StudyToCert

All certifications / JNCIA-Junos / Cheat sheet

JNCIA-Junos JN0-106 cheat sheet

Every exam tip and key term from the free JNCIA-Junos lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Networking fundamentals (15%)

Exam tips

Key terms

Collision domain
A network segment where simultaneous transmissions can collide; each switch or router port is its own collision domain.
Broadcast domain
The set of devices that receive a Layer 2 broadcast from any member; bounded by routers and by VLANs.
CSMA/CD
Carrier sense multiple access with collision detection, the half-duplex Ethernet method of listening, detecting collisions and backing off.
Full duplex
A link mode where a device can send and receive at the same time, which removes collisions entirely.
VLAN
Virtual LAN: a logical Layer 2 segment on a switch; each VLAN is a separate broadcast domain.
Frame
A Layer 2 unit of data with a header containing source and destination MAC addresses.
Packet
A Layer 3 unit of data with a header containing source and destination IP addresses and a TTL.
Ethernet switching table
The Junos table mapping learned MAC addresses to interfaces and VLANs, shown with show ethernet-switching table.
Routing table
A table of destination prefixes and next hops; on Junos the IPv4 unicast table is inet.0.
Longest-prefix match
The rule that a router uses the most specific matching route when several prefixes contain the destination.
MAC address
A 48-bit Layer 2 hardware address, written as 12 hexadecimal digits, that identifies a network interface.
OUI
Organizationally unique identifier: the first 24 bits of a MAC address, identifying the manufacturer.
EtherType
The 2-byte field that identifies the payload protocol, such as 0x0800 for IPv4 or 0x0806 for ARP.
FCS
Frame check sequence: a CRC at the end of the frame used to detect transmission errors.
Flooding
Sending a frame out all ports in the VLAN except the ingress port, used for broadcasts and unknown destinations.
ARP
Address Resolution Protocol: maps an IPv4 address to a MAC address on the local link using a broadcast request and a unicast reply.
ARP cache
The table of learned IP-to-MAC mappings, shown on Junos with show arp.
Gratuitous ARP
An unsolicited ARP about the sender's own IP, used for duplicate address detection and to update neighbors' caches.
no-resolve
A Junos output option that stops the command from doing reverse DNS lookups on addresses.
CIDR
Classless inter-domain routing: addressing with arbitrary prefix lengths written as address/length, replacing classful boundaries.
Subnet mask
A 32-bit value of contiguous 1s (network part) followed by 0s (host part), such as 255.255.255.192 for /26.
RFC 1918 private ranges
10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, reserved for internal use and not routed on the internet.
Broadcast address
The last address in a subnet, with all host bits set to 1, used to reach every host on that subnet.
Block size
256 minus the interesting mask octet; the spacing between consecutive subnet addresses.
Hextet
One of the eight 16-bit groups of an IPv6 address, written as up to four hexadecimal digits.
Link-local address
An fe80::/10 address automatically present on every IPv6 interface, valid only on the local link.
Global unicast address
A publicly routable IPv6 address, currently from 2000::/3.
EUI-64
A method of forming a 64-bit interface ID from a MAC address by inserting fffe and flipping the universal/local bit.
Multicast (IPv6)
Addresses in ff00::/8 that deliver to a group; IPv6 uses multicast instead of broadcast.
Encapsulation
Adding each layer's header (and trailer) to data as it moves down the stack.
TCP
Connection-oriented, reliable transport using a three-way handshake, sequence numbers, acknowledgments and retransmission.
UDP
Connectionless, best-effort transport with a small header and no acknowledgments or retransmission.
Well-known ports
Port numbers 0 to 1023, assigned to common services such as SSH (22) and HTTPS (443).
Three-way handshake
The SYN, SYN-ACK, ACK exchange that opens a TCP connection.
Class of service (CoS)
The set of features that classify, queue, schedule and mark traffic so different classes get different treatment.
Forwarding class
The Junos label assigned to a packet that determines which output queue it uses.
Loss priority
A per-packet value (such as low or high) that tells the router which packets to drop first under congestion.
Scheduler
A set of parameters for a queue, including transmit rate, buffer size and priority.
Rewrite rule
An egress rule that sets CoS markings like DSCP in outgoing packets based on forwarding class and loss priority.
best-effort (BE)
Default forwarding class for ordinary traffic, mapped to queue 0.
expedited-forwarding (EF)
Default forwarding class for low-latency, low-jitter traffic such as voice, mapped to queue 1.
assured-forwarding (AF)
Default forwarding class for traffic that needs a bandwidth guarantee, mapped to queue 2.
network-control (NC)
Default forwarding class for routing and control protocol traffic, mapped to queue 3.
show interfaces queue
Operational command that shows per-queue transmit and drop counters for an interface.
Behavior aggregate (BA) classifier
A classifier that maps a single CoS marking (DSCP, IP precedence, 802.1p or MPLS EXP) to a forwarding class and loss priority.
Multifield (MF) classifier
A firewall filter that matches several header fields and sets forwarding class and loss priority as its action.
DSCP
Differentiated Services Code Point: 6 bits in the IP header used to mark a packet's CoS treatment.
EF (DSCP 46)
The DSCP value conventionally used for expedited, low-latency traffic such as voice.

Domain 2: Junos OS fundamentals (15%)

Exam tips

Key terms

Junos OS
Juniper's network operating system, used across its routing, switching and security platforms.
Daemon
A background process with a single responsibility, such as routing or the CLI, running in its own protected memory.
Modularity
The design in which separate processes can fail and restart independently without crashing the system.
Candidate configuration
The working copy of the configuration you edit; it takes effect only after a commit.
Control plane
The functions that decide where traffic goes: routing protocols, management and table building, handled by the Routing Engine.
Forwarding plane
The functions that move transit packets using the forwarding table, handled by the Packet Forwarding Engine.
Routing Engine (RE)
The CPU-based component that runs Junos, the CLI and routing protocols.
Packet Forwarding Engine (PFE)
The component, usually ASIC-based, that forwards traffic at line rate.
Exception traffic
Packets that the PFE must send up to the RE, such as traffic addressed to the router itself.
Routing table (RIB)
The RE's table of all known routes from every source; inet.0 holds IPv4 unicast routes.
Forwarding table (FIB)
The table of active routes with resolved next hops that the RE pushes to the PFE.
Route preference
Junos's value for choosing between sources for the same prefix; lower wins (direct 0, static 5, OSPF 10, BGP 170).
Active route
The route the RE chooses for a prefix and installs in the forwarding table, marked with * in show route.
PFE
Packet Forwarding Engine: the component that forwards transit traffic using a copy of the forwarding table.
ASIC
Application-specific integrated circuit: custom silicon that performs lookups and forwarding at high speed.
FPC
Flexible PIC Concentrator: a line card in a modular Junos chassis that contains PFE hardware.
PIC
Physical Interface Card: the module that provides the physical ports; its number is the middle value in names like ge-0/1/0.
Firewall filter
Juniper's stateless packet filter, evaluated in the PFE, similar to an access control list.
rpd
Routing protocol daemon: runs routing protocols, policy and route selection, and maintains the routing tables.
mgd
Management daemon: serves the CLI and automation interfaces and processes configuration commits.
dcd
Device control daemon: configures and manages physical and logical interfaces.
chassisd
Chassis daemon: monitors and controls hardware components and raises chassis alarms.
Transit traffic
Packets that pass through the device to another destination, forwarded entirely by the PFE.
Host-bound traffic
Traffic addressed to the device itself, such as routing protocols, SSH, SNMP or pings.
DDoS protection
Per-protocol policing on many Junos platforms that limits how much of each exception traffic type reaches the RE.
Junos OS Evolved
A Linux-based variant of Junos with a more distributed internal architecture and the same CLI.
FreeBSD
A Unix-like open-source operating system that is the base of classic Junos OS.
show version
Operational command that shows the model, host name and running software release.
lo0
The loopback interface, representing the device itself; a filter on it applies to all host-bound traffic.
Firewall filter term
One rule in a filter, with from match conditions and then actions, evaluated in order.
Implicit discard
The hidden final action of every Junos firewall filter that drops packets matching no term.
Prefix list
A named list of prefixes under policy-options that filters and policies can reference.
commit confirmed
A commit that rolls back automatically unless confirmed with another commit within a set time.
Primary boot media
The storage device the system normally boots Junos from, typically internal flash or SSD.
Backup boot media
Alternate storage, such as a second partition, disk or USB, used when the primary fails.
Snapshot
A copy of the running software and configuration to backup media, made with request system snapshot.
Rescue configuration
A saved known-good configuration you can restore with rollback rescue.
juniper.conf.gz
The compressed file in /config that holds the active configuration.

Domain 3: User interfaces (14%)

Exam tips

Key terms

Operational mode
The CLI mode, shown by the > prompt, used for monitoring, troubleshooting and system actions.
Configuration mode
The CLI mode, shown by the # prompt, used to change the candidate configuration.
configure exclusive
Enters configuration mode and locks the candidate so no other user can commit.
configure private
Enters configuration mode with a private candidate so only your changes are committed.
[edit] banner
The line above the configuration prompt that shows your current position in the hierarchy.
edit
Moves to (and creates if needed) a configuration hierarchy level.
up
Moves up one level, or several with a number, such as up 2.
top
Moves to the top of the hierarchy, or runs a command from the top when used as a prefix.
exit configuration-mode
Leaves configuration mode from any hierarchy level.
Space completion
Pressing Space to complete built-in Junos commands and keywords.
Tab completion
Pressing Tab to complete both built-in keywords and user-defined names such as filters and policies.
Context-sensitive help
Using ? to list the commands, options or values valid at the current point.
Syntax error caret
The ^ marker Junos prints under the part of a command it could not understand.
help topic
Displays conceptual, usage-guide information about a feature.
help reference
Displays syntax, hierarchy location, options and defaults for a configuration statement.
help apropos
Searches configuration statements for a string and lists matching statements and their paths.
help syslog
Explains the meaning of a system log message tag.
| match
Shows only output lines that match a pattern (regular expression).
| except
Hides output lines that match a pattern.
| find
Starts displaying output at the first line matching a pattern.
| count
Counts output lines instead of displaying them.
| save
Writes command output to a file on the device.
| display set
Shows configuration as the list of set commands that would recreate it.
| compare
Shows differences between the candidate and active configuration, or against a rollback, using + and - markers.
| display inheritance
Shows configuration with values inherited from configuration groups filled in and annotated.
Configuration group
A reusable block of configuration under [edit groups] applied elsewhere with apply-groups.
run
A configuration-mode command that executes an operational-mode command without leaving configuration mode.
show (configuration mode)
Displays the candidate configuration at or below the current hierarchy level.
run show
Displays operational state from within configuration mode.
Operational state
What the device is actually doing now, such as interface status, routes and neighbors.
Active configuration
The committed configuration the device is currently running.
Candidate configuration
The editable copy of the configuration; changes take effect only after commit.
Rollback
Loading a previously committed configuration (0 to 49) into the candidate; it must then be committed.
rollback 0
Discards uncommitted changes by resetting the candidate to the active configuration.
show system commit
Lists commit history with time, user and any comments.
J-Web
The web-based graphical interface for managing many Junos devices.
web-management
The [edit system services] statement that enables J-Web over HTTP and/or HTTPS.
system-generated-certificate
An option that lets Junos create a self-signed certificate for HTTPS access to J-Web.
Login class
The set of permissions assigned to a user, which applies in J-Web as in the CLI.
Console port
A serial port connected directly to the RE, usable without any network configuration.
SSH
Secure Shell: encrypted remote CLI access over TCP port 22, enabled with set system services ssh.
Out-of-band management
Managing a device over a network path separate from the traffic it forwards.
fxp0 / me0 / em0
Platform-specific names for the dedicated management Ethernet interface connected to the RE.
root-login deny
SSH option that blocks the root account from logging in over SSH.

Domain 4: Configuration basics (15%)

Exam tips

Key terms

Factory-default configuration
The platform-specific configuration a Junos device ships with and returns to after a reset.
root-authentication
The mandatory [edit system] statement that sets the root account's password or key.
plain-text-password
An option that prompts for a password and stores it in hashed form in the configuration.
load factory-default
A configuration-mode command that replaces the candidate with the factory-default configuration.
request system zeroize
An operational command that erases configuration and data and returns the device to factory state.
host-name
The [edit system] statement that names the device, shown in the prompt and logs.
Login class
A set of permissions assigned to user accounts; predefined classes are super-user, operator, read-only and unauthorized.
super-user
Predefined login class with all permissions.
Static default route
A manually configured 0.0.0.0/0 route used when no more specific route matches.
next-hop
The address of the neighboring router to which a static route sends matching traffic.
type-fpc/pic/port
The Junos interface naming format, such as ge-0/0/1, identifying technology, line card, interface card and port.
Logical unit
A logical interface under a physical port, written as .unit, that holds families and addresses.
Physical properties
Settings for the whole port, such as MTU, speed, description and VLAN tagging.
family inet / inet6
Protocol families that enable IPv4 or IPv6 on a logical unit.
vlan-tagging
A physical property that allows multiple units, each with its own VLAN ID, on one port.
lo0
The loopback interface representing the device itself; always up, typically holding a /32 router ID address.
Management interface
fxp0, em0 or me0: an out-of-band Ethernet port connected to the RE, not used for transit traffic.
irb
Integrated routing and bridging: a Layer 3 interface attached to a VLAN that acts as its routed gateway.
l3-interface
The VLAN statement that associates a VLAN with its irb unit.
commit check
Validates the candidate configuration without activating it.
commit confirmed
Commits with an automatic rollback (10 minutes by default) unless confirmed by a second commit.
commit and-quit
Commits and then exits configuration mode if the commit succeeds.
commit comment
Attaches a text note to a commit, shown in show system commit.
commit at
Schedules a validated commit to take effect at a specified time; cancel with clear system commit.
Rollback 0
The currently active (committed) configuration; rollback with no number returns the candidate to it.
Rollback n
A previously committed configuration, numbered 1 to 49 by age, which can be loaded into the candidate.
show | compare
Displays differences between the candidate and the active configuration or a named rollback, using + and - markers.
Rescue configuration
A manually saved known-good configuration, loaded with rollback rescue, that is not replaced by normal commits.
load merge
Combines statements from a file or terminal with the existing candidate, with the loaded values winning on conflicts.
load override
Discards the whole candidate and replaces it with the loaded configuration.
load replace
Replaces only the configuration sections that are marked with the replace: tag in the loaded text.
load set
Loads a list of set and delete commands, as produced by | display set.
deactivate
Marks a statement inactive: so it stays in the configuration but is ignored at commit; reversed with activate.
annotate
Attaches a comment to a statement at the current hierarchy level, shown as /* ... */.
rename
Changes the name of a configuration element in place without updating other references to it.
insert
Moves an ordered element, such as a policy or filter term, before or after another.
groups
The configuration hierarchy where reusable blocks of configuration are defined.
apply-groups
The statement that makes a group's configuration inherit into the level where it is applied.
Wildcard (<...>)
A pattern in angle brackets inside a group, such as <ge-*>, that matches existing configuration names.
display inheritance
A show pipe option that expands inherited group statements and marks where each came from.
SSH
Secure Shell, an encrypted protocol for remote command-line access, enabled with set system services ssh.
NTP
Network Time Protocol, which synchronizes the device clock with a time server.
Syslog severity
The level of an event, from emergency (most serious) to debug; a configured level includes all more serious levels.
SNMP community
A shared string used by SNMPv1/v2c to authorize polling; it provides weak, clear-text protection.

Domain 5: Operational monitoring and maintenance (15%)

Exam tips

Key terms

Chassis alarm
A hardware or environmental alarm, such as a failed fan or power supply, shown by show chassis alarms.
System alarm
A software or configuration alarm, such as a missing rescue configuration, shown by show system alarms.
Routing Engine (RE)
The control-plane component that runs Junos, routing protocols and management; its health is shown by show chassis routing-engine.
FPC
Flexible PIC Concentrator, a line card slot that holds PICs and forwards traffic on many Junos platforms.
show interfaces terse
A one-line-per-interface summary of admin status, link status, protocol families and addresses.
extensive
The most detailed interface output, including error counters such as CRC errors, drops and carrier transitions.
monitor interface
A live, auto-refreshing display of one interface's counters and rates.
monitor traffic interface
A tcpdump-like capture of packets to and from the Routing Engine on an interface.
ping rapid
A ping mode that sends a burst of echo requests and prints ! for replies and . for timeouts.
source option
Sets the source IP address of a test packet, which affects whether the far end can reply.
traceroute
A tool that reveals each router hop to a destination using increasing TTL values.
routing-instance option
Runs a test using a specific routing instance's table instead of the default inet.0.
/var/log/messages
The main system log file on Junos, holding events from all facilities at the configured severity.
show log
Displays a log file from /var/log, or lists the files when used alone.
monitor start
Prints new lines of a log or trace file to the terminal in real time until monitor stop.
traceoptions
Per-protocol or per-process debugging configuration that writes detailed events to a trace file based on selected flags.
file list
Lists files in a directory; detail adds size, owner and date.
file show
Displays the contents of a text file from the CLI.
request system storage cleanup
Removes rotated logs, crash files and temporary files after showing the list and asking for confirmation.
dry-run
A cleanup option that shows which files would be deleted without deleting them.
request system software add
The operational command that installs a Junos software package, optionally with reboot to activate it immediately.
Configuration validation
A check during installation that confirms the current configuration is compatible with the new software.
request system snapshot
Copies the current software and configuration to alternate boot media as a backup.
show version
Displays the hostname, model and installed Junos software version.
request system reboot
Gracefully shuts down and restarts the device, optionally at a scheduled time.
request system halt
Gracefully stops the software while leaving power on, so the device can be safely unplugged or restarted from the console.
request system power-off
Gracefully shuts down and powers off the device; it stays off until powered on physically.
clear system reboot
Cancels a pending scheduled reboot.
Single-user mode
A minimal boot state, entered from the loader (for example with boot -s), used for recovery tasks.
recovery
The keyword typed at the single-user prompt to start the Junos CLI as root for password recovery.
root-authentication
The system configuration statement that holds the root user's password; it must be set before any commit.
console insecure
A system ports console setting that requires the root password to enter single-user mode, blocking console password recovery.
request system configuration rescue save
Saves the current active configuration as the rescue configuration.
rollback rescue
Loads the rescue configuration into the candidate; a commit activates it.
request system configuration rescue delete
Removes the saved rescue configuration.
Rescue alarm
A minor system alarm raised on many devices when no rescue configuration has been saved.
show ntp associations
Lists NTP servers with stratum, reachability and offset; * marks the server the device is synchronized to.
SNMP trap
An unsolicited message from the device's SNMP agent to a management system about an event.
SNMPv3
A version of SNMP that adds user-based authentication and encryption.
source-address
An option for services such as syslog and NTP that fixes the source IP of outgoing packets, often to the loopback.

Domain 6: Routing fundamentals (14%)

Exam tips

Key terms

Longest-prefix match
The forwarding rule that chooses the most specific matching prefix for a destination address.
Next hop
The neighboring address and outgoing interface to which a packet is sent.
Active route
The single best route for a prefix, marked * in show route, and the only one installed in the forwarding table.
Forwarding table
The table built from active routes that the Packet Forwarding Engine uses to forward packets.
inet.0
The main IPv4 unicast routing table.
inet6.0
The IPv6 unicast routing table.
inet.3
An IPv4 table of MPLS LSP egress addresses used mainly for BGP next-hop resolution.
Instance table
A routing table belonging to a routing instance, named like vr1.inet.0.
Route preference
A number assigned to each route source in Junos; for the same prefix the lowest value becomes active.
OSPF internal route
A route learned from within the OSPF domain, with default preference 10.
OSPF external route
A route redistributed into OSPF from another source, with default preference 150.
Floating static route
A static route with a raised preference so it is used only when a better route is missing.
virtual-router
An instance type with its own interfaces and routing table, used to create independent routers on one device without VPN signaling.
forwarding instance
An instance type with a routing table but no interfaces, used with firewall filters for filter-based forwarding.
VRF
VPN routing and forwarding instance type used for MPLS Layer 3 VPNs, requiring a route distinguisher and VRF target or policies.
Route distinguisher
A value added to VPN prefixes to keep overlapping customer addresses unique in the provider network.
next-hop
The directly connected address a static route forwards to; if unreachable, the route is not usable.
qualified-next-hop
A next hop within a static route that has its own preference or metric, used for backup paths.
discard vs reject
Both drop matching packets; reject also sends an ICMP unreachable message, discard stays silent.
Default route
The route 0.0.0.0/0 (or ::/0) that matches any destination not covered by a more specific route.
Aggregate route
A summary route under routing-options aggregate, active only when a contributing route exists, with a reject next hop by default.
Contributing route
An active, more specific route that falls within an aggregate or generated route and keeps it active.
Generated route
A summary-like route that takes the next hop of its primary contributing route instead of reject.
Autonomous system (AS)
A network under one administrative control with its own routing policy, identified by an AS number.
IGP
Interior gateway protocol, such as OSPF, IS-IS or RIP, used within a single AS.
EGP
Exterior gateway protocol used between autonomous systems; BGP is the one used today.
Link-state
A protocol design, used by OSPF, where routers flood link information and each computes paths with SPF.
AS path
A BGP attribute listing the autonomous systems a route has crossed, used for loop prevention and path selection.
Hidden route
A route Junos knows but cannot use, often because its next hop is unresolvable or a policy rejected it; shown with show route hidden.
Direct route
A route to the subnet configured on an interface, with preference 0.
Local route
A /32 (or /128) route to the device's own interface address, with preference 0.
show route detail
Output that adds state, age, task, inactive reason and protocol attributes for each route.

Domain 7: Routing policy and firewall filters (12%)

Exam tips

Key terms

Import policy
A routing policy applied to routes received from a protocol before they are placed in the routing table.
Export policy
A routing policy applied to active routes as they are advertised from the routing table into a protocol.
Redistribution
Advertising routes learned from one source into another protocol; in Junos this is done with export policy.
policy-statement
The named routing policy object configured under policy-options.
Default policy
The built-in, protocol-specific policy evaluated after all configured policies when none has made a final decision.
BGP default export
Advertises active BGP routes to BGP peers, except that IBGP-learned routes are not sent to other IBGP peers.
OSPF default export
Rejects all routes; OSPF's own link-state information is still flooded by the protocol itself.
RIP default export
Rejects all routes, so a RIP router advertises nothing until an export policy is configured.
Term
A named if-then rule inside a policy, containing from match conditions and then actions.
Terminating action
accept or reject; ends policy evaluation for that route immediately.
Flow-control action
next term or next policy; moves evaluation to another term or policy without deciding the route's fate.
Modifying action
An action that changes route attributes, such as metric or community, without ending evaluation.
Policy chain
An ordered list of policies applied in one place, evaluated left to right.
Fall-through
What happens when no configured policy makes a terminating decision, so the protocol's default policy decides.
Explicit reject term
A final term with no from and then reject, used to prevent routes from reaching the default policy.
Policy hierarchy in BGP
Policies applied at neighbor level override those at group level, which override global ones.
exact
Matches only the route equal to the filter's prefix and length.
orlonger
Matches the filter's prefix and any more specific route inside it.
longer
Matches only routes more specific than the filter's prefix, not the prefix itself.
upto
Matches routes inside the prefix with lengths from the prefix's own length up to the stated length.
prefix-length-range
Matches routes inside the prefix whose lengths fall between two stated lengths.
Prefix list
A named, reusable list of prefixes, matched exactly with prefix-list or with a match type via prefix-list-filter.
test policy
An operational command that runs routing table entries through a policy and shows the routes it accepts.
Default accept in test policy
Routes not explicitly rejected by the tested policy are shown as accepted.
advertising-protocol
show route advertising-protocol bgp <neighbor> shows the routes actually being advertised to a BGP neighbor.
commit confirmed
A commit that rolls back automatically unless confirmed within a set time, useful when applying risky policy changes.
Stateless filter
A filter that evaluates each packet independently without tracking connections, so return traffic must be explicitly allowed.
Implicit discard
The hidden final action of every Junos firewall filter that silently drops packets not matched by any term.
tcp-established
A match condition for TCP packets with the ACK or RST flag set, typically reply traffic.
Match condition
A from criterion such as address, protocol or port used to select packets in a filter term.
discard
A terminating action that drops the packet silently.
reject
A terminating action that drops the packet and sends an ICMP unreachable (or TCP reset) to the source.
count
A non-terminating action that increments a named packet and byte counter.
policer
A non-terminating action that rate-limits matching traffic using a policer defined under firewall policer.
log vs syslog
log stores packet headers in a Routing Engine buffer for show firewall log; syslog writes to the system log.
Input filter
A filter applied to packets arriving on an interface.
Output filter
A filter applied to packets leaving an interface.
lo0 filter
An input filter on the loopback interface that inspects all traffic destined to the Routing Engine from any interface.
Host-bound traffic
Packets addressed to the device itself, such as management and routing protocol traffic, processed by the RE.
uRPF
Unicast reverse path forwarding, a check that validates a packet's source address against the forwarding table to drop spoofed traffic.
Strict mode
The source must be reachable via the same interface the packet arrived on.
Loose mode
The source only needs a route in the forwarding table via any interface.
fail-filter
A firewall filter applied only to packets that fail the uRPF check, used for exceptions or logging.
Feasible paths
An option that lets uRPF consider all valid alternate paths, not just active ones, to handle asymmetric routing.
Study JNCIA-Junos for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the JNCIA-Junos study plan