Build a network on the canvas and trace every packet hop by hop. Press Go Live and every node becomes a real isolated instance — with its own IP, routing table, and firewall. No hardware, no VMs, no installs. Just your browser.
Every lab comes with a step-by-step guide: key concepts, hands-on exercises, and real-world context. The guide tracks your progress and suggests what to try next.
Click the play button on any exercise to run it. Traces animate on the topology canvas, test results show pass/fail instantly, and "Do it for me" applies a change step when you are stuck. Learn by doing, not just reading.
Stuck on a concept? Ask the AI assistant. It understands your exact lab topology and gives specific answers — referencing your nodes, IPs, and routes. Like having a networking tutor who can see your screen.
Place hosts, routers, switches, firewalls, DNS servers, and more on the canvas. Connect them with cables, then give them addresses, routes and rules.
Send a packet and watch it travel through your topology. See MAC addresses rewrite at routers, firewall rules allow or block, and NAT translate addresses — all animated on the canvas.
Click "Go Live" and every node becomes a real running instance. Run real ping, traceroute, dig. Real DHCP leases. Real DNS resolution. No simulation — actual networking.
Watch packets traverse your network hop by hop. On a running lab, traces also run real ping, traceroute and connection tests inside isolated instances in the cloud.
Click any device to see its routing and ARP tables and its firewall rules. Its console takes ping, traceroute, ip route, arp, dig, iptables -L and Cisco-style show commands; on a running lab, birdc shows OSPF neighbours and BGP sessions.
Hop-by-hop visualization with MAC/IP/TTL changes, firewall decisions, and NAT rewrites.
Rules with a default-deny policy, run as real iptables on a live lab. A trace names the rule that blocked a packet.
dnsmasq resolves hostnames to IPs. Run dig from inside any network node.
On a running lab, a dnsmasq DHCP server hands out real leases. Check the address a host received with ip addr.
802.1Q segmentation on a single switch. Inter-VLAN routing through a router.
DNAT across backend servers. On a live lab, real iptables shares new connections round robin, by weight or at random, as you configure it.
SNAT for outbound masquerade, DNAT for port forwarding. Watch IP addresses change.
Labs with intentional bugs. Practice the debug → fix → retest workflow.
When a trace fails, get a contextual explanation and a fix suggestion.
Run ping, traceroute, dig, ip addr inside each network node.
Full canvas with touch drag-and-drop. Tab navigation for labs, guide, and runtime.
In live mode, each node has its own IP stack, routing table, and processes. Not a simulation — real networking running in the cloud.
No routers to buy, no VMs to configure, no GNS3 to install. Drag a router onto the canvas and it exists. That's it.
Real-world scenarios that teach you how networks actually work. Each lab has a step-by-step coach with checked exercises, hop-by-hop packet traces, and a Go Live mode that runs it on real Linux networking. Signed-in users can also ask the AI tutor.
Free, no signup, runs in your browser. Pick any lab above to open it directly.
Wondering how natted.cloud stacks up against GNS3, EVE-NG, Cisco Packet Tracer, or Containerlab? We put together an honest, side-by-side comparison — including where others win.
66 labs. Real network instances. MPLS, OSPF and BGP routing. AI-powered tutor. Free — no credit card, no install.
Launch Lab →