quickly explore any firewall.4 devices · 90 min
How to get on one
Request a free 48-hour demo. You pick two platforms, and the 16 free labs for those open immediately — credentials are emailed, there is no card and nothing to install. Paid plans unlock all 55.
NexusSec vLabs · Navi Mumbai, Maharashtra, India · catalogue generated from the live database