ZNetLab — hands-on networking labs in your browser
ZNetLab runs a real network simulation engine in the browser. You configure devices at a
Cisco IOS-style or Juniper Junos command line, watch packets move hop by hop, and are graded
automatically on the state of the resulting network — not on the text you typed.
What you can practise
- Routing — static routes, OSPFv2 with real Dijkstra SPF, EIGRP with the
composite metric and feasibility condition, RIPv2, BGP with eBGP/iBGP and recursive next
hops, redistribution, route-maps and prefix-lists.
- Switching — VLANs, 802.1Q trunking, DTP, spanning tree and RSTP,
EtherChannel with LACP and PAgP, VTP, port security.
- IPv6 — addressing, EUI-64 link-locals, Neighbor Discovery, static routing.
- Redundancy — HSRP, VRRP and GLBP, including how they differ.
- Security — access lists, NAT, zone-based firewalls with stateful
inspection, DHCP snooping and Dynamic ARP Inspection.
- QoS — the Modular QoS CLI as IOS builds it: class-maps that match,
policy-maps that act, and the
service-policy that fails at the moment it is
attached rather than when it was written — naming the class that asked for too much.
The 75% reserved-bandwidth ceiling, priority behaving as a policer as well
as a queue, and policing that marks down so a downstream policy sees the result.
- Service provider and SD-WAN — OSPF underlay with iBGP overlay, and an
SD-WAN fabric with vBond, vSmart, TLOCs, OMP and BFD.
- MPLS — LDP hellos and neighbour discovery, one local label per
prefix, downstream-unsolicited advertising with liberal retention (which is why
show mpls ldp bindings dwarfs the forwarding table), and a data plane that
pushes at the ingress, swaps in the middle and pops at the penultimate hop.
- Broadband access — PPPoE in the stages the real thing uses, so a
failure lands on the stage that caused it: PADI/PADO/PADR/PADS discovery, LCP, CHAP or
PAP against the concentrator, then IPCP handing out an address. Plus the four last
miles — fibre, DSL, microwave and satellite — into one core.
- Automation — RESTCONF, NETCONF, config templating, playbooks with real
idempotency, and configuration drift detection.
- Juniper — the Junos configuration model: candidate configuration,
commit, commit check and rollback, on the same
topology as the Cisco devices.
The labs
- Static routing between two LANs
- Enterprise campus — VLANs, trunking, router-on-a-stick
- Service provider core — OSPF underlay + iBGP overlay
- Branch edge — NAT overload and an inbound ACL
- CCNP — EIGRP and OSPF domains joined by redistribution
- Web services — DNS and HTTP across a routed network
- Spanning tree — a redundant triangle without a loop
- IPv6 — two /64 segments across a routed link
- EtherChannel — three cables, one logical link
- Zone-based firewall — inside, outside and a DMZ
- Junos and IOS — two vendors, one OSPF area
- ISP access — fibre, DSL, microwave and satellite
- PPPoE — the line is up but there is no internet
- SD-WAN — control plane, TLOCs and an OMP overlay
- Network automation — facts, templates, playbooks and drift
- MPLS — label switching across a provider core
- QoS — the policy that will not attach
- Per-VLAN spanning tree — two VLANs, two roots
- MST — one region, two instances, forty VLANs
- Private VLANs — same subnet, no conversation
- GRE — your routing protocol over somebody else’s network
- NAT — a pool out, and a server published in
- Policy routing — one host out of the other door
- BGP — a community, a local preference and a longer path
- HSRP — pull the uplink, watch the standby take over
- OSPFv3 — the same network, routed twice
- EIGRP for IPv6 — the process that starts shut down
- Named EIGRP — and a second path that is worse on purpose
- Wireless — a WLAN, an AP that joins, and a client in its VLAN
- Wireless troubleshooting — four ways it looks broken
- Four vendors, one OSPF area
Common questions
Do I need to install anything?
No. It runs in the browser and works offline once loaded. No plugin, no download, no
virtual machine.
Is this a simulator or an emulator?
Both, in two halves. This page is the simulator: protocol behaviour is reimplemented in
JavaScript rather than running vendor software, which is why it opens instantly and costs
nothing to serve — and why what it knows has an edge. Anything it does not implement is
refused with the reason instead of being silently accepted. The other half is emulation:
your own licensed images booted on a lab server, where the command line is the vendor’s
own because the software is.
Can I run real Cisco IOS images?
Not in the browser — an IOS image needs a machine emulator and gigabytes of RAM. A small
local backend can boot your own licensed images and bridge their consoles into the
workspace. ZNetLab does not distribute vendor images.
Does the free plan do anything useful?
It is the whole simulator, not a sample of it. Unlimited graded attempts, every track and
every level, topologies up to sixty devices, unlimited saved labs, the full command line
with TAB completion, packet capture with .pcap export, automation, SD-WAN,
fault injection and the subnetting tools. Nothing in the simulator is held back for a
paying account — it runs in your own browser and costs nothing to serve. What the paid
plans buy is real vendor images booting on a lab server.
Which vendors are supported?
Cisco IOS-style devices and Juniper Junos devices, on the same topology. A Junos
router and a Cisco router form an OSPF adjacency and pass traffic, because the
configuration language differs but the protocol does not.
This page needs JavaScript for the interactive parts. Everything above
describes what the page shows when it loads.