Drag. Drop.
Real Network Instances.

Build a network on the canvas and trace every packet hop by hop. Press Go Live and every node becomes a real isolated instance — with its own IP, routing table, and firewall. No hardware, no VMs, no installs. Just your browser.

Try a Lab Free See How It Works

What Comes With Every Lab

Guided Learning Path

Every lab comes with a step-by-step guide: key concepts, hands-on exercises, and real-world context. The guide tracks your progress and suggests what to try next.

Interactive Exercises

Click the play button on any exercise to run it. Traces animate on the topology canvas, test results show pass/fail instantly, and "Do it for me" applies a change step when you are stuck. Learn by doing, not just reading.

AI Lab Assistant

Stuck on a concept? Ask the AI assistant. It understands your exact lab topology and gives specific answers — referencing your nodes, IPs, and routes. Like having a networking tutor who can see your screen.

How It Works

1

Drag & Drop Devices

Place hosts, routers, switches, firewalls, DNS servers, and more on the canvas. Connect them with cables, then give them addresses, routes and rules.

2

Trace Packets Hop by Hop

Send a packet and watch it travel through your topology. See MAC addresses rewrite at routers, firewall rules allow or block, and NAT translate addresses — all animated on the canvas.

3

Go Live

Click "Go Live" and every node becomes a real running instance. Run real ping, traceroute, dig. Real DHCP leases. Real DNS resolution. No simulation — actual networking.

See It In Action

Live Packet Tracing

Watch packets traverse your network hop by hop. On a running lab, traces also run real ping, traceroute and connection tests inside isolated instances in the cloud.

Deep Inspection

Click any device to see its routing and ARP tables and its firewall rules. Its console takes ping, traceroute, ip route, arp, dig, iptables -L and Cisco-style show commands; on a running lab, birdc shows OSPF neighbours and BGP sessions.

Everything You Need to Learn Networking

Packet Tracing

Hop-by-hop visualization with MAC/IP/TTL changes, firewall decisions, and NAT rewrites.

Real Firewalls

Rules with a default-deny policy, run as real iptables on a live lab. A trace names the rule that blocked a packet.

Real DNS

dnsmasq resolves hostnames to IPs. Run dig from inside any network node.

Real DHCP

On a running lab, a dnsmasq DHCP server hands out real leases. Check the address a host received with ip addr.

VLANs

802.1Q segmentation on a single switch. Inter-VLAN routing through a router.

Load Balancing

DNAT across backend servers. On a live lab, real iptables shares new connections round robin, by weight or at random, as you configure it.

NAT

SNAT for outbound masquerade, DNAT for port forwarding. Watch IP addresses change.

Troubleshooting

Labs with intentional bugs. Practice the debug → fix → retest workflow.

Interactive Hints

When a trace fails, get a contextual explanation and a fix suggestion.

Live Console

Run ping, traceroute, dig, ip addr inside each network node.

Mobile Friendly

Full canvas with touch drag-and-drop. Tab navigation for labs, guide, and runtime.

Real Isolated Instances

In live mode, each node has its own IP stack, routing table, and processes. Not a simulation — real networking running in the cloud.

Zero Hardware

No routers to buy, no VMs to configure, no GNS3 to install. Drag a router onto the canvas and it exists. That's it.

66 Labs — From Beginner to Expert

Real-world scenarios that teach you how networks actually work. Each lab has a step-by-step coach with checked exercises, hop-by-hop packet traces, and a Go Live mode that runs it on real Linux networking. Signed-in users can also ask the AI tutor.

8Beginner
8Beginner+
27Intermediate
8Intermediate+
15Advanced
Beginner — Start Here
Your Home Network Connected But Can't Ping (Mask Mismatch) WiFi Connected But No Internet Two Hosts And A Switch Direct Connection: Two Hosts, One Cable Subnetting: Why /24 Matters
Intermediate — Real Services
Firewall: Allow & Deny I Added Allow But Still Blocked NAT: Private to Public Two Layers of NAT Port Forward: Gaming Server DNS: Name Resolution Packets Enter But Never Leave Why This Route, Not That One? Startup Office: WiFi + Servers + Firewall Hairpin NAT: Can't Reach Myself Stale DNS Record: The Server Moved MTU Black Hole: Ping Works, Big Transfers Hang Stateful vs Stateless Firewall Accidental Lockout: Locked Out of My Server Overlapping Subnets: The Router Is Never Asked Default Route Loop: Infinite Bounce Asymmetric Path Breaks Firewall
Going Further — Routing, Services and MPLS
BGP: Two ISPs Exchanging Routes OSPF Failure Recovery Anycast: Same IP, Multiple Locations Zero Trust: Microsegmentation Internet Exchange Point: 3 ISPs Peering Incident Response: Database Breach Container Networking: Pod to Service CDN: Load Balancer + Multiple Origins Multi-Homed Customer: Two ISP Uplinks Switch Loops and Broadcast Storms Ring vs Star: Topology Trade-offs MPLS: Label Switching Basics MPLS: Penultimate Hop Popping MPLS VPN: Two Customer Sites MPLS: Multiple LSPs
Start with the first lab

Free, no signup, runs in your browser. Pick any lab above to open it directly.

How Do We Compare?

Wondering how natted.cloud stacks up against GNS3, EVE-NG, Cisco Packet Tracer, or Containerlab? We put together an honest, side-by-side comparison — including where others win.

0 min Setup: nothing to install
66 labs Including MPLS, BGP, OSPF
AI tutor Answers about your own topology
See Full Comparison →

Stop Reading. Start Building.

66 labs. Real network instances. MPLS, OSPF and BGP routing. AI-powered tutor. Free — no credit card, no install.

Launch Lab →