Ten scenario labs for Containerlab. Each one deploys already broken, asks you to work out why before showing the fix, and ends with the actual mechanism explained — not just a corrected config file.
A lab that hands you a script to run doesn't build the instinct you need on a real network. These are built the other way around: something is broken, you investigate, and the explanation only shows up after you've formed a theory.
Every lab deploys already misconfigured. You diagnose it the way you'd work a ticket — no walkthrough waiting at the bottom of the page.
The write-up doesn't stop at "change this line." It explains why the protocol behaves that way, so the lesson carries to configs you haven't seen yet.
Each lab isolates one behavior — one LSA type, one best-path rule, one redistribution trap. Three or four routers, not a sprawling topology.
This is Lab 01 — the same one running in the terminal above. It's free, so you can check the format and quality before buying anything.
Every lab ships with the topology file, a startup config per router, and the scenario doc shown here. Deploy in one command.
r3 advertises three /24 subnets into area 1. They should reach area 0 as a single summarized route. They don't.
area range configured right now — and is that a router where the command can take effect?No signup needed. Full scenario doc, topology, and configs.
Ten labs — five OSPF, five BGP. Each one isolates a single behavior that trips people up in both exam labs and real troubleshooting.
Summarization configured on the wrong router — why it silently does nothing.
Mismatched stub flags in one area — the adjacency stays up, routing doesn't.
An MTU mismatch that looks like a neighbor problem but isn't — and the state machine that gives it away.
Point-to-point on one side, broadcast on the other. Hellos arrive; the adjacency never forms.
Two-way OSPF/BGP redistribution with no route tagging — where the loop actually forms.
iBGP split-horizon, and why a full mesh isn't optional past three routers.
The route is in the table but never installed — what next-hop-self is really for.
The full best-path order, and why prepending is often the wrong lever to pull.
Two attributes that both "prefer a path" — and which one wins, in which direction.
The prefix exists, the neighbor is up, and BGP still won't originate it. Exact-match rules explained.
Same four-step shape every time, so you spend your time on the networking, not on the format.
One command spins up the topology in Containerlab, already broken.
Check the routing table or adjacency state and compare it to what's expected.
Work through the scenario doc's questions — no answers given yet.
Read the concept explanation and the fix, then reconverge to confirm it.
One price, everything included. No account, no subscription.
All ten labs, yours to keep.
Docker and Containerlab on any Linux host or VM — a laptop with 4 GB of free RAM is enough. No physical gear, no EVE-NG license, no vendor images to source.
Basic familiarity helps — these assume you know what the protocols are and roughly how they work. The labs are aimed at the gap between "I passed the exam module" and "I'd catch this on a real network."
Yes. The scenarios are chosen because they're the kind of behavior that trips people up in both exam labs and production troubleshooting — not exam trivia.
FRR runs in a plain Docker container with no licensing, so the labs work on anything. The protocol behavior is the same — the concepts you learn here transfer directly to IOS, Junos, or Arista.
New scenario packs are released separately as they're built. This page lists what's current.