← All projects

Network Design Lab

Active May 6, 2026 · 5 min read

Multi-vendor lab on Cisco Modeling Labs and EVE-NG. Routing, switching, wireless, security, SD-WAN, identity, and observability platforms.

Network design lab — CML and EVE-NG platforms
20
node CML license
2
simulation platforms
7+
active topologies

Cisco CML — platform coverage

Routing
IOSv, IOS XRv 9000, CSR1000v, Catalyst 8000V, IOL XE
Switching
IOSvL2, IOL XE Switch, Catalyst 9000v, Nexus 9000v
Wireless
Catalyst 9800 Wireless Controller for Cloud
Security
ASAv, FTDv, FMCv
Catalyst SD-WAN
Manager, Controller, Validator, vEdge, Edge
Identity & AAA
ISE, FreeRADIUS, TACACS+
Observability
Splunk, ThousandEyes, TRex, WAN Emulator
Linux
Ubuntu, Alpine, Tiny Core

EVE-NG — non-Cisco vendors

Fortinet
FortiGate — policy, NAT, VPN · live
Juniper · Arista · FRR
vMX / vEOS / BIRD — planned

Active topologies

L3 BGP Hot Cut
BGP migration topology for practicing live cutover work. Mirrors customer onboarding — with the freedom to break it on purpose.
securebytes-failure-series-01
Failure injection. Convergence behavior under partial peer drops and asymmetric paths. See how a design fails before it ships.
L2
HSRP active and standby, STP root election, VLAN segmentation, port-channel trunking.
Akwaaba Tech Solutions Lab V2
Multi-site enterprise topology with distribution-layer redundancy.
FTD lab
Cisco Firepower NGFW policy and inspection iterations.
Fortinet lab
FortiGate policy, NAT, and VPN topologies on EVE-NG.
Network Automation Lab
Test environment for the Ansible work. Config drift detection, idempotency testing, rollback rehearsal.

Roadmap

Multi-vendor interop as Juniper comes online in EVE-NG
Data center fabric topologies — leaf-spine, VxLAN, EVPN
ISE-driven 802.1X and TrustSec for identity-aware segmentation
Catalyst SD-WAN topology with full control plane
Sanitized topology repo on GitHub once dual-repo workflow is in place

Stack

Cisco CMLEVE-NGIOS-XRNX-OSCatalyst SD-WANISEFTDvFortinet
← Previous
AWS Detection Engineering