CCNA: One Year to Understand What Is Behind "It Just Works"

I’ve always wanted to pass the CCNA and commit to it seriously. Once you start getting into it, networking becomes a genuinely fascinating subject.

But I have to be honest, and I fully understand beginners who give up. Unlike web development or front-end, for example, where you directly see the result of what you’re doing, it’s normal to feel more motivated by code. Within a few lessons, you already have the start of something concrete in front of you, and so the feeling that your efforts are paying off, even if the road ahead is still long.

With networking, everything happens in the background, in the so-called back-end. Naturally, it’s harder to stay motivated, because the subject is long and sometimes tedious. But once you discover what’s actually happening behind the scenes, it all becomes fascinating. You don’t realize how many things are working in the background just so that, simply, “it works”.

And one thing must not be forgotten: absolutely everything relies on the network. Cloud, data centers, AI, all of it depends on it. It’s the foundation of infrastructure.

It took me about a year of preparation to pass the exam, on my second attempt. I studied after work and also on weekends, which means combining both. There’s no miracle: if you want to pass your CCNA, you have to put in the work, really work. Fair warning, it can literally turn into a second job, a bit like a student juggling classes and a part-time job.

But I promise you this: if you’re fully committed, the subject is fascinating.

The tools

First of all, I strongly recommend buying and reading the official guide first: CCNA 200-301 Official Cert Guide Library (Wendell Odom, David Hucaby, Jason Gooley). It’s a real bible. It covers every topic in a simple and pedagogical way, and prepares you 100% for the exam.

For a more condensed review: CCNA 200-301 Exam Cram (Anthony Sequeira), which summarizes the key points to know and remember in a clear and straightforward way.

Both include practice tests, which are extremely useful.

Then, you obviously need to install Cisco Packet Tracer, because you’ll need a lot of hands-on practice with real simulations. And if a topic gets you stuck, I’d recommend having an AI at hand (Claude or ChatGPT) to have it explained to you differently. In my case, I would ask it to generate network exercises with a simple diagram, then I’d redo the exercise myself on Packet Tracer.

My advice: on Packet Tracer, create several types of diagrams and blank exercises, and save them under different names. (You will find concrete examples of exercises further down in this article.)

All of this, once you’ve finished the official guide 100%, done the exercises, and followed these recommendations.

Getting started with studying

If you already have a demanding job like I do, my advice is to take it slow so you don’t get overwhelmed and want to give up entirely. Start by calmly reading the official guide to properly understand what’s being discussed, do the exercises, and let it explain each topic to you. Take the time to really read and, above all, to understand.

You absolutely need to master the following topics (taken from the official guide and Cisco’s public blueprint, with no exam spoilers):

  • Network Fundamentals (20%): role of network components (routers, Layer 2/Layer 3 switches, firewalls, access points), network topology architectures (two-tier, three-tier, spine-leaf), cabling, TCP vs UDP, IPv4/IPv6 addressing and subnetting, virtualization, switching concepts.
  • Network Access (20%): VLANs, trunking and 802.1Q, discovery protocols (CDP/LLDP), EtherChannel, Spanning Tree (Rapid PVST+), wireless architectures and fundamentals.
  • IP Connectivity (25%): this is the biggest chunk. Routing tables, router forwarding decisions, IPv4/IPv6 static routing, single-area OSPFv2, first-hop redundancy protocols (FHRP).
  • IP Services (10%): NAT, NTP, DHCP and DNS, SNMP, syslog, SSH, QoS, TFTP/FTP.
  • Security Fundamentals (15%): security concepts, access control, VPN (IPsec), access control lists (ACL), Layer 2 security (DHCP snooping, port security), AAA, wireless security (WPA2/WPA3).
  • Automation and Programmability (10%): impact of automation, controller-based networking, SDN (control plane / data plane separation), REST APIs, JSON format, tools like Ansible.

Yes, that’s a lot, and I won’t lie to you: the CCNA is a difficult exam. The passing score is high (reportedly around 82-85% of correct answers, according to various sources), and it’s not just about answering questions. There are real simulations you need to complete, where you have to configure and verify equipment under realistic conditions. That’s what really sets it apart from a purely theoretical exam, and it’s also why practicing on Packet Tracer isn’t optional.

And above all, don’t underestimate any topic whatsoever. Given the sheer amount of material and the high passing score, a single poorly mastered domain can be enough to make you fail the exam. You can’t afford to skip anything by telling yourself “that one barely shows up, I’ll just skim it”. Everything counts, and on exam day, you have zero control over which topics come up. You’re better off being solid across the board than brilliant in three domains and shaky everywhere else.

The first exam (failed)

After several months of serious studying, I felt ready. And despite all of that… I failed the exam by a small margin, with around 75% on average.

I won’t lie to you, it hit my morale pretty hard. First because the exam had cost me 300 dollars, and then because I was leaving on vacation right after. In my head, clearly, I didn’t deserve to go on vacation after failing such an important exam. And to be completely honest, that vacation was partly ruined: I couldn’t disconnect, I kept thinking about the CCNA even while on holiday.

So right after my vacation, I set up a new plan, a more intensive one. Like I said: there’s no miracle, the CCNA is difficult, you really have to be all in.

New study routine

After this first failure, I decided to rethink my entire revision and training strategy.

In the morning, during my commute to the office, I would focus on a “CCNA cheat sheet”, a document that summarizes everything you need to know by heart. I forced myself to re-read it every single day, morning and evening, to memorize properly and not forget the slightest detail.

Having already read and practiced the official guide, I obviously wasn’t starting from zero. But I wanted to give myself every chance for the second exam.

So very simply, I spent all my evenings on Cisco Packet Tracer, with ChatGPT or Claude next to me. I would ask them to create diagrams with tasks and exercises in the style of the CCNA exam. I would do the exercise on Packet Tracer, then ask for a detailed correction: what I had forgotten, what I could have done better.

It’s very important to build the habit and know the commands by heart, because once again, there are real simulations in the exam, and they are critical for the final score.

So sorry if I insist, but the combination of cheat sheet + exercises on Packet Tracer really teaches you to master the subject.

This period lasted a few months. Then, I felt 100% ready. And guess what? I passed the exam on the second attempt. :)

The labs: train like it’s the real exam

As promised, here are some concrete examples of exercises, in the same spirit as the ones I used to generate during my preparation.

An important clarification: these labs are AI-generated. There is no exam spoiler in there, no Cisco question, nothing confidential. And actually, this is not even specifically CCNA material: it’s networking, plain and simple. Configuring a router, setting up VLANs, running OSPF, these are universal skills, whatever the certification.

The instructions are deliberately in English, like in the exam. And like in the exam, no command is given to you: it’s up to you to know them.

My opinion is simple: if you cannot do these labs comfortably, without looking up the commands at every step, don’t book your exam yet. It’s not a criticism, it’s a barometer.

And don’t forget the practice tests included in the two books mentioned above: they are excellent. The combination of both, labs + practice tests, gives you an honest view of your level. When you can chain the labs without hesitating and your practice test scores are consistently above the passing threshold, then you’re ready.

One last thing before the labs, and it goes back to what I said earlier about not skipping anything. IPv6 is the topic almost everyone underestimates. People tell themselves it’s rare in production, so they skim it. But it is clearly in the blueprint, both in the addressing part and in the static routing part, and it will not be optional forever. So most labs below have an IPv6 add-on section, and the last one is dedicated entirely to it. Do them. This is exactly the kind of gap that costs you a few percent, and a few percent is exactly what I was missing on my first attempt.

Exercise 1 – Device Configuration & SSH

PC1 ---------------- G0/0 [R1] G0/1 ---------------- PC2
192.168.1.10/24                      192.168.2.10/24

Tasks:

  1. Configure the hostname R1 and the domain name lab.local.
  2. Configure both interfaces with the first usable address of each subnet and enable them.
  3. Secure privileged EXEC access with an encrypted secret.
  4. Create a local user account and enable SSH version 2.
  5. Allow only SSH connections on the VTY lines.
  6. Encrypt all plaintext passwords in the configuration.
  7. Configure a MOTD banner.
  8. From PC1, verify connectivity to PC2, then open an SSH session to R1.
  9. Save the configuration.

IPv6 add-on (dual-stack):

  • LAN 1: 2001:db8:1::/64, LAN 2: 2001:db8:2::/64.
  • Enable IPv6 routing on R1.
  • Configure each interface with the ::1 address of its prefix, and give the PCs the ::10 address.
  • Display the link-local addresses generated automatically and identify their prefix.
  • Verify connectivity with ping over IPv6, then open an SSH session to R1 using its IPv6 address.
LAN A                                            LAN B
192.168.10.0/24                          192.168.20.0/24
    |                                              |
   G0/0                                          G0/0
   [R1] G0/1 ----- 10.0.0.0/30 ----- G0/1 [R2]
        G0/2 ----- 10.0.1.0/30 ----- G0/2   (backup link)

Tasks:

  1. Configure all interfaces. Routers use the first usable address on their LAN.
  2. Configure static routes on both routers through the primary link.
  3. Configure floating static routes through the backup link with an administrative distance of 200.
  4. Verify that the routing table only shows the primary routes.
  5. Shut down the primary link and verify that the floating static routes take over.
  6. Test connectivity with ping at each step.
  7. Save the configuration.

IPv6 add-on (dual-stack):

  • LAN A: 2001:db8:10::/64, LAN B: 2001:db8:20::/64.
  • Primary link: 2001:db8:0:12::/64, backup link: 2001:db8:0:13::/64.
  • Enable IPv6 routing and configure all interfaces.
  • Configure IPv6 static routes through the primary link, then floating IPv6 static routes through the backup link with an administrative distance of 200.
  • Shut down the primary link and verify the failover in the IPv6 routing table.

Exercise 3 – VLANs & Inter-VLAN Routing (Router-on-a-Stick)

                    [R1]
                     | G0/0 (trunk)
                   Fa0/24
                   [SW1]
      Fa0/1 -------- Fa0/2
       PC1            PC2
     VLAN 10        VLAN 20

VLAN 10 (Sales):      192.168.10.0/24
VLAN 20 (HR):         192.168.20.0/24
VLAN 99 (Management): 192.168.99.0/24

Tasks:

  1. Create VLAN 10 (Sales), VLAN 20 (HR) and VLAN 99 (Management).
  2. Assign Fa0/1 to VLAN 10 and Fa0/2 to VLAN 20 as access ports.
  3. Configure Fa0/24 as a trunk with VLAN 99 as the native VLAN.
  4. On R1, create one subinterface per VLAN with 802.1Q encapsulation and the first usable address of each subnet.
  5. Configure an SVI on SW1 in VLAN 99 with a default gateway, for remote management.
  6. Verify that PC1 and PC2 can ping each other through R1.
  7. Verify the trunk status and the VLAN assignments.
  8. Save the configuration.

IPv6 add-on (dual-stack):

  • VLAN 10: 2001:db8:10::/64, VLAN 20: 2001:db8:20::/64.
  • Enable IPv6 routing on R1 and add an IPv6 address to each subinterface, keeping the same 802.1Q encapsulation.
  • Let the PCs obtain their address automatically through SLAAC.
  • Verify that the two VLANs can reach each other over IPv6, and check which address the PCs picked.

Exercise 4 – DHCP Server & Relay

PC1 ----- [SW1] ----- G0/0 [R1] G0/1 ----- SRV1
VLAN 10                                192.168.50.10/24
192.168.10.0/24                        (DHCP server)

Tasks:

  1. Configure R1 interfaces with the first usable address of each network.
  2. On R1, create a DHCP pool named OFFICE for 192.168.10.0/24: default gateway, DNS server 8.8.8.8, and exclude the first 10 addresses.
  3. Verify that PC1 obtains an IP address automatically.
  4. Now disable the pool on R1, configure the DHCP service on SRV1 instead, and configure R1 to relay DHCP requests from the LAN to SRV1.
  5. Verify that PC1 still obtains an address, and check the bindings.
  6. Save the configuration.

Exercise 5 – OSPF Single Area with Default Route Propagation

[ISP] ----- [R1] ----- [R2] ----- [R3]
             |          |          |
           LAN1       LAN2       LAN3

LAN1: 192.168.1.0/24     R1-R2: 10.1.12.0/30
LAN2: 192.168.2.0/24     R2-R3: 10.1.23.0/30
LAN3: 192.168.3.0/24

Tasks:

  1. Configure IP addressing on all routers.
  2. Configure OSPFv2 process 1, area 0, with manual router IDs (1.1.1.1, 2.2.2.2, 3.3.3.3).
  3. Advertise the connected networks using exact wildcard masks.
  4. Configure all LAN interfaces as passive.
  5. Verify OSPF neighbor adjacencies and the routing table.
  6. On R1, configure a default static route towards the ISP and propagate it through OSPF.
  7. Verify that R3 learns the default route.
  8. Test end-to-end connectivity and save the configuration.

Exercise 6 – Standard & Extended ACLs

PC1 (192.168.1.10) ----+
                       [SW1] ----- G0/0 [R1] G0/1 ----- SRV1
PC2 (192.168.1.20) ----+                          192.168.50.10/24
                                                  (HTTP server)

Tasks:

  1. Configure all interfaces.
  2. Create an extended ACL: deny HTTP traffic from PC1 to SRV1, allow ICMP from PC1, and permit all other traffic.
  3. Apply the ACL on the most appropriate interface and in the correct direction.
  4. Create a standard ACL that allows only PC2 to access the VTY lines of R1.
  5. Verify: PC1 can ping SRV1 but cannot open the web page, PC2 can do both, and only PC2 can connect to R1 remotely.
  6. Check the ACL hit counters.
  7. Save the configuration.

IPv6 add-on (dual-stack):

  • LAN: 2001:db8:1::/64, server segment: 2001:db8:50::/64.
  • Configure IPv6 addressing and a static route so that both segments can reach each other.
  • Create a named IPv6 access list that blocks HTTP from PC1 to the server, permits ICMPv6 from PC1, and permits everything else.
  • Apply it in the right direction and verify the behaviour.
  • Note what happens if you forget to permit ICMPv6 neighbor discovery, and explain why.

Exercise 7 – NAT (Static & PAT)

LAN 192.168.1.0/24                        203.0.113.0/24
PC1 (.10)  ----+
PC2 (.20)  ----+-- [SW1] -- G0/0 [R1] G0/1 ----- [ISP] ----- WebServer
SRV1 (.100) ---+                                          198.51.100.10

Tasks:

  1. Configure all interfaces and a default route from R1 towards the ISP.
  2. Define the inside and outside interfaces.
  3. Configure PAT so that all LAN hosts share the address of R1’s outside interface.
  4. Configure a static NAT so that the internal server 192.168.1.100 is reachable from outside on 203.0.113.100.
  5. From PC1, browse to the web server and verify the translations in the NAT table.
  6. From outside, verify that the internal server is reachable through its public address.
  7. Save the configuration.

Exercise 8 – STP & EtherChannel

          [SW1]  (root bridge)
         /      \
     [SW2] ==== [SW3]
       |    x2
      PC1  (two links between SW2 and SW3)

Tasks:

  1. Configure SW1 as the primary root bridge and SW2 as the secondary root bridge.
  2. Bundle the two links between SW2 and SW3 into an LACP EtherChannel (Port-channel 1) and configure it as a trunk.
  3. After convergence, identify which port is blocking and explain why.
  4. Enable PortFast and BPDU Guard on the access port connected to PC1.
  5. Verify everything with the appropriate show commands.
  6. Save the configuration.

Exercise 9 – IPv6 Addressing, Subnetting & Static Routing

LAN1 ----- [R1] ----- [R2] ----- [R3] ----- LAN3
                        |
                      LAN2

Allocated prefix: 2001:db8:acad::/48
You design the subnet plan yourself.

Tasks:

  1. From the allocated /48, design a subnet plan: one /64 per LAN and one /64 per point-to-point link. Write it down before configuring anything, this is the actual exercise.
  2. Enable IPv6 routing on all three routers.
  3. Configure the LAN interfaces with a static global unicast address (use ::1 as the router address on each LAN).
  4. Configure the point-to-point links using EUI-64, then display the resulting addresses and explain how the interface identifier was built.
  5. Display the link-local addresses. On R2, replace the automatic one with a manual link-local address that is easier to read, such as FE80::2.
  6. Configure the PCs to obtain their address automatically through SLAAC, and verify which prefix they received.
  7. On R1 and R3, configure IPv6 static routes towards the remote LANs, plus an IPv6 default route pointing to R2.
  8. On R2, configure the specific IPv6 static routes towards both remote LANs.
  9. Verify everything: interface status, the IPv6 routing table, the neighbor table, and end-to-end connectivity between LAN1 and LAN3.
  10. For each address in your plan, identify its type: global unicast, link-local, multicast, or solicited-node multicast. This is pure blueprint material and it comes up.
  11. Save the configuration.

Bonus, beyond the CCNA scope: replace the static routes with OSPFv3. It is not on the 200-301 blueprint, so skip it if you are short on time, but if you already know OSPFv2 it takes fifteen minutes and it makes the logic click.

Conclusion

If I had to summarize this year in one sentence: you don’t pass the CCNA with talent, you pass it with consistency.

Looking back, that first failure was useful. It forced me to build a real method, and that method taught me much more than the certification itself. Failing at 75% doesn’t mean knowing nothing. It means not knowing well enough, and the difference between the two is exactly what the exam measures.

Today, when something “just works”, I no longer see the same thing as before. I see the VLANs, the routing, the thousands of mechanisms running behind the scenes. That understanding, nobody can take it away from me, and it serves me every day, far beyond the exam.

So if you’re hesitating to get started: do it. But do it seriously, with a plan, the right tools, and accepting that it will take time. The network is the foundation of everything, the cloud, the data centers, AI. Understanding that foundation is an investment that never expires.

And if there is only one thing to remember from my journey, it would be this one: there is no miracle. Just work. But I promise you, it’s worth it.