Lessons free to read with no account, and a full browser simulator on a free account — nothing to install. When you need actual Cisco, Juniper or Arista images running on real interfaces, that is here too.
R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.2 1 FULL/DR 00:00:34 10.1.12.2 Gi0/0 10.0.0.3 1 FULL/BDR 00:00:31 10.1.13.3 Gi0/1 R1# show ip route ospf | include 10.2 O 10.2.0.0/24 [110/2] via 10.1.12.2, 00:04:11, Gi0/0 R1#
Nothing here is a mock-up of a different product. These are the real commands, the real boot messages, the real interface names and the real columns of the capture window — playing at the speed you would see them.
Drag the devices in, click one port then the other. Sixty devices to a topology, saved to your browser and to your account as you work.
Loading ios-adventerprisek9-M.bin Cisco IOS Software, IOSv Software Press RETURN to get started R1 is running · console ready
One device, not the lab. About fifty seconds, and most of it is IOS waking up inside the image rather than the server thinking.
The console in the page, or over telnet from your own terminal. They share one session, so two people can watch one router.
A real .pcap, not an impression of one. Capture any
link while the lab runs, and read every header layer by layer.
Not a trial and not metered. The simulator runs in your own browser, which is why serving it costs us nothing. The lab server is where plans start.
One account, two ways to practise: a simulator that runs inside this browser tab, and a lab server that boots the vendor images you are licensed to run.
Most people learning networks hit the same wall twice. The first time is at the start, when the software costs money, or will not install, or wants a machine with more memory than the one they have. The second comes later, when the simulator runs out of road — the thing they now need to practise is a real configuration on real software, and a teaching tool cannot show it to them.
ZNetLab is built for both walls. The teaching half is a complete simulator written in JavaScript. It runs in your browser, on your own machine, which is why it is free and will stay free: serving it costs us nothing. It speaks IOS-style and Junos-style syntax, it checks your work as you go, and it covers routing, switching, MPLS, QoS, firewalls, SD-WAN and IPv6.
The lab half runs actual vendor images — IOSv, CSR1000v, Nexus, ASAv, vSRX,
vEOS and the rest — under Dynamips, IOL or QEMU on a Linux server, with consoles
you can reach from the page or from your own terminal, and captures taken by
tcpdump that open in any protocol analyser. ZNetLab ships no vendor software:
you supply the images you are licensed to run, which is the same position
any honest tool in this field takes.
Nothing is installed on your computer for either half. There is no virtual machine to keep alive, no hypervisor to configure, and no download that your work laptop will refuse. A browser is the whole requirement.
.gns3a) are read as they comeA simulator that speaks IOS-style and Junos-style syntax, with guided labs that check your work. It runs entirely on your machine, so it costs nothing to give away — and that is the whole reason it is free rather than a trial.
Actual vendor images — IOSv, CSR1000v, Nexus, ASAv, vSRX, vEOS — booting under Dynamips, IOL or QEMU on a server, with consoles you can reach from your own terminal and captures that open in any protocol analyser. Nothing to install on your machine.
tcpdump capture, exported as .pcapNot an artist's impression and not a competitor's screenshot — the actual workspace, captured from the running app.
The hard part of networking is not typing the commands. It is knowing what happened between the device that sent and the device that did not answer.
One ping, five hops. In the simulator you can stop it at any of them and read the frame.
The simulator animates every frame and will pause on one so you can open it and look — the headers, the ARP that went first, the decision each device made. That is a teaching view, and it is honest about being one: a simulated frame is always labelled as simulated.
On the lab platform the same picture comes from the wire. Each link is a Linux
bridge, and a capture is tcpdump running on it. What you download
is a plain .pcap — open it in your own analyser, send it to a colleague,
attach it to a ticket. Nothing has been reconstructed for you.
A capture reads one cable — the server runs tcpdump on
that link and the frames arrive in the window as they cross it. What you export is a real
.pcap: little-endian, LINKTYPE_ETHERNET, read by every analyser,
tshark and tcpdump, because it is the format and not an
impression of it.
Every frame the server reads, as it reads it. The window keeps your place when you scroll back and follows the newest frame when you are at the bottom.
ip.addr == 10.0.0.1 and icmp,
tcp.port == 179, !arp — a term it cannot parse is
reported, never silently droppedA simulated frame is always labelled as simulated, in the list and in the exported file. The one thing an analyser must never do is let you mistake a drawing for evidence.
A lab with eleven devices in it is a small network, and a small network still needs the screen every network has: not graphs to admire, but a list of what is wrong, attached to the thing that is wrong with it, with what to do about it.
A site is a label you typed — “HQ”, “Branch-2” — and a place with nothing running in it is reported once, against the place.
An alarm you acknowledge stays on the screen, greyed, with your name and the time on it. It leaves when the state it describes is gone — which is the only thing that can honestly clear it. An alarm's identity is what is wrong with what, so the same fault on two ports is two alarms and a restart does not resurrect one you have already seen.
Beside it: who signed in, who was refused, who was locked out, and whose console was opened on which device — ZNetLab's own authentication trail, kept separate from the devices' AAA, because conflating them would be claiming to know something it does not.
Both halves share one account, one design and one set of ideas. You move between them without noticing a seam.
The simulator does not paraphrase. show ip protocols prints what a
router prints, including the lines everyone forgets are there.
An administrator uploads an image and a device appears on the shelf, with the right RAM, disk bus and interface naming. Nobody edits JavaScript.
The Virtual PC is a Linux network namespace and the LAN Switch is a kernel bridge. Real ARP, real MAC learning, no licence.
On a real lab the frames come from tcpdump on the bridge. Simulated
frames are labelled as simulated, always.
Every running device gets a telnet port. Use the console in the page, or the terminal client you already have — they share one session.
Vendor software is licensed by its vendor. You supply what you are licensed to run — which is the only position a tool that bundles nothing can take.
There is no feature matrix with crosses in it. Every plan, including the free one, has every feature — what a plan changes is how many devices in a lab may need a vendor image, and how many labs you may run at once.
? help and tab completion.pcap export, and a frame-by-frame simulation viewtcpdump capture on any link, exported as .pcapThe lessons, the articles and the guide are open to anyone — no account, no trial, no email. An account is for running things: the simulator, and labs on the server.
Each one is a topology and a list of tasks, and each task is checked against the configuration you actually typed — not against a button you pressed.
Not a feature list. Four labs you can follow to the end, in the simulator and on the real platform, with the output you should see at each step and what it means when you do not see it.
Written by people who had to fix them, with the topology and the real output — and a lab attached where there is one, so you can reproduce the fault yourself.
show output attachedInside the analyser: which protocols belong on the cable you are reading, what their timers are supposed to be, what the packets themselves say they are, and the trouble each one is famous for.
The point of all of it. These are the things people cannot do before and can do after, which is the only honest measure of a lab platform.
Built from the handbook that ships with the server, so the help search answers from the same text the documentation does — rebuilt on every start, so it cannot drift away from what the product does.
Four places ZNetLab is the wrong answer, written down before you pay rather than discovered afterwards. If one of them is your situation, the honest recommendation is not us.
ZNetLab ships no vendor software at all. You supply what you are licensed to run, and ZNetLab's job is to recognise it and boot it correctly.
120 platforms are recognised from the image filename alone, each with the memory, disk bus, NIC model and interface naming it actually needs — so an image library you already have works unchanged, with no template to write by hand. Cisco, Juniper, Arista, Fortinet and the open-source routers sit in one topology instead of one vendor's.
If you hold no licence and need genuine IOS-XE, NX-OS or IOS-XR, nothing on our side substitutes for a licence on yours. That is a purchase from the vendor, and no amount of platform engineering here changes it. Three device types work before you own a single licence; the rest wait on you.
The free half reimplements protocol behaviour in JavaScript rather than running vendor code, which is exactly why it opens instantly and costs nothing to serve.
It starts in a browser tab with nothing installed, marks thirty-one labs against the state of the network rather than the text you typed, and never pretends: a command it does not implement is refused with the reason, and a simulated frame is labelled simulated in the list and in the exported file.
What it knows has an edge, and you will reach it. The day you need a command it was never taught, or the specific way one release behaves, a simulation cannot answer — that is the day you move to the lab server and a real image. It is the same account, which is the point, but it is not the free half.
Devices boot under Dynamips, IOL or QEMU on a Linux machine, and you reach their consoles over the network.
A six-device lab does not need six devices' worth of your own memory, and it does not stop when you close the lid. Nothing is installed on your computer, so a managed laptop cannot refuse it, and an evening that gets interrupted costs nothing — the lab is there tomorrow exactly as you left it.
It needs a network to reach. If you want a lab that runs on hardware you own, entirely offline, on a train or behind an air gap, the hosted half is not that — and you can host ZNetLab yourself, but then the server and its memory are your problem rather than ours.
Each link on a real lab is a Linux bridge and each capture is taken on it, so the frames and the timings are real in the sense that matters for protocols.
Captures you can act on rather than admire: a plain .pcap that
opens in whatever analyser you already use, 29 protocols audited against the
cable they crossed, and link conditioning — bandwidth, delay, jitter, loss —
so you can watch a protocol behave the way it does on a bad circuit.
Optics, line cards, power, cabling mistakes and the specific way a chassis fails are not reproduced here and will not be. If the exam or the change window you are preparing for turns on physical behaviour, you need the hardware, and we would rather say so now.
We publish feedback only when a real person has said it and agreed to be named. That means this section fills up slowly, and that is the point of it.
Used ZNetLab for a lab, a course or a certification? Tell us how it went — the good and the parts that wasted your time. We will ask before we print anything, and we will print it as you wrote it.
Every lesson and the whole browser simulator are free, permanently — they run in your own browser, so serving them costs us nothing. What the paid plans buy is memory on a server booting real vendor images, and they are priced by how many devices in a lab need one. Virtual PCs are never counted, on any plan.
Per month. A device counts only when it needs a vendor image — Virtual PCs, LAN Switches and NAT Clouds are unlimited on every plan, including the free one. Past twenty devices, talk to support.
See the plans and work out your costThe eight that come up before anybody signs up, answered in full rather than pointed at a sales page. Every answer is on this page whether you open it or not.
Ask something elseYes, and free means complete — it is not metered and nothing is held back for a
paying account. Every lesson, every track and every level, unlimited attempts,
topologies up to sixty devices, packet capture with .pcap export,
automation and fault injection. Reading the lessons needs no account at all; the
simulator needs a free one so it can save your work. It runs entirely in your own
browser, so it costs nothing to serve. The paid plans buy time on a server that
boots real vendor images, which is the part that costs money.
No. IOS, Junos and other vendor software are licensed by their vendors, and redistributing them would be infringement. You supply images you are licensed to run — the only honest position a tool in this field can take. The built-in Virtual PC, LAN Switch and NAT Cloud need no image at all.
Not on your own machine. Emulation runs on a Linux lab server under Dynamips, IOL or QEMU and reaches you through the browser. Only the server administrator needs virtualisation.
For the protocols, yes. FRRouting, VyOS, MikroTik CHR, Cumulus VX and Arista vEOS are free, and between them cover BGP, OSPF, IS-IS, MPLS L3VPN, VXLAN with EVPN, IPsec, multicast and QoS. What they do not give you is Cisco's command syntax, which is what a Cisco Modeling Labs licence is for.
Memory on a server, counted in devices. A plan sets how many devices in one lab may need a vendor image: Free is two at $0.00, Starter four at $2.00 a month, Standard six at $3.00, Advanced ten at $10.00 and Expert twenty at $20.00. Virtual PCs, LAN Switches and NAT Clouds need no image and are never counted, however many you connect. One account runs one lab at a time on every plan, because a lab belongs to the window that opened it. Every feature is in every plan, including the free one. Past twenty devices, or for a company account, talk to support and an administrator will build the plan around what you need.
No, and that is deliberate. A real lab runs in one browser tab at a time. The window that started the work keeps it, and a second tab or a second browser is told so immediately rather than quietly starting a second set of devices you would be paying for. The browser simulator has no such limit, because it runs on your own machine and costs nobody anything. Signing in on a second device signs the first one out, so a phone and a laptop each need their own account.
The simulator saves as you go, into this browser, and reopens where you left off. You can also save a topology to your account — File → Save to the portal — and open it on another machine, or save it to a .nblab file and keep it yourself. On the lab platform a topology belongs to your account rather than to the tab, and devices left running are warned and then stopped after thirty idle minutes, so nothing bills you overnight.
Whatever you hold a licence for. ZNetLab recognises 120 platforms by their image filenames — Cisco IOSv, IOSvL2, CSR1000v, Nexus 9000v, ASAv and IOS-XRv; Juniper vSRX and vMX; Arista vEOS; Nokia, Huawei, HPE, Aruba and Extreme; Fortinet, Palo Alto, Check Point and Sophos on the firewall side; and the open-source routers MikroTik CHR, VyOS, FRRouting and Cumulus VX — and it sets the memory, disk bus and interface naming each one needs. The open-source ones are free to download and between them cover BGP, OSPF, IS-IS, MPLS, VXLAN and IPsec with no licence at all.
The simulator is free and opens in this tab. When a lesson stops being enough and you need genuine vendor software on real interfaces, the same account already has it — from $0.00, and you only ever pay for devices that need an image.