Core services
Multiple VLANs, inter VLAN routing, DNS, DHCP, monitoring, logging, and protected server access.
Network lab · Completed
A secure Cisco environment linking headquarters and a branch, built to be tested, broken, and repaired.
This project turns CCNA topics into a realistic network across two locations. It documents the design, configuration, verification, packet evidence, failure diagnosis, and repair process instead of showing only the final topology.
TYPENetwork engineering lab
PLATFORMCisco routing and switching
FOCUSCCNA · security · operations
DELIVERYEvidence · repository documentation
01 · The goal
The lab models two business locations with segmented users and services, dynamic routing, controlled internet access, encrypted traffic between sites, and centralized operational visibility.
Every major feature has an acceptance test. Selected configurations were intentionally broken so the project could document the symptoms, evidence, root cause, repair, and final verification.
02 · Network topology
Headquarters provides central services and visibility. The branch retains local access while learning remote routes and reaching approved resources through the encrypted tunnel.
Multiple VLANs, inter VLAN routing, DNS, DHCP, monitoring, logging, and protected server access.
OSPF route exchange, NAT at the edge, ACL enforcement, and encrypted traffic between sites.
Segmented client networks, local switching and routing, service access, monitoring, and controlled failure scenarios.
03 · Build scope
Each area was configured and validated individually, then tested again across VLAN, routing, service, security, and site boundaries.
Separate user, server, management, voice, and guest traffic into intentional broadcast and security boundaries.
Route required traffic between VLANs while preserving clear gateways, addressing, and troubleshooting paths.
Exchange routes dynamically between the headquarters and branch routing layers and verify neighbor and route behavior.
Provide repeatable client addressing and name resolution across segmented networks and routed site boundaries.
Translate internal addressing at the internet edge and verify expected outbound traffic without exposing internal networks.
Allow required business flows and block unnecessary access between users, servers, guests, and management networks.
Protect traffic moving between headquarters and the branch and validate the encrypted tunnel under normal and failed conditions.
Collect logging and monitoring data centrally so routing, security, service, and device events can be correlated.
Use Wireshark captures and deliberately broken configurations to prove behavior, isolate faults, and document each repair.
04 · Validation workflow
The project documentation records the working configuration, controlled failures, diagnosis process, repairs, and final verification.
Defined the two site topology, VLAN plan, addressing, trust boundaries, services, and acceptance tests before configuring devices.
Configured switching, routing, OSPF, DHCP, DNS, NAT, ACLs, VPN connectivity, and central operational visibility.
Introduced controlled faults across Layer 2, Layer 3, services, security policy, and the VPN, then diagnosed each issue from evidence.
Captured working configurations, route and neighbor output, logs, packet traces, failure reports, repair notes, and repository documentation.
Verified evidence
The case study includes the topology, sanitized configurations, verification commands, central logs, Wireshark captures, fault records, repair notes, and repository documentation.
The network was built, tested under normal conditions, exposed to controlled faults, repaired from evidence, and verified after each change. The supporting notes preserve the reasoning behind the final configuration.
The larger takeaway