All certifications / JNCIA-Junos / Cheat sheet
JNCIA-Junos JN0-106 cheat sheet
Domain 1: Networking fundamentals (15%)
Exam tips
- Watch for questions that mix hubs, switches and routers in one diagram. A hub adds no collision domains; a switch adds one per port but none for broadcasts; a router adds a broadcast domain per interface.
- Exam questions like to ask what changes at each hop. In routed traffic, MAC addresses change at every router while IP addresses stay the same (ignoring NAT).
- Switches learn from the source MAC and forward based on the destination MAC. Questions often try to swap these two.
- Remember that an ARP request is a broadcast and an ARP reply is normally unicast, and that a device ARPs for its next hop, not for a remote destination.
- Check whether a question asks for addresses or usable hosts. The usable count is 2 to the power of host bits minus 2 (except /31 and /32, which are special cases).
- The double colon may appear only once in an address. An answer choice with two
::is always invalid. - Know which protocol each well-known port uses. DNS is the classic trick: it uses UDP 53 for most queries but TCP 53 for zone transfers and large responses. BGP uses TCP 179, while OSPF uses IP protocol 89 and no port.
- Keep the order straight: classify on ingress, queue and schedule on egress, rewrite on egress. Questions often ask where in the path each step happens.
- Memorise the queue numbers: BE 0, EF 1, AF 2, NC 3. Also remember that by default only BE and NC get scheduler resources.
- If a question mentions matching on addresses or ports, the answer is multifield (a firewall filter). If it mentions reading DSCP, precedence, 802.1p or EXP, the answer is behavior aggregate. When both apply, MF overrides BA.
Key terms
- Collision domain
- A network segment where simultaneous transmissions can collide; each switch or router port is its own collision domain.
- Broadcast domain
- The set of devices that receive a Layer 2 broadcast from any member; bounded by routers and by VLANs.
- CSMA/CD
- Carrier sense multiple access with collision detection, the half-duplex Ethernet method of listening, detecting collisions and backing off.
- Full duplex
- A link mode where a device can send and receive at the same time, which removes collisions entirely.
- VLAN
- Virtual LAN: a logical Layer 2 segment on a switch; each VLAN is a separate broadcast domain.
- Frame
- A Layer 2 unit of data with a header containing source and destination MAC addresses.
- Packet
- A Layer 3 unit of data with a header containing source and destination IP addresses and a TTL.
- Ethernet switching table
- The Junos table mapping learned MAC addresses to interfaces and VLANs, shown with
show ethernet-switching table. - Routing table
- A table of destination prefixes and next hops; on Junos the IPv4 unicast table is inet.0.
- Longest-prefix match
- The rule that a router uses the most specific matching route when several prefixes contain the destination.
- MAC address
- A 48-bit Layer 2 hardware address, written as 12 hexadecimal digits, that identifies a network interface.
- OUI
- Organizationally unique identifier: the first 24 bits of a MAC address, identifying the manufacturer.
- EtherType
- The 2-byte field that identifies the payload protocol, such as 0x0800 for IPv4 or 0x0806 for ARP.
- FCS
- Frame check sequence: a CRC at the end of the frame used to detect transmission errors.
- Flooding
- Sending a frame out all ports in the VLAN except the ingress port, used for broadcasts and unknown destinations.
- ARP
- Address Resolution Protocol: maps an IPv4 address to a MAC address on the local link using a broadcast request and a unicast reply.
- ARP cache
- The table of learned IP-to-MAC mappings, shown on Junos with
show arp. - Gratuitous ARP
- An unsolicited ARP about the sender's own IP, used for duplicate address detection and to update neighbors' caches.
- no-resolve
- A Junos output option that stops the command from doing reverse DNS lookups on addresses.
- CIDR
- Classless inter-domain routing: addressing with arbitrary prefix lengths written as address/length, replacing classful boundaries.
- Subnet mask
- A 32-bit value of contiguous 1s (network part) followed by 0s (host part), such as 255.255.255.192 for /26.
- RFC 1918 private ranges
- 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, reserved for internal use and not routed on the internet.
- Broadcast address
- The last address in a subnet, with all host bits set to 1, used to reach every host on that subnet.
- Block size
- 256 minus the interesting mask octet; the spacing between consecutive subnet addresses.
- Hextet
- One of the eight 16-bit groups of an IPv6 address, written as up to four hexadecimal digits.
- Link-local address
- An fe80::/10 address automatically present on every IPv6 interface, valid only on the local link.
- Global unicast address
- A publicly routable IPv6 address, currently from 2000::/3.
- EUI-64
- A method of forming a 64-bit interface ID from a MAC address by inserting fffe and flipping the universal/local bit.
- Multicast (IPv6)
- Addresses in ff00::/8 that deliver to a group; IPv6 uses multicast instead of broadcast.
- Encapsulation
- Adding each layer's header (and trailer) to data as it moves down the stack.
- TCP
- Connection-oriented, reliable transport using a three-way handshake, sequence numbers, acknowledgments and retransmission.
- UDP
- Connectionless, best-effort transport with a small header and no acknowledgments or retransmission.
- Well-known ports
- Port numbers 0 to 1023, assigned to common services such as SSH (22) and HTTPS (443).
- Three-way handshake
- The SYN, SYN-ACK, ACK exchange that opens a TCP connection.
- Class of service (CoS)
- The set of features that classify, queue, schedule and mark traffic so different classes get different treatment.
- Forwarding class
- The Junos label assigned to a packet that determines which output queue it uses.
- Loss priority
- A per-packet value (such as low or high) that tells the router which packets to drop first under congestion.
- Scheduler
- A set of parameters for a queue, including transmit rate, buffer size and priority.
- Rewrite rule
- An egress rule that sets CoS markings like DSCP in outgoing packets based on forwarding class and loss priority.
- best-effort (BE)
- Default forwarding class for ordinary traffic, mapped to queue 0.
- expedited-forwarding (EF)
- Default forwarding class for low-latency, low-jitter traffic such as voice, mapped to queue 1.
- assured-forwarding (AF)
- Default forwarding class for traffic that needs a bandwidth guarantee, mapped to queue 2.
- network-control (NC)
- Default forwarding class for routing and control protocol traffic, mapped to queue 3.
- show interfaces queue
- Operational command that shows per-queue transmit and drop counters for an interface.
- Behavior aggregate (BA) classifier
- A classifier that maps a single CoS marking (DSCP, IP precedence, 802.1p or MPLS EXP) to a forwarding class and loss priority.
- Multifield (MF) classifier
- A firewall filter that matches several header fields and sets forwarding class and loss priority as its action.
- DSCP
- Differentiated Services Code Point: 6 bits in the IP header used to mark a packet's CoS treatment.
- EF (DSCP 46)
- The DSCP value conventionally used for expedited, low-latency traffic such as voice.
Domain 2: Junos OS fundamentals (15%)
Exam tips
- Exam answers that stress 'one OS, one CLI, one release train, modular daemons' describe Junos. An answer saying each platform has a different operating system is wrong.
- If a question asks which component forwards transit traffic, the answer is the PFE. If it asks which runs protocols, builds tables or hosts the CLI, the answer is the RE.
- The RE builds both tables but does not forward transit traffic. If an answer says the RE forwards packets between interfaces, it is describing the wrong component.
- Firewall filters, policers and CoS are enforced in the PFE even though you configure them on the RE. Questions sometimes suggest the RE inspects every transit packet; it does not.
- Match the daemon to the symptom: routing problems point to rpd, CLI or commit problems to mgd, interface configuration to dcd and hardware alarms to chassisd.
- Traceroute replies, pings to the router and routing protocol packets are all exception traffic. A ping through the router to a host on the other side is transit traffic.
- If an answer says Junos OS Evolved needs a different CLI or configuration syntax, it is wrong. The difference is the underlying OS: FreeBSD for Junos OS, Linux for Evolved.
- The filter goes on lo0 as an input filter under the family you want to protect (inet, inet6). Forgetting routing protocols, or forgetting that there is an implicit discard, is the usual trap.
- Snapshots copy software and configuration to backup media for booting; the rescue configuration is only a configuration file. Keep the two apart in exam answers.
Key terms
- Junos OS
- Juniper's network operating system, used across its routing, switching and security platforms.
- Daemon
- A background process with a single responsibility, such as routing or the CLI, running in its own protected memory.
- Modularity
- The design in which separate processes can fail and restart independently without crashing the system.
- Candidate configuration
- The working copy of the configuration you edit; it takes effect only after a commit.
- Control plane
- The functions that decide where traffic goes: routing protocols, management and table building, handled by the Routing Engine.
- Forwarding plane
- The functions that move transit packets using the forwarding table, handled by the Packet Forwarding Engine.
- Routing Engine (RE)
- The CPU-based component that runs Junos, the CLI and routing protocols.
- Packet Forwarding Engine (PFE)
- The component, usually ASIC-based, that forwards traffic at line rate.
- Exception traffic
- Packets that the PFE must send up to the RE, such as traffic addressed to the router itself.
- Routing table (RIB)
- The RE's table of all known routes from every source; inet.0 holds IPv4 unicast routes.
- Forwarding table (FIB)
- The table of active routes with resolved next hops that the RE pushes to the PFE.
- Route preference
- Junos's value for choosing between sources for the same prefix; lower wins (direct 0, static 5, OSPF 10, BGP 170).
- Active route
- The route the RE chooses for a prefix and installs in the forwarding table, marked with * in
show route. - PFE
- Packet Forwarding Engine: the component that forwards transit traffic using a copy of the forwarding table.
- ASIC
- Application-specific integrated circuit: custom silicon that performs lookups and forwarding at high speed.
- FPC
- Flexible PIC Concentrator: a line card in a modular Junos chassis that contains PFE hardware.
- PIC
- Physical Interface Card: the module that provides the physical ports; its number is the middle value in names like ge-0/1/0.
- Firewall filter
- Juniper's stateless packet filter, evaluated in the PFE, similar to an access control list.
- rpd
- Routing protocol daemon: runs routing protocols, policy and route selection, and maintains the routing tables.
- mgd
- Management daemon: serves the CLI and automation interfaces and processes configuration commits.
- dcd
- Device control daemon: configures and manages physical and logical interfaces.
- chassisd
- Chassis daemon: monitors and controls hardware components and raises chassis alarms.
- Transit traffic
- Packets that pass through the device to another destination, forwarded entirely by the PFE.
- Host-bound traffic
- Traffic addressed to the device itself, such as routing protocols, SSH, SNMP or pings.
- DDoS protection
- Per-protocol policing on many Junos platforms that limits how much of each exception traffic type reaches the RE.
- Junos OS Evolved
- A Linux-based variant of Junos with a more distributed internal architecture and the same CLI.
- FreeBSD
- A Unix-like open-source operating system that is the base of classic Junos OS.
- show version
- Operational command that shows the model, host name and running software release.
- lo0
- The loopback interface, representing the device itself; a filter on it applies to all host-bound traffic.
- Firewall filter term
- One rule in a filter, with
frommatch conditions andthenactions, evaluated in order. - Implicit discard
- The hidden final action of every Junos firewall filter that drops packets matching no term.
- Prefix list
- A named list of prefixes under
policy-optionsthat filters and policies can reference. - commit confirmed
- A commit that rolls back automatically unless confirmed with another commit within a set time.
- Primary boot media
- The storage device the system normally boots Junos from, typically internal flash or SSD.
- Backup boot media
- Alternate storage, such as a second partition, disk or USB, used when the primary fails.
- Snapshot
- A copy of the running software and configuration to backup media, made with
request system snapshot. - Rescue configuration
- A saved known-good configuration you can restore with
rollback rescue. - juniper.conf.gz
- The compressed file in /config that holds the active configuration.
Domain 3: User interfaces (14%)
Exam tips
- Link the keyword to its effect: exclusive locks others out; private isolates your changes; plain configure shares one candidate with everyone.
upgoes one level up;exitreturns to where you were before the lastedit, which may be several levels up. At the top level,exitleaves configuration mode.- Space completes only built-in keywords; Tab completes built-in keywords and user-defined names. That difference is a favourite exam question.
- Match the verb to the need: concepts use
help topic, exact syntax useshelp reference, and searching for a statement by keyword useshelp apropos. findstarts at the first match and keeps printing everything after it;matchprints only matching lines. Questions often contrast them.- In configuration mode,
show | comparecompares candidate against active. Addingrollback ncompares against an older commit. Inherited group settings stay hidden unless you use| display inheritance. - In configuration mode,
showmeans configuration andrun showmeans live status. If a question asks how to ping from configuration mode, the answer includesrun. - Rollback only changes the candidate. Nothing on the device changes until you commit the rolled-back candidate.
- The statement is
set system services web-managementwithhttporhttps. J-Web changes use the same candidate, commit and rollback model as the CLI. - Know which management interface name goes with which platform family and remember it connects to the RE, not the PFE, so it does not route transit traffic.
Key terms
- Operational mode
- The CLI mode, shown by the
>prompt, used for monitoring, troubleshooting and system actions. - Configuration mode
- The CLI mode, shown by the
#prompt, used to change the candidate configuration. - configure exclusive
- Enters configuration mode and locks the candidate so no other user can commit.
- configure private
- Enters configuration mode with a private candidate so only your changes are committed.
- [edit] banner
- The line above the configuration prompt that shows your current position in the hierarchy.
- edit
- Moves to (and creates if needed) a configuration hierarchy level.
- up
- Moves up one level, or several with a number, such as
up 2. - top
- Moves to the top of the hierarchy, or runs a command from the top when used as a prefix.
- exit configuration-mode
- Leaves configuration mode from any hierarchy level.
- Space completion
- Pressing Space to complete built-in Junos commands and keywords.
- Tab completion
- Pressing Tab to complete both built-in keywords and user-defined names such as filters and policies.
- Context-sensitive help
- Using
?to list the commands, options or values valid at the current point. - Syntax error caret
- The ^ marker Junos prints under the part of a command it could not understand.
- help topic
- Displays conceptual, usage-guide information about a feature.
- help reference
- Displays syntax, hierarchy location, options and defaults for a configuration statement.
- help apropos
- Searches configuration statements for a string and lists matching statements and their paths.
- help syslog
- Explains the meaning of a system log message tag.
- | match
- Shows only output lines that match a pattern (regular expression).
- | except
- Hides output lines that match a pattern.
- | find
- Starts displaying output at the first line matching a pattern.
- | count
- Counts output lines instead of displaying them.
- | save
- Writes command output to a file on the device.
- | display set
- Shows configuration as the list of
setcommands that would recreate it. - | compare
- Shows differences between the candidate and active configuration, or against a rollback, using + and - markers.
- | display inheritance
- Shows configuration with values inherited from configuration groups filled in and annotated.
- Configuration group
- A reusable block of configuration under
[edit groups]applied elsewhere withapply-groups. - run
- A configuration-mode command that executes an operational-mode command without leaving configuration mode.
- show (configuration mode)
- Displays the candidate configuration at or below the current hierarchy level.
- run show
- Displays operational state from within configuration mode.
- Operational state
- What the device is actually doing now, such as interface status, routes and neighbors.
- Active configuration
- The committed configuration the device is currently running.
- Candidate configuration
- The editable copy of the configuration; changes take effect only after commit.
- Rollback
- Loading a previously committed configuration (0 to 49) into the candidate; it must then be committed.
- rollback 0
- Discards uncommitted changes by resetting the candidate to the active configuration.
- show system commit
- Lists commit history with time, user and any comments.
- J-Web
- The web-based graphical interface for managing many Junos devices.
- web-management
- The
[edit system services]statement that enables J-Web over HTTP and/or HTTPS. - system-generated-certificate
- An option that lets Junos create a self-signed certificate for HTTPS access to J-Web.
- Login class
- The set of permissions assigned to a user, which applies in J-Web as in the CLI.
- Console port
- A serial port connected directly to the RE, usable without any network configuration.
- SSH
- Secure Shell: encrypted remote CLI access over TCP port 22, enabled with
set system services ssh. - Out-of-band management
- Managing a device over a network path separate from the traffic it forwards.
- fxp0 / me0 / em0
- Platform-specific names for the dedicated management Ethernet interface connected to the RE.
- root-login deny
- SSH option that blocks the root account from logging in over SSH.
Domain 4: Configuration basics (15%)
Exam tips
- After
load factory-defaultthe root password is gone from the candidate, so you must set it again before committing. Questions often describe this failed commit and ask why. - Know the four predefined login classes and what each allows: super-user everything, operator view plus operational actions, read-only view only, unauthorized nothing.
- In a name like xe-1/2/3.0, the numbers are FPC 1, PIC 2, port 3, unit 0. Addresses always go under a unit and family, never directly on the physical interface.
- lo0 is always up and used for router IDs and RE protection; the management interface is out-of-band and does not forward transit traffic; irb is the Layer 3 gateway for a VLAN.
- If you do not confirm,
commit confirmedrolls back automatically, 10 minutes by default. Confirm with a plaincommit.commit checknever changes the active configuration. - Remember that
rollback ndoes not take effect by itself; it only replaces the candidate. You must still commit. Also remember the range: 0 is the active config and 49 is the oldest. - Exam questions usually test merge versus override: merge keeps existing config and adds to it, override wipes everything not in the file. Also remember that factory-default will not commit without a root password.
- Know the difference between
deactivate(configuration kept but ignored),delete(configuration removed) anddisable(configured but administratively down). Also know that new terms go to the end, soinsertis the fix when term order is wrong. - Explicit configuration always beats group inheritance, and the first group listed wins among peers. If a question asks why a statement is in effect but not visible, the answer is usually a group;
show | display inheritancereveals it. - Expect questions on where services live:
system servicesfor SSH and telnet,system ntp,system syslog, but top-levelsnmp. Also remember that a syslog severity includes everything more severe than it.
Key terms
- Factory-default configuration
- The platform-specific configuration a Junos device ships with and returns to after a reset.
- root-authentication
- The mandatory
[edit system]statement that sets the root account's password or key. - plain-text-password
- An option that prompts for a password and stores it in hashed form in the configuration.
- load factory-default
- A configuration-mode command that replaces the candidate with the factory-default configuration.
- request system zeroize
- An operational command that erases configuration and data and returns the device to factory state.
- host-name
- The
[edit system]statement that names the device, shown in the prompt and logs. - Login class
- A set of permissions assigned to user accounts; predefined classes are super-user, operator, read-only and unauthorized.
- super-user
- Predefined login class with all permissions.
- Static default route
- A manually configured 0.0.0.0/0 route used when no more specific route matches.
- next-hop
- The address of the neighboring router to which a static route sends matching traffic.
- type-fpc/pic/port
- The Junos interface naming format, such as ge-0/0/1, identifying technology, line card, interface card and port.
- Logical unit
- A logical interface under a physical port, written as .unit, that holds families and addresses.
- Physical properties
- Settings for the whole port, such as MTU, speed, description and VLAN tagging.
- family inet / inet6
- Protocol families that enable IPv4 or IPv6 on a logical unit.
- vlan-tagging
- A physical property that allows multiple units, each with its own VLAN ID, on one port.
- lo0
- The loopback interface representing the device itself; always up, typically holding a /32 router ID address.
- Management interface
- fxp0, em0 or me0: an out-of-band Ethernet port connected to the RE, not used for transit traffic.
- irb
- Integrated routing and bridging: a Layer 3 interface attached to a VLAN that acts as its routed gateway.
- l3-interface
- The VLAN statement that associates a VLAN with its irb unit.
- commit check
- Validates the candidate configuration without activating it.
- commit confirmed
- Commits with an automatic rollback (10 minutes by default) unless confirmed by a second commit.
- commit and-quit
- Commits and then exits configuration mode if the commit succeeds.
- commit comment
- Attaches a text note to a commit, shown in
show system commit. - commit at
- Schedules a validated commit to take effect at a specified time; cancel with
clear system commit. - Rollback 0
- The currently active (committed) configuration;
rollbackwith no number returns the candidate to it. - Rollback n
- A previously committed configuration, numbered 1 to 49 by age, which can be loaded into the candidate.
- show | compare
- Displays differences between the candidate and the active configuration or a named rollback, using + and - markers.
- Rescue configuration
- A manually saved known-good configuration, loaded with
rollback rescue, that is not replaced by normal commits. - load merge
- Combines statements from a file or terminal with the existing candidate, with the loaded values winning on conflicts.
- load override
- Discards the whole candidate and replaces it with the loaded configuration.
- load replace
- Replaces only the configuration sections that are marked with the
replace:tag in the loaded text. - load set
- Loads a list of
setanddeletecommands, as produced by| display set. - deactivate
- Marks a statement
inactive:so it stays in the configuration but is ignored at commit; reversed withactivate. - annotate
- Attaches a comment to a statement at the current hierarchy level, shown as
/* ... */. - rename
- Changes the name of a configuration element in place without updating other references to it.
- insert
- Moves an ordered element, such as a policy or filter term, before or after another.
- groups
- The configuration hierarchy where reusable blocks of configuration are defined.
- apply-groups
- The statement that makes a group's configuration inherit into the level where it is applied.
- Wildcard (<...>)
- A pattern in angle brackets inside a group, such as
<ge-*>, that matches existing configuration names. - display inheritance
- A
showpipe option that expands inherited group statements and marks where each came from. - SSH
- Secure Shell, an encrypted protocol for remote command-line access, enabled with
set system services ssh. - NTP
- Network Time Protocol, which synchronizes the device clock with a time server.
- Syslog severity
- The level of an event, from emergency (most serious) to debug; a configured level includes all more serious levels.
- SNMP community
- A shared string used by SNMPv1/v2c to authorize polling; it provides weak, clear-text protection.
Domain 5: Operational monitoring and maintenance (15%)
Exam tips
- Chassis alarms are about hardware and environment; system alarms are about software and configuration. A missing rescue configuration is the classic example of a system alarm.
- Remember that
monitor traffic interfacenormally sees only traffic to or from the Routing Engine, not transit traffic. And up/down (admin up, link down) is a physical problem, while down in the Admin column means the interface is disabled in configuration. - Junos ping runs forever without
countorrapid. When a question describes a ping from the router working but hosts failing, think about the source address and the return route. - Syslog records events at a chosen severity; traceoptions give protocol-level debugging detail. Both end up in /var/log and both are read with
show log <file>. Always remove traceoptions after troubleshooting. - Use
dry-runto preview a cleanup. Know the directories: logs in /var/log, packages usually staged in /var/tmp, and user files in the home directory wheresavewrites by default. - The install command is
request system software add; addrebootto activate it immediately. Snapshots copy software and configuration to alternate media, so take them after the new release has proven stable. - Know the outcome of each command: reboot restarts automatically, halt stops but stays powered, power-off turns the power off. Never pull power from a running device without halting first.
- Password recovery requires physical console access and ends with a normal commit of the new root password. Marking the console
insecureprevents this recovery method. - Saving is an operational-mode
requestcommand, but restoring isrollback rescuein configuration mode followed by commit. A missing rescue configuration shows up inshow system alarms. - An asterisk in
show ntp associationsmeans synchronized. SNMP polls are answered by the agent, traps are pushed by it; SNMPv3 adds authentication and encryption that v2c lacks.
Key terms
- Chassis alarm
- A hardware or environmental alarm, such as a failed fan or power supply, shown by
show chassis alarms. - System alarm
- A software or configuration alarm, such as a missing rescue configuration, shown by
show system alarms. - Routing Engine (RE)
- The control-plane component that runs Junos, routing protocols and management; its health is shown by
show chassis routing-engine. - FPC
- Flexible PIC Concentrator, a line card slot that holds PICs and forwards traffic on many Junos platforms.
- show interfaces terse
- A one-line-per-interface summary of admin status, link status, protocol families and addresses.
- extensive
- The most detailed interface output, including error counters such as CRC errors, drops and carrier transitions.
- monitor interface
- A live, auto-refreshing display of one interface's counters and rates.
- monitor traffic interface
- A tcpdump-like capture of packets to and from the Routing Engine on an interface.
- ping rapid
- A ping mode that sends a burst of echo requests and prints
!for replies and.for timeouts. - source option
- Sets the source IP address of a test packet, which affects whether the far end can reply.
- traceroute
- A tool that reveals each router hop to a destination using increasing TTL values.
- routing-instance option
- Runs a test using a specific routing instance's table instead of the default inet.0.
- /var/log/messages
- The main system log file on Junos, holding events from all facilities at the configured severity.
- show log
- Displays a log file from /var/log, or lists the files when used alone.
- monitor start
- Prints new lines of a log or trace file to the terminal in real time until
monitor stop. - traceoptions
- Per-protocol or per-process debugging configuration that writes detailed events to a trace file based on selected flags.
- file list
- Lists files in a directory;
detailadds size, owner and date. - file show
- Displays the contents of a text file from the CLI.
- request system storage cleanup
- Removes rotated logs, crash files and temporary files after showing the list and asking for confirmation.
- dry-run
- A cleanup option that shows which files would be deleted without deleting them.
- request system software add
- The operational command that installs a Junos software package, optionally with
rebootto activate it immediately. - Configuration validation
- A check during installation that confirms the current configuration is compatible with the new software.
- request system snapshot
- Copies the current software and configuration to alternate boot media as a backup.
- show version
- Displays the hostname, model and installed Junos software version.
- request system reboot
- Gracefully shuts down and restarts the device, optionally at a scheduled time.
- request system halt
- Gracefully stops the software while leaving power on, so the device can be safely unplugged or restarted from the console.
- request system power-off
- Gracefully shuts down and powers off the device; it stays off until powered on physically.
- clear system reboot
- Cancels a pending scheduled reboot.
- Single-user mode
- A minimal boot state, entered from the loader (for example with
boot -s), used for recovery tasks. - recovery
- The keyword typed at the single-user prompt to start the Junos CLI as root for password recovery.
- root-authentication
- The
systemconfiguration statement that holds the root user's password; it must be set before any commit. - console insecure
- A
system ports consolesetting that requires the root password to enter single-user mode, blocking console password recovery. - request system configuration rescue save
- Saves the current active configuration as the rescue configuration.
- rollback rescue
- Loads the rescue configuration into the candidate; a commit activates it.
- request system configuration rescue delete
- Removes the saved rescue configuration.
- Rescue alarm
- A minor system alarm raised on many devices when no rescue configuration has been saved.
- show ntp associations
- Lists NTP servers with stratum, reachability and offset;
*marks the server the device is synchronized to. - SNMP trap
- An unsolicited message from the device's SNMP agent to a management system about an event.
- SNMPv3
- A version of SNMP that adds user-based authentication and encryption.
- source-address
- An option for services such as syslog and NTP that fixes the source IP of outgoing packets, often to the loopback.
Domain 6: Routing fundamentals (14%)
Exam tips
- Longest match is decided first; preference only chooses among routes to the exact same prefix. The
*marks the active route and>marks the selected next hop. - Learn the naming pattern: family (inet or inet6) plus a number, with instance tables prefixed by the instance name. inet.3 is for MPLS next-hop resolution, not ordinary IP forwarding.
- Memorize the list in order: 0, 5, 10, 100, 130, 150, 170. The classic trap is comparing OSPF external (150) with RIP (100): RIP wins. Another trap is forgetting that longest match comes before preference.
- Match the type to the use: virtual-router for simple separation, forwarding for filter-based forwarding (no interfaces), vrf for MPLS Layer 3 VPNs with route distinguishers and targets.
- A static next hop must normally be directly connected, or the route will not become active. A higher preference makes a route a backup, and reject differs from discard only by sending an ICMP unreachable.
- An aggregate needs at least one contributing route to be active, uses preference 130, has reject as its default next hop and is not advertised until an export policy sends it out.
- IGP means inside one AS and is about fast, best-path convergence; EGP means between ASs and is about policy and scale. OSPF is link-state with SPF and areas; BGP is path-vector over TCP 179 with the AS path for loop prevention.
- Know every symbol:
*active,>selected next hop, brackets show protocol/preference. Useprotocolto filter by source,tableto choose a table anddetailto see why a route is inactive.
Key terms
- Longest-prefix match
- The forwarding rule that chooses the most specific matching prefix for a destination address.
- Next hop
- The neighboring address and outgoing interface to which a packet is sent.
- Active route
- The single best route for a prefix, marked
*inshow route, and the only one installed in the forwarding table. - Forwarding table
- The table built from active routes that the Packet Forwarding Engine uses to forward packets.
- inet.0
- The main IPv4 unicast routing table.
- inet6.0
- The IPv6 unicast routing table.
- inet.3
- An IPv4 table of MPLS LSP egress addresses used mainly for BGP next-hop resolution.
- Instance table
- A routing table belonging to a routing instance, named like
vr1.inet.0. - Route preference
- A number assigned to each route source in Junos; for the same prefix the lowest value becomes active.
- OSPF internal route
- A route learned from within the OSPF domain, with default preference 10.
- OSPF external route
- A route redistributed into OSPF from another source, with default preference 150.
- Floating static route
- A static route with a raised preference so it is used only when a better route is missing.
- virtual-router
- An instance type with its own interfaces and routing table, used to create independent routers on one device without VPN signaling.
- forwarding instance
- An instance type with a routing table but no interfaces, used with firewall filters for filter-based forwarding.
- VRF
- VPN routing and forwarding instance type used for MPLS Layer 3 VPNs, requiring a route distinguisher and VRF target or policies.
- Route distinguisher
- A value added to VPN prefixes to keep overlapping customer addresses unique in the provider network.
- next-hop
- The directly connected address a static route forwards to; if unreachable, the route is not usable.
- qualified-next-hop
- A next hop within a static route that has its own preference or metric, used for backup paths.
- discard vs reject
- Both drop matching packets; reject also sends an ICMP unreachable message, discard stays silent.
- Default route
- The route 0.0.0.0/0 (or ::/0) that matches any destination not covered by a more specific route.
- Aggregate route
- A summary route under
routing-options aggregate, active only when a contributing route exists, with a reject next hop by default. - Contributing route
- An active, more specific route that falls within an aggregate or generated route and keeps it active.
- Generated route
- A summary-like route that takes the next hop of its primary contributing route instead of reject.
- Autonomous system (AS)
- A network under one administrative control with its own routing policy, identified by an AS number.
- IGP
- Interior gateway protocol, such as OSPF, IS-IS or RIP, used within a single AS.
- EGP
- Exterior gateway protocol used between autonomous systems; BGP is the one used today.
- Link-state
- A protocol design, used by OSPF, where routers flood link information and each computes paths with SPF.
- AS path
- A BGP attribute listing the autonomous systems a route has crossed, used for loop prevention and path selection.
- Hidden route
- A route Junos knows but cannot use, often because its next hop is unresolvable or a policy rejected it; shown with
show route hidden. - Direct route
- A route to the subnet configured on an interface, with preference 0.
- Local route
- A /32 (or /128) route to the device's own interface address, with preference 0.
- show route detail
- Output that adds state, age, task, inactive reason and protocol attributes for each route.
Domain 7: Routing policy and firewall filters (12%)
Exam tips
- Import and export are relative to the routing table: import is into it, export is out of it. OSPF import policy cannot stop LSA flooding; to advertise static or direct routes into OSPF you need an export policy.
- The RIP trap is common: RIP needs an export policy even to advertise its own connected networks. For OSPF, 'export rejects all' does not stop normal OSPF operation; it only stops redistribution of other routes.
- Several conditions in one
fromare ANDed; several values in one condition are ORed. A term with nofrommatches everything, and a term with only modifying actions continues to the next term. - The first terminating action anywhere in the chain wins; later policies and the default are never consulted for that route. If nothing terminates, the protocol default policy decides, which for BGP export means advertising active BGP routes.
- Know the difference between orlonger (includes the prefix) and longer (excludes it), and between upto (starts at the prefix length) and prefix-length-range (starts where you say). Multiple route filters in one term use longest match first, then the match type.
test policyaccepts by default any route the policy does not explicitly reject, regardless of the protocol's default policy. Use0.0.0.0/0to test the whole table.- Filters are stateless, evaluated top to bottom, and end with an implicit discard. Multiple conditions in one term are ANDed, multiple values in one condition are ORed.
- A term with only non-terminating actions implicitly accepts the packet. Discard is silent; reject sends ICMP back. Log goes to a local buffer (
show firewall log); syslog goes to the system log. - A filter on lo0 input protects the Routing Engine from traffic arriving on any interface but does not filter transit traffic. Always include routing protocols and management services, and use
commit confirmed. - Strict mode checks the arrival interface and suits single-homed edges; loose mode only checks that a route exists and suits asymmetric or multihomed links. Asymmetric routing plus strict mode drops legitimate traffic.
Key terms
- Import policy
- A routing policy applied to routes received from a protocol before they are placed in the routing table.
- Export policy
- A routing policy applied to active routes as they are advertised from the routing table into a protocol.
- Redistribution
- Advertising routes learned from one source into another protocol; in Junos this is done with export policy.
- policy-statement
- The named routing policy object configured under
policy-options. - Default policy
- The built-in, protocol-specific policy evaluated after all configured policies when none has made a final decision.
- BGP default export
- Advertises active BGP routes to BGP peers, except that IBGP-learned routes are not sent to other IBGP peers.
- OSPF default export
- Rejects all routes; OSPF's own link-state information is still flooded by the protocol itself.
- RIP default export
- Rejects all routes, so a RIP router advertises nothing until an export policy is configured.
- Term
- A named if-then rule inside a policy, containing
frommatch conditions andthenactions. - Terminating action
acceptorreject; ends policy evaluation for that route immediately.- Flow-control action
next termornext policy; moves evaluation to another term or policy without deciding the route's fate.- Modifying action
- An action that changes route attributes, such as metric or community, without ending evaluation.
- Policy chain
- An ordered list of policies applied in one place, evaluated left to right.
- Fall-through
- What happens when no configured policy makes a terminating decision, so the protocol's default policy decides.
- Explicit reject term
- A final term with no
fromandthen reject, used to prevent routes from reaching the default policy. - Policy hierarchy in BGP
- Policies applied at neighbor level override those at group level, which override global ones.
- exact
- Matches only the route equal to the filter's prefix and length.
- orlonger
- Matches the filter's prefix and any more specific route inside it.
- longer
- Matches only routes more specific than the filter's prefix, not the prefix itself.
- upto
- Matches routes inside the prefix with lengths from the prefix's own length up to the stated length.
- prefix-length-range
- Matches routes inside the prefix whose lengths fall between two stated lengths.
- Prefix list
- A named, reusable list of prefixes, matched exactly with
prefix-listor with a match type viaprefix-list-filter. - test policy
- An operational command that runs routing table entries through a policy and shows the routes it accepts.
- Default accept in test policy
- Routes not explicitly rejected by the tested policy are shown as accepted.
- advertising-protocol
show route advertising-protocol bgp <neighbor>shows the routes actually being advertised to a BGP neighbor.- commit confirmed
- A commit that rolls back automatically unless confirmed within a set time, useful when applying risky policy changes.
- Stateless filter
- A filter that evaluates each packet independently without tracking connections, so return traffic must be explicitly allowed.
- Implicit discard
- The hidden final action of every Junos firewall filter that silently drops packets not matched by any term.
- tcp-established
- A match condition for TCP packets with the ACK or RST flag set, typically reply traffic.
- Match condition
- A
fromcriterion such as address, protocol or port used to select packets in a filter term. - discard
- A terminating action that drops the packet silently.
- reject
- A terminating action that drops the packet and sends an ICMP unreachable (or TCP reset) to the source.
- count
- A non-terminating action that increments a named packet and byte counter.
- policer
- A non-terminating action that rate-limits matching traffic using a policer defined under
firewall policer. - log vs syslog
logstores packet headers in a Routing Engine buffer forshow firewall log;syslogwrites to the system log.- Input filter
- A filter applied to packets arriving on an interface.
- Output filter
- A filter applied to packets leaving an interface.
- lo0 filter
- An input filter on the loopback interface that inspects all traffic destined to the Routing Engine from any interface.
- Host-bound traffic
- Packets addressed to the device itself, such as management and routing protocol traffic, processed by the RE.
- uRPF
- Unicast reverse path forwarding, a check that validates a packet's source address against the forwarding table to drop spoofed traffic.
- Strict mode
- The source must be reachable via the same interface the packet arrived on.
- Loose mode
- The source only needs a route in the forwarding table via any interface.
- fail-filter
- A firewall filter applied only to packets that fail the uRPF check, used for exceptions or logging.
- Feasible paths
- An option that lets uRPF consider all valid alternate paths, not just active ones, to handle asymmetric routing.
Study JNCIA-Junos for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the JNCIA-Junos study planLessons, quizzes, exam simulations and hands-on labs.