ITCertFoundryTechnical training system

CCNP ENCOR hands-on lab library

Build Enterprise-Grade Networks in Cisco Modeling Labs.

Every lab is a step-by-step guide you follow while building, configuring, verifying, breaking, and repairing a real topology yourself. Cisco Modeling Labs is the recommended platform for ENCOR — it's the only free-tier-friendly option that behaves like real IOS XE for BGP, multiarea OSPF, and multicast. A few topics have no viable hands-on platform at all and are guided output-analysis activities instead — labeled clearly, never disguised as a live controller.

Architecture

🔒 Locked

Two-Tier Campus Core with HSRP Redundancy

Recommended platform: Cisco Modeling Labs (CML). This topology and HSRP behavior are realistic on CML's IOS XE nodes; Packet Tracer can approximate basic HSRP but does not model preemption timing and failover behavior reliably enough for this lab's break/fix step, so CML is the platform this lab is written for.

Preview →
🔒 Locked

Interpreting and Building a QoS Policy on a WAN Edge Router

This objective's core skills — class-map/policy-map syntax, LLQ/CBWFQ, and interface application — are genuinely supported in Cisco Packet Tracer, making it a viable free platform for this specific lab. Cisco Modeling Labs remains a good option too if you have it, and will show more realistic 'show policy-map interface' counters under real traffic load.

Preview →

Virtualization

🔒 Locked

Configuring and Verifying VRF-Lite

Recommended platform: Cisco Modeling Labs (CML). VRF-Lite is well supported on CML's IOS XE nodes. Packet Tracer's VRF support is limited and inconsistent across versions, so CML is the platform this lab is written for.

Preview →
🔒 Locked

Building a GRE Tunnel Between Two Routers

Recommended platform: Cisco Modeling Labs (CML). GRE tunnel behavior and OSPF-over-tunnel adjacency are realistic on CML's IOS XE nodes. Packet Tracer supports basic GRE tunnel configuration reasonably well too, making it a workable secondary option specifically for this lab.

Preview →
🔒 Locked

Site-to-Site IPsec VPN Using a Virtual Tunnel Interface

Recommended platform: Cisco Modeling Labs (CML). IKEv2/IPsec VTI configuration requires real crypto engine behavior that Packet Tracer does not model — this lab is written specifically for CML's IOS XE nodes.

Preview →
🔒 Locked

Building a VXLAN Overlay Between Two Linux Hosts

A full LISP control-plane deployment (Map Server/Resolver infrastructure) requires licensed platform features this course cannot provide — the LISP portion of this lab is guided output analysis, using the same representative-output approach as the SD-Access activity in Domain 1.0. VXLAN itself, however, is genuinely achievable hands-on: Linux's built-in 'ip link add type vxlan' support works on ordinary Linux host nodes in Cisco Modeling Labs (or any Linux VM/container), making the VXLAN half of this lab fully real, not simulated.

Preview →

Infrastructure

🔒 Locked

Troubleshooting Trunking and EtherChannel

This objective's core skills — trunk configuration, native VLAN, and EtherChannel with LACP — are genuinely supported in Cisco Packet Tracer, making it a viable free platform for this lab. Cisco Modeling Labs remains a good option too and will show more realistic DTP negotiation behavior if you want to explore it further than this lab requires.

Preview →
🔒 Locked

Configuring RSTP and a Multi-Instance MST Region

Recommended platform: Cisco Modeling Labs (CML). MST region behavior and multi-instance root election are realistic on CML's IOS XE/L2 nodes. Packet Tracer's MST support is limited and inconsistent, so CML is the platform this lab is written for.

Preview →
🔒 Locked

Configuring and Verifying Root Guard and BPDU Guard

This objective's core skills are well supported in both Cisco Modeling Labs and Cisco Packet Tracer — either platform works fine for this lab.

Preview →
🔒 Locked

Building a Multiarea OSPF Network with a Stub Area

Recommended platform: Cisco Modeling Labs (CML). Multiarea OSPF, stub areas, and route summarization are fully and realistically supported on CML's IOS XE nodes. Packet Tracer supports basic single-area OSPF reasonably well but its multiarea and stub-area behavior is inconsistent, so CML is the platform this lab is written for.

Preview →
🔒 Locked

Configuring eBGP Peering and Influencing Best-Path Selection

Recommended platform: Cisco Modeling Labs (CML). BGP session negotiation, path attributes, and best-path selection behave realistically on CML's IOS XE nodes. Packet Tracer's BGP support is limited and not recommended for this lab.

Preview →
🔒 Locked

Redirecting Traffic with Policy-Based Routing

This objective's core skills — access lists, route-maps, and PBR — are well supported in both Cisco Modeling Labs and Cisco Packet Tracer. Either platform works fine for this lab.

Preview →
🔒 Locked

Configuring NTP Client and Server Roles

This objective's core skills are well supported in both Cisco Modeling Labs and Cisco Packet Tracer. Either platform works fine for this lab. PTP hardware-timestamping behavior itself is not practically labbable on either free platform and is covered through the lesson's guided explanation instead.

Preview →
🔒 Locked

Configuring PAT for Internet-Bound Traffic

This objective's core skills are well supported in both Cisco Modeling Labs and Cisco Packet Tracer. Either platform works fine for this lab.

Preview →
🔒 Locked

Configuring HSRP with Interface Tracking

This objective's core skills — HSRP, VRRP, and interface tracking — are well supported in both Cisco Modeling Labs and Cisco Packet Tracer. Either platform works fine for this lab.

Preview →
🔒 Locked

Configuring PIM Sparse Mode and Verifying RPF

Recommended platform: Cisco Modeling Labs (CML). PIM-SM, RP behavior, and RPF checks are realistically supported on CML's IOS XE nodes. Packet Tracer's multicast/PIM support is too limited and inconsistent for this lab.

Preview →
🔒 Locked

Configuring IGMPv3 and Source-Specific Multicast

Recommended platform: Cisco Modeling Labs (CML). IGMPv3 and SSM behavior are realistically supported on CML's IOS XE nodes. Packet Tracer's multicast/PIM support is too limited for this lab.

Preview →

Network Assurance

🔒 Locked

Ping, Traceroute, Conditional Debug, SNMP, and Syslog

This objective's core skills are well supported in both Cisco Modeling Labs and Cisco Packet Tracer. Either platform works fine for this lab.

Preview →
🔒 Locked

Configuring Flexible NetFlow

Recommended platform: Cisco Modeling Labs (CML). Flexible NetFlow configuration and statistics are realistically supported on CML's IOS XE nodes. Packet Tracer's NetFlow support is too limited for this lab.

Preview →
🔒 Locked

Configuring Local SPAN Traffic Mirroring

Local SPAN is well supported in both Cisco Modeling Labs and Cisco Packet Tracer, making either platform viable for this lab. RSPAN and ERSPAN require a multi-switch (RSPAN) or routed (ERSPAN) topology beyond what this single-switch lab covers — the Network Assurance 4.4 lesson explains their configuration differences at the concept level, since building genuinely separate multi-switch and Layer-3 topologies for each isn't practical to add on top of this lab's core skill.

Preview →
🔒 Locked

Configuring IP SLA Tracked Static Routes

Recommended platform: Cisco Modeling Labs (CML). IP SLA operations and tracking are realistically supported on CML's IOS XE nodes. Packet Tracer's IP SLA support is too limited for this lab.

Preview →
🔒 Locked

Querying and Configuring a Device with NETCONF and RESTCONF

This lab is genuinely achievable without any licensed platform: NETCONF and RESTCONF are standard, built-in features on IOS XE devices (including CML's IOS XE nodes), reachable using ordinary tools — a Python NETCONF library (like ncclient) for NETCONF, and curl or Postman for RESTCONF. Recommended platform: Cisco Modeling Labs (CML) for a real IOS XE target device; the client-side tooling runs on any ordinary Linux host or your own machine.

Preview →

Security

🔒 Locked

Configuring Device Access with Local, TACACS+, and Fallback AAA

Recommended platform: Cisco Modeling Labs (CML). AAA, TACACS+ server groups, and method-list fallback behavior are realistically supported on CML's IOS XE nodes. Packet Tracer's TACACS+/RADIUS support is too limited for this lab.

Preview →
🔒 Locked

Configuring Management/Data-Plane ACLs and Control Plane Policing

Recommended platform: Cisco Modeling Labs (CML). CoPP configuration and policy-map statistics are realistically supported on CML's IOS XE nodes. Packet Tracer's CoPP support is too limited for this lab; ACL configuration alone would work on either platform.

Preview →

Automation and Artificial Intelligence

🔒 Locked

Reading, Troubleshooting Python, and Constructing Valid JSON

Recommended platform: any local machine with Python 3 installed (no network device or CML topology required — this lab is entirely local scripting/text work, genuinely runnable by every student regardless of lab-platform access).

Preview →
🔒 Locked

Interpreting HTTP/REST Response Codes and JSON Error Payloads

This is a local, text-based reasoning activity — no live API or network device is required, since the objective itself is about correctly interpreting representative response evidence, exactly matching how it's tested on the exam.

Preview →
🔒 Locked

Configuring a Device via RESTCONF PATCH and NETCONF edit-config/commit

Recommended platform: Cisco Modeling Labs (CML), using an IOS XE node with RESTCONF and NETCONF both enabled. This lab goes beyond the Network Assurance 4.7/4.8 lab's Describe-level GET-only coverage into actual configuration changes (PATCH/PUT and edit-config/commit), requiring a real, writable RESTCONF/NETCONF-capable target — Packet Tracer does not support either protocol.

Preview →
🔒 Locked

Configuring an EEM Applet for Event-Driven Interface Diagnostics

Recommended platform: Cisco Modeling Labs (CML) or Packet Tracer — EEM applet configuration with syslog event detectors and CLI-command actions is supported on both platforms for this lab's scope.

Preview →

Guided Analysis Activities

For topics with no viable hands-on platform (Catalyst Center AI workflows, SD-WAN internals, TrustSec) — real, sanitized output and API payloads instead of a live controller.

🔒 Locked

SD-WAN Control and Data Plane: Guided Output Analysis

There is no free-tier way to stand up a real Cisco Catalyst SD-WAN control plane (vManage/vSmart/vBond) — it requires licensed infrastructure this course will never claim to provide. This is a guided output-analysis activity: every command output below is a realistic, representative sample, clearly labeled as such, not captured from a live controller. The goal is reading fluency — recognizing healthy versus broken control-plane state from real evidence — not hands-on controller administration.

Preview →
🔒 Locked

SD-Access Fabric Roles and the Fusion Router Boundary

A real SD-Access fabric requires Cisco Catalyst Center and licensed fabric-capable hardware that this course cannot provide or claim to simulate. This is a guided output-analysis activity using representative, clearly labeled sample output and the fusion router route-leak scenario from the Architecture 1.6 lesson — the goal is recognizing fabric roles and diagnosing the routing boundary correctly, not hands-on fabric provisioning.

Preview →
🔒 Locked

Hypervisors and Virtual Switching: Guided Analysis

A full hypervisor cluster (vCenter, distributed vSwitches, shared datastores) is well beyond what this course can provide for free. This is a guided output-analysis activity using a representative single-host topology and configuration tables — the goal is reading fluency for vSwitch/port-group design, not hands-on hypervisor administration. If you have access to VirtualBox, Proxmox, or ESXi in a personal lab, everything described here maps directly onto real settings you can go configure yourself.

Preview →
🔒 Locked

Bidir-PIM and MSDP: Guided Analysis

A genuine many-to-many Bidir-PIM deployment or a real two-domain MSDP topology requires more infrastructure and address planning than is practical to build for a guided exercise, and both objectives are Describe-level in the blueprint. This is a guided output-analysis activity using representative, clearly labeled sample output — the goal is reading fluency for these two less commonly deployed but exam-relevant technologies, building on the hands-on PIM-SM and RPF skills from the earlier labs in this domain.

Preview →
🔒 Locked

Catalyst Center Assurance: Guided Analysis

Cisco Catalyst Center is a licensed, centrally hosted platform that this course cannot provide free access to. This is a guided output-analysis activity using a representative, clearly labeled assurance dashboard summary — the goal is reading fluency for interpreting assurance output and correctly framing AI-assisted suggestions as requiring validation, not hands-on platform administration.

Preview →
🔒 Locked

REST API Authentication: Guided Analysis

This is a guided output-analysis activity rather than a hands-on build, since the point of this objective is evaluating authentication/authorization design decisions and their consequences — genuinely well suited to reading and reasoning about representative examples rather than a lab build. If you want hands-on RESTCONF request practice, the Network Assurance 4.7/4.8 lab (encor-netconf-restconf-lab) already covers that with a real IOS XE target.

Preview →
🔒 Locked

Threat Defense, Endpoint Security, and NGFW: Guided Analysis

Threat-defense platforms, endpoint security suites, and NGFW appliances are licensed commercial products this course cannot provide free access to, and all three objectives here are Describe-level in the blueprint. This is a guided output-analysis activity using representative, clearly labeled logs and scenarios — the goal is reading fluency for cross-component integration and correct deployment-mode reasoning, not hands-on product administration.

Preview →
🔒 Locked

TrustSec SGT Propagation and MACsec: Guided Analysis

A genuine TrustSec/ISE deployment and a real multi-switch MACsec topology require licensed platform features and physical topology complexity beyond what this course can practically provide, and both objectives are Describe-level in the blueprint. This is a guided output-analysis activity using the exact representative scenarios from the Security 5.10 and 5.11 lessons — the goal is reading fluency for diagnosing propagation and topology gaps in identity-based segmentation and Layer 2 encryption.

Preview →
🔒 Locked

YANG Modeling and Catalyst Center / SD-WAN Manager API Structure: Guided Analysis

Catalyst Center and Catalyst SD-WAN Manager are licensed commercial controller platforms this course cannot provide free access to. This is a guided output-analysis activity using representative, clearly labeled YANG excerpts and API responses — the goal is reading fluency for YANG structure and API request/response patterns, not hands-on controller administration.

Preview →
🔒 Locked

Agent-Based vs. Agentless Orchestration and AI-Assisted Operations: Guided Analysis

These three objectives are conceptual/comparative (tool architecture tradeoffs, and AI-assisted operations use cases and risk), not hands-on configuration tasks with a concrete device target. This is a guided reasoning activity using the exact representative scenarios from the 6.10, 6.11, and 6.12 lessons — the goal is sound judgment applied to realistic scenarios, matching how this content is tested on the exam.

Preview →

Capstone Projects

🔒 Locked

Capstone: Enterprise Campus — HA Core, EtherChannel, Hardened Spanning Tree

Recommended platform: Cisco Modeling Labs (CML). Every piece of this capstone — HSRP, LACP EtherChannel, RSTP/MST root placement, Root Guard, BPDU Guard — is realistically supported on CML's IOS XE nodes. This is every Architecture and Infrastructure Layer 2 lesson from this course combined into one coherent campus design: if you can build and troubleshoot this from a blank canvas, you've internalized the domain, not just the individual pieces.

Preview →
🔒 Locked

Capstone: Enterprise WAN — Site-to-Site VPN, Multiarea OSPF, eBGP Edge, PBR, and NAT

Recommended platform: Cisco Modeling Labs (CML). Every technology here — GRE, IPsec tunnel protection, multiarea OSPF, eBGP, PBR, VRF-Lite, NAT — is realistically configurable on CML's IOS XE nodes. This is the WAN half of the Virtualization and Infrastructure Routing domains combined into one realistic branch-connectivity design: a real enterprise WAN edge looks almost exactly like this.

Preview →
🔒 Locked

Capstone: Secure Enterprise Core — Layered AAA, ACLs, and Control Plane Policing

Recommended platform: Cisco Modeling Labs (CML). AAA with TACACS+/RADIUS, ACLs, and CoPP policy-map statistics are all realistically supported on CML's IOS XE nodes. This capstone consolidates every device-hardening technique from the Security domain onto one router, and — critically — teaches the harder skill of diagnosing WHICH layer is actually at fault when access fails, since AAA, ACLs, and CoPP can all independently block a session in ways that look similar from the outside.

Preview →
🔒 Locked

Capstone: Automated Network Operations — RESTCONF/NETCONF, Python Validation, EEM Remediation, and Telemetry

Recommended platform: Cisco Modeling Labs (CML) for Ops-Router, plus any local machine with Python 3 for Automation-Host. RESTCONF, NETCONF, EEM, IP SLA, NetFlow, and SPAN are all realistically configurable on CML's IOS XE nodes. This capstone is the payoff of the whole Automation & AI domain combined with Network Assurance: a single router that detects a problem (IP SLA), automatically reacts to it (EEM), stays configurable and auditable via API (RESTCONF/NETCONF, validated by a real Python script), and remains observable throughout (NetFlow, SPAN).

Preview →