CCNA® 200-301
Cisco's foundational networking certification. Aligned to the official 200-301 exam blueprint. Each topic page: summary · mental model · topology · commands · verification · common mistakes · lab · cheat strip.
Free: CCNA 12-Week Study Plan Week-by-week schedule · free certs to stack · lab list · mock-exam strategy Open →Taking the exam on or after February 3, 2027? You will sit CCNA v2.0. See the v2.0 topic map →
Mapped to the official Cisco 200-301 v1.1 blueprint.
Cisco's exam blueprint defines six weighted domains. Our library covers every one. These are the same buckets Cisco grades you on. The table below maps our categories to the official domains.
| Official Cisco 200-301 domain | Our library categories | Topics |
|---|---|---|
| 1.0 Network Fundamentals | Network Fundamentals + Device Operations | 18 + 7 |
| 2.0 Network Access | Network Access + Wireless | 13 + 6 |
| 3.0 IP Connectivity | IP Connectivity | 11 |
| 4.0 IP Services | IP Services | 13 |
| 5.0 Security Fundamentals | Security Fundamentals | 14 |
| 6.0 Automation & Programmability | Automation & Programmability | 10 |
Cisco®, CCNA® and 200-301 are trademarks of Cisco Systems, Inc. PacketMentor is independent and not affiliated with Cisco. Weights are from the official Cisco 200-301 v1.1 blueprint.
Network Fundamentals
OSI Model & TCP/IP
Two networking reference models compared side-by-side. The seven OSI layers, the four TCP/IP layers, and which one the real internet actually runs on (spoiler: not OSI).
IPv4 Addressing
32-bit addresses, dotted decimal, classful vs classless, private ranges, and the special addresses (loopback, broadcast, APIPA) you should never accidentally use for production hosts.
Spine-Leaf Architecture (Modern Data Center Topology)
The two-tier data center fabric that replaced core/distribution/access. Every leaf is one hop from every spine for predictable latency and easy scale-out.
Private IPv4 Addressing (RFC 1918)
The three private IPv4 ranges (10/8, 172.16/12 and 192.168/16) reserved for internal networks, hidden behind NAT and never routable on the public internet.
TCP vs UDP
Two flavors of Layer 4 transport. TCP gives reliability and order at the cost of latency; UDP gives speed with no safety net. Covers the 3-way handshake, ports, when to use each, and the protocols that pick the wrong one.
Interface & Cable Issues: Collisions, Errors, Duplex/Speed Mismatch
Late collisions, input errors, CRC counters, and the classic auto-negotiation trap where one side ends up half-duplex and the link crawls at a fraction of its rated speed.
Subnetting
CCNA subnetting guide: the magic-number method, VLSM, wildcard masks, enterprise IP plans, 8 worked practice problems and a fast mental subnetting drill.
IPv6 Basics
128-bit addresses, hex notation, the :: shortcut, address types (global, link-local, multicast), SLAAC, and why IPv6 is finally happening 25 years after it was supposed to.
ARP: Address Resolution Protocol
How a host turns an IP address into the MAC address it needs to actually deliver a frame. Broadcast question, unicast answer, cached for hours. Also covers Gratuitous ARP, Proxy ARP, and the ARP spoofing attack.
ICMP: Internet Control Message Protocol
The network's diagnostic channel. Covers echo / reply (ping), destination unreachable, TTL exceeded (traceroute), and the security trade-offs of blocking ICMP at the firewall.
IPv6 Address Types: Unicast, Anycast, Multicast, and EUI-64
The three IPv6 delivery modes: unicast (one-to-one), anycast (one-to-nearest) and multicast (one-to-many), plus how EUI-64 builds a host ID from a MAC.
TCP 3-Way Handshake
The three packets that start every TCP connection: SYN, SYN-ACK and ACK. Sequence numbers, the half-open state, SYN floods and HTTPS on high-latency links.
Verify IP Parameters on the Client OS (Windows / macOS / Linux)
Commands to check a laptop's IP, gateway, DNS, ARP table and route table on Windows, macOS and Linux (the ones you run before you ever SSH into a switch).
Cabling & Media Standards
What's inside the cables and fiber you plug in: Cat5e/6/6A/8, single-mode vs multi-mode fiber, SFP/SFP+/QSFP transceivers, distance and bandwidth limits.
MTU & Fragmentation
Why packets get fragmented or dropped on links with smaller MTU than expected. Covers MTU vs MSS, the Don't-Fragment bit, ICMP 'Fragmentation Needed,' Path MTU Discovery, and why blocking ICMP breaks the internet.
WAN Connection Types
WAN connection types at branch sites: leased lines, Metro Ethernet, MPLS L3VPN, broadband (cable, DSL, FTTH), LTE/5G, and how SD-WAN ties them together.
Hierarchical Network Design
Cisco's three-tier model (Access, Distribution, Core) for campus networks: when to collapse the core, where to put redundancy, and why it beats flat networks.
Network Virtualization & Containers
Hypervisors, VMs, virtual switches, containers and container networking: how server virtualization changed networking and what CCNA candidates must know.
Device Operations
Cisco IOS Device Management
How you actually log into and configure a Cisco device. Covers console / SSH / Telnet access, command modes (user / privileged / config), saving config, banners, the password types, and modern best practices for line security.
Power over Ethernet (PoE)
How a switch port also powers a phone, AP, or camera over the same Ethernet cable. PoE standards (802.3af / at / bt), power classes, detection sequence, budgets, and the troubleshooting questions you'll actually ask.
Cisco IOS File System
Where Cisco IOS stores configs, images and logs (flash:, nvram:, system:, tftp:), plus copy syntax, image management, boot variables and file commands.
Password Recovery & Configuration Register
How to recover access to a Cisco router or switch when you've lost the enable password. Covers the configuration register, ROMMON, the standard CCNA recovery procedure, and the security implications of physical access.
Network Troubleshooting Methodology
How seasoned engineers approach unknown problems: bottom-up, top-down and divide-and-conquer, questions to ask before commands, and Cisco's seven steps.
Extended Ping and Traceroute on Cisco IOS
Read ping and traceroute output on Cisco IOS, use extended ping to test the return path and MTU, and follow a clear workflow for Layer 3 connectivity faults.
Reading Packet Captures for CCNA
Read Wireshark style capture output like an engineer: where captures come from, what each column means, and the patterns behind ARP, DHCP, TCP and DNS faults.
Network Access
MAC Address Table
How a switch learns where every device is and decides where to forward each frame. Covers source-MAC learning, destination-MAC lookup, unknown-unicast flooding, and the CAM table on Cisco switches.
VLANs
CCNA VLAN guide: broadcast domains, access vs trunk ports, 802.1Q tagging, native and voice VLANs, VTP, a 6-step trunk debug, security pitfalls and 7 scenarios.
Edge Port Configuration: PCs, Phones, APs and Servers
CCNA 2.2 edge ports on Catalyst IOS XE: access and voice VLANs, PortFast, BPDU Guard, PoE, AP trunks, LACP to servers, and the show commands that prove it.
Trunks & 802.1Q Tagging
How switches carry multiple VLANs over a single link using 802.1Q tags. Includes DTP behavior, native VLAN gotchas, and the allowed-VLAN list.
Spanning Tree Protocol (STP)
CCNA STP guide: why loops are catastrophic, root election, port roles and states, BPDUs, PortFast, BPDU Guard, Root Guard, Loop Guard, RSTP and MSTP.
EtherChannel (Link Aggregation)
Bundle physical links between two switches into one logical Port-Channel for more bandwidth and instant failover. Covers LACP, PAgP, static and load balancing.
Switching Operation
How a switch actually decides where to forward each frame. Covers source-MAC learning, destination-MAC lookup, the three outcomes (forward / flood / drop), and store-and-forward vs cut-through.
CDP & LLDP: Neighbor Discovery
How devices discover directly connected neighbors. CDP is Cisco-proprietary, LLDP is the vendor-neutral standard, and both share identity, model, IOS and port.
BPDU Guard & Root Guard
Two Spanning Tree security features that protect your STP topology from misconfiguration and rogue switches. BPDU Guard locks user-facing ports; Root Guard pins the root bridge so a misplaced switch can't hijack it.
Catalyst Boot Process
What happens between powering on a Cisco device and the prompt appearing. Covers POST, ROMMON, IOS image selection, config register, boot variables, and password recovery.
VTP: VLAN Trunking Protocol
Cisco's protocol for sharing VLAN config across switches in the same VTP domain. Powerful, dangerous, and the reason every CCNA engineer learns the value of `vtp mode transparent`.
Rapid STP & MSTP
Why classic 802.1D STP's 50-second convergence is unacceptable and how RSTP and MSTP fix it: port roles, port states, sync, and MST regions and instances.
Private VLANs (PVLAN)
How Private VLANs isolate hosts in one Layer-3 subnet: primary and secondary VLANs, isolated, community and promiscuous ports, and hotel and hosting use cases.
Wireless
Wireless LAN Basics
CCNA Wi-Fi fundamentals: SSID, BSS, ESS and BSSID, autonomous vs lightweight APs, CAPWAP, WLC discovery (DHCP option 43, DNS), WPA2/WPA3 and roaming.
WLAN Architectures: Autonomous, Centralized (WLC), Cloud, Embedded
CCNA WLAN architecture guide: autonomous, centralized, cloud-managed and embedded WLC, split-MAC, CAPWAP, AP modes, WLC discovery, and N+1 and SSO redundancy.
Wi-Fi Security: WEP, WPA, WPA2, WPA3
Twenty-five years of wireless security in one page. Why WEP is broken, why WPA is a stop-gap, why WPA2 ruled for two decades, and what WPA3 actually fixes.
Wi-Fi 6, 6E, and 7 Features
What changed in Wi-Fi 6 (802.11ax), 6E and Wi-Fi 7 (802.11be): OFDMA, MU-MIMO, target wake time, 6 GHz spectrum and MLO, and what each means for users.
Wireless RF Fundamentals
How Wi-Fi moves bits through the air: channels, bands, SNR, RSSI, free-space path loss and antenna patterns, and why laptops drop in the conference room.
Access Point Operating Modes
Cisco AP modes explained: Local, FlexConnect, Bridge/Mesh, Monitor, Sniffer, SE-Connect and Rogue Detector, and when each fits real enterprise Wi-Fi.
IP Connectivity
Inter-VLAN Routing
How devices in different VLANs talk to each other. Covers router-on-a-stick (with sub-interfaces), Layer-3 switch SVIs, and when to pick each.
Static Routing
CCNA static routing guide: next-hop vs exit-interface routes, default, floating and summary routes, recursive lookup, IPv6 statics and 8 worked scenarios.
Default Routing
The catch-all route every edge router needs. Covers static defaults, dynamic defaults (originated by OSPF/EIGRP/BGP), gateway of last resort, and the difference between a default and a summary route.
Routing Decision Process
How a router picks a route: longest prefix match, then administrative distance, then metric. Why a more specific OSPF route beats a less specific static route.
FHRP: HSRP, VRRP & GLBP
First-hop redundancy protocols. How two routers share one virtual IP so hosts don't notice when their default gateway fails. Covers HSRP states, election, preemption, and the GLBP load-balancing twist.
Layer-3 Switch & SVI Routing
How a Layer-3 switch routes between VLANs at line rate using SVIs (Switched Virtual Interfaces), the modern replacement for router-on-a-stick.
OSPF Single-Area
CCNA OSPF guide: link-state model, seven neighbor states, LSA types, DR/BDR election, cost tuning, authentication, summarization and 8 worked scenarios.
OSPFv3 for IPv6
Configure single-area OSPFv3 for IPv6 on Cisco IOS XE: router ID, per-interface enablement, DR/BDR election, passive interfaces and the show commands.
Route Summarization
Why aggregating many specific routes into one shorter prefix shrinks route tables, speeds convergence, and limits the blast radius of a flapping link. Covers manual, OSPF, and EIGRP summarization.
IPv6 SLAAC & DHCPv6
Two ways an IPv6 host gets an address. SLAAC has hosts auto-generate from a router-advertised prefix. DHCPv6 mirrors IPv4 DHCP. Covers RA/RS messages, EUI-64, privacy addresses, and stateful vs stateless DHCPv6.
IPv6 Transition Mechanisms
How networks bridge the IPv4 to IPv6 gap: dual-stack, tunneling (6to4, 6in4, GRE), NAT64 and DNS64, and the realistic migration patterns in use in 2026.
IP Services
TFTP and FTP: Network File Transfer Basics
TFTP (UDP/69, config uploads) vs FTP (TCP/20 and 21, larger IOS images) for the CCNA: when to use each and the copy commands between flash and a server.
SCP and SFTP on Cisco IOS XE
Move configs and IOS XE images securely with SCP and SFTP over SSH: prerequisites, ip scp server enable, copy scp:// and sftp:// commands, and verification.
HSRP vs VRRP vs GLBP: FHRP Compared
Side-by-side of the three First Hop Redundancy Protocols on Cisco gear. When HSRP wins, why VRRP is the open standard, how GLBP load-balances across multiple actives, and which to pick in 2026.
DHCP: Dynamic Host Configuration Protocol
CCNA DHCP guide: the DORA exchange, packet anatomy, DHCP options, T1/T2 lease renewal, Cisco IOS server and relay config, DHCP Snooping and 8 scenarios.
NAT & PAT
CCNA NAT guide: static NAT, dynamic NAT, PAT/overload, inside/outside terms, port forwarding, CGNAT, hairpin NAT, 8 worked scenarios and NAT debugging.
DNS: Domain Name System
How www.example.com becomes an IP address. Covers the recursive query path (root → TLD → authoritative), record types (A, AAAA, CNAME, MX, PTR), TTL caching, and the most common DNS failure modes.
NTP: Network Time Protocol
How every device on the network ends up with the same clock. Covers stratum hierarchy, client and server config, authentication, and why broken NTP makes log correlation a nightmare.
Syslog
Send every device's log messages to a central server. Covers severity levels (0-7), facilities, message format, where to send logs (local buffer / console / monitor / server), and the eternal question of how much logging is too much.
QoS Basics
How routers and switches handle congestion: classification, DSCP marking, priority queueing, shaping and policing, and why VoIP and video get special treatment.
SNMP: Simple Network Management Protocol
How monitoring systems pull metrics and receive alerts from network devices. Covers SNMPv1/v2c/v3, community strings, traps vs informs, MIB / OID navigation, and why SNMPv3 is the only one acceptable in 2026.
IGMP & IGMP Snooping
How hosts join multicast groups with IGMP and how a switch learns which ports want multicast (IGMP snooping), so it stops flooding video out every port.
NTP Authentication & Security
How to harden NTP: authentication keys, peer, client and server roles, ACL restrictions, and why a bad clock breaks Kerberos, TLS, logs and forensics.
DHCP Relay & IP Helper
How the ip helper-address command forwards DHCP DISCOVER broadcasts across Layer 3 boundaries so one DHCP server can serve many VLANs. Includes Option 82, the GIADDR field, and the relay troubleshooting flow.
Security Fundamentals
Access Control Lists (ACLs)
CCNA ACL guide: first-match-wins, implicit deny, wildcard masks, standard, extended and named ACLs, in vs out, time-based ACLs, 9 scenarios and debugging.
Port Security
Lock a switch port to a specific MAC address (or addresses). Covers static, dynamic, and sticky learning, violation modes (protect / restrict / shutdown), and the err-disable recovery dance.
Storm Control
Stop broadcast, multicast and unicast storms at the switch port. Covers rising and falling thresholds, drop vs shutdown vs trap, recovery and show commands.
DHCP Snooping
Switch security feature that blocks rogue DHCP servers. Trusts one port (where the real server lives) and drops DHCP server messages from any other port. Foundation for Dynamic ARP Inspection too.
AAA · RADIUS & TACACS+
AAA (authentication, authorization and accounting) explained: RADIUS vs TACACS+, method lists, and why networks over 5 devices use centralized auth.
802.1X: Port-Based Network Access Control
Lock every switch port until the connected device proves identity. Covers the supplicant / authenticator / auth server roles, EAPOL on the wire, and how 802.1X plugs into RADIUS for enterprise Wi-Fi and wired auth.
VPN Basics: IPsec & SSL
How two separated networks (or one user and a network) can talk privately over the public internet. Covers site-to-site IPsec, remote-access SSL/TLS VPNs, IKE phases, and what 'tunnel' actually means.
Dynamic ARP Inspection (DAI)
The Layer-2 security feature that kills ARP spoofing. It checks every ARP packet against the DHCP Snooping binding table and drops bogus replies.
IP Source Guard (IPSG)
IP Source Guard, the fourth Layer-2 security feature, checks every packet's source IP against the DHCP Snooping binding table to block IP spoofing.
IPv6 RA Guard
What IPv6 RA Guard does, why it matters, and the one-command Cisco IOS config. Covers CCNA 200-301 v2.0 objective 4.7.d.
Security Program Elements: Awareness, Training, and Physical Access
The non-technical layers of a security program (user awareness, formal training and physical access controls) that network engineers must understand.
Encryption Fundamentals
Cryptography for network engineers: symmetric vs asymmetric, hashing, digital signatures and certificates, and where each is used in IPsec, TLS, SSH and 802.1X.
Password Policy: Management, Complexity, MFA, Certificates, Biometrics
A real-world password policy goes past strong passwords: length over complexity, no forced rotation, MFA, certificate auth, and where Cisco IOS supports each.
Cybersecurity Threats & Mitigation
Threats every network engineer must recognize (phishing, ransomware, MITM, DDoS, supply-chain attacks, insider threats) and the mitigation controls that work.
Automation & Programmability
REST APIs for Network Engineers
Modern Cisco devices expose REST APIs so you can configure them with HTTP requests and JSON instead of SSH and screen-scraping. Covers verbs (GET/POST/PUT/DELETE), authentication, data formats, and where REST fits in network automation.
Ansible for Network Engineers
Push configuration to dozens of Cisco devices from one YAML playbook. Covers inventory, modules, idempotency, and why Ansible became the default automation tool for network teams who don't want to write a custom Python script for every change.
JSON, YAML & XML for Network Engineers
The three data formats you'll meet doing network automation. JSON for APIs, YAML for configs/playbooks, XML for legacy and NETCONF. Same data, three syntaxes, different ergonomics.
NETCONF & YANG
The structured-data alternative to SSH-and-screen-scrape. Covers how NETCONF moves XML configs over SSH, what YANG models are, and where they fit alongside REST APIs in modern network automation.
Python for Network Engineers
Why Python leads network automation, plus four libraries you'll use: Netmiko (SSH), NAPALM (vendor-agnostic), Nornir (parallel runner) and requests (REST).
SDN & Controller-Based Networking
Software-Defined Networking explained. Why control plane and data plane were separated, what a network controller actually does, and where Cisco DNA Center, ACI, and Meraki fit in.
Network Management Approaches
Device-based, cloud-based, controller-based, automation-based and infrastructure as code: how each one makes changes and where the source of truth lives.
AI & ML in Network Operations
Where machine learning really shows up in networks: anomaly detection, predictive maintenance and generative AI assistants, plus marketing AI vs the real thing.
Agentic AI in Network Operations
What an AI agent actually does on a network, how it differs from a chatbot or a script, and how to check its recommendations before anything touches production.
Choosing a Good Prompt for Network Operations
CCNA v2.0 objective 5.2: judge prompts to a generative AI tool by data classification, output format, persona and instructions, with worked network examples.
Ready for more? Browse CCNP-level topics →
