Professional firewall & Zero Trust labs — in the browser
Train like production: real vendor workflows, CLI muscle memory, policy traces, and connector deploy labs. Open any lab immediately with guest dummy data — no VM, no licence. Sign in only if you want the same workspace across devices.
Featured labs
Start here — highest student use
Zscaler Policy & Connector Labs
URL/SSL policy tests, App · Branch · Cloud Connector · Private Service Edge (PSE) deploy wizard, readiness scoring, and 40+ guided CLI labs with dummy Techclick tenant data.
Launch lab →Palo Alto PAN-OS
Full WebUI-style practice — Policies, Objects, Network, Device — plus CLI with configure, commit, and show workflows for PCNSA/PCNSE prep.
Launch lab →PAN-OS Traffic Lab
Desktop → Firewall → Server topology. Student pings/curls from the PC; security policy decides allow/deny; live traffic logs on the firewall CLI.
Open traffic lab →Topology Lab Builder
Drag firewalls, PCs, and switches onto a canvas. Run multi-device scenarios (IPsec site-to-site, HA) with realistic mismatch diagnostics.
Open builder →PAN-OS Lab Workbook
20 investigation tasks across 5 levels — recon, log analysis, policy design, troubleshooting, and reporting. Self-paced and printable.
Open workbook →CLI consoles
Multi-vendor shell practice for certifications
Check Point Gaia CLI
clish + expert mode for interfaces, routes, ClusterXL, fw stat, cpinfo, and tcpdump-style practice.
Open CLI →FortiGate FortiOS CLI
Hierarchical config tree with context-aware prompts and full get / show / execute / diagnose coverage.
Open CLI →Juniper SRX Junos CLI
Operational and configuration modes with candidate config, commit, rollback, and show | compare.
Open CLI →Cisco ASA CLI
Multi-mode IOS-style shell — ACLs, objects, NAT, interfaces, and packet-tracer workflows.
Open CLI →SonicWall NSv CLI
Zones, address/service objects, access rules, NAT, and routes — pending until commit.
Open CLI →Cisco IOS Switch
VLANs, trunking, STP, EtherChannel, CDP, and port-security for CCNA fundamentals.
Open CLI →Cisco IOS Router
OSPF, BGP, NAT, ACL, static routes, and DHCP pools for CCNA / CCNP routing practice.
Open CLI →F5 BIG-IP TMSH
Virtuals, pools, nodes, monitors, and profiles with show / list / create / save sys config.
Open CLI →Policy & Zero Trust
GUI-style decision engines and NAC practice
Cisco ISE Policy Simulator
Build authentication and authorization policies, then trace RADIUS requests to the matching profile, VLAN, and dACL.
Open policy sim →Zscaler Connectors
App Connector, Branch Connector, Cloud Connector, and Private Service Edge (PSE) — configure, deploy, and validate with dummy data and readiness checks.
Open connector labs →App Connector Troubleshooting
14 guided scenarios between App Connector and backend app — DNS, port, enrollment, TLS, HA, policy — with dummy diagnose output.
Open App Connector TS →Forescout NAC
Asset inventory with classification, compliance state, and VLAN assignment. Click an endpoint to see policy match and remediation.
Open NAC sim →New high-quality vendor labs
10 more platforms — SSE, EDR, SIEM, identity, cloud & DC networking
Cisco Meraki MX
Cloud-managed MX: interfaces, VLANs, firewall rules, Auto VPN, clients — dummy dashboard CLI for CMNA-style practice.
Open lab →HPE Aruba CX
AOS-CX campus core: VLANs, trunks, LACP, VSX, AAA/RADIUS — realistic show outputs and config mode.
Open lab →Netskope SSE
Real-time policies, private access apps, clients, publishers, event search, and URL policy test against dummy tenant.
Open lab →Prisma Access
SASE practice: mobile users, remote networks, security policy, HIP objects, service connections, traffic log.
Open lab →CrowdStrike Falcon
EDR lab: detections, hosts, IOCs, incidents, containment, and hunt-style process search with dummy sensors.
Open lab →Microsoft Sentinel
SIEM practice with KQL-style queries, incidents, analytics rules, and watchlists on dummy SecurityEvent data.
Open lab →Okta Identity
Workforce IAM: users, groups, apps, MFA/sign-on policies, auth evaluation, and system log with dummy org.
Open lab →Arista EOS
Data-center leaf-spine: interfaces, BGP, EVPN, VXLAN VNIs, MLAG — EOS-style show commands and config.
Open lab →pfSense CE
Open-source NGFW: interfaces, filter/NAT, gateways, states, packages — SME/home-lab dummy config.
Open lab →AWS Network Security
VPC, subnets, security groups, NACLs, route tables, flow-log samples, and SG evaluation tests (dummy account).
Open lab →Utilities
Daily tools used in class and ops
