All certifications / JNCIA-Junos / Lessons
JNCIA-Junos JN0-106 lessons
Study JNCIA-Junos for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the JNCIA-Junos study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Networking fundamentals
- Collision domains and broadcast domains, and how switches and routers divide them
- What routers and switches do: Layer 2 frame forwarding vs Layer 3 packet forwarding
- Ethernet frames, MAC addresses (48 bits, OUI) and the MAC learning/flooding process
- ARP: resolving an IPv4 next hop to a MAC address; gratuitous ARP; `show arp`
- IPv4 addressing: classes, private ranges, subnet masks, CIDR prefixes and subnetting math
- IPv6 addressing: 128-bit format, compression rules, global unicast, link-local (fe80::/10), multicast, EUI-64
- OSI and TCP/IP models; TCP vs UDP; well-known ports
- Class of service concepts: why traffic is classified, queued, scheduled and rewritten
- Junos default forwarding classes (best-effort, expedited-forwarding, assured-forwarding, network-control)
- Behavior aggregate (DSCP-based) vs multifield classification
Domain 2: Junos OS fundamentals
- Junos OS as one modular OS across routing, switching and security platforms
- Separation of control plane and forwarding plane
- Routing Engine (RE): runs the CLI, routing protocols, builds the routing and forwarding tables
- Packet Forwarding Engine (PFE): forwards transit traffic using the forwarding table copied from the RE
- Key daemons: rpd (routing), mgd (management/CLI), dcd (interfaces), chassisd (chassis)
- Transit traffic vs exception (host-bound) traffic and why exception traffic is rate-limited to the RE
- Junos OS vs Junos OS Evolved (FreeBSD-based vs Linux-based)
- Protecting the RE with a filter on the lo0 interface
- Boot sequence and storage: primary/backup media, snapshots
Domain 3: User interfaces
- CLI modes: operational (`>`) and configuration (`#`); entering with `configure`, `configure private`, `configure exclusive`
- Navigating the hierarchy: `edit`, `up`, `top`, `exit`, `exit configuration-mode`; the `[edit ...]` banner
- Command completion with Space and Tab; `?` for context help
- Help: `help topic`, `help reference`, `help apropos`
- Output filtering with pipes: `| match`, `| except`, `| find`, `| count`, `| no-more`, `| last`, `| save`
- `| display set`, `| compare`, `| display inheritance`
- Running operational commands from configuration mode with `run`
- Active vs candidate configuration
- J-Web GUI and enabling it with `system services web-management`
- Remote access: SSH, console, out-of-band management interface (fxp0/em0/me0)
Domain 4: Configuration basics
- Factory-default configuration and the root-password requirement before the first commit
- Initial configuration: host name, root authentication, users and login classes, management interface, static default route
- Interface naming (type-fpc/pic/port.unit), physical vs logical properties, unit 0, family inet/inet6
- Special interfaces: lo0, fxp0/em0/me0, irb
- Commit model: `commit check`, `commit confirmed`, `commit and-quit`, `commit comment`, `commit at`
- Rollback: `rollback n` (0–49), `show | compare rollback n`, rescue configuration
- Saving and loading: `save`, `load merge`, `load override`, `load replace`, `load set`, `load factory-default`
- Editing tools: `delete`, `deactivate`/`activate`, `annotate`, `copy`, `rename`, `insert`
- Configuration groups with `groups` and `apply-groups`, including wildcards
- System services: SSH, NTP, syslog, SNMP basics
Domain 5: Operational monitoring and maintenance
- Monitoring the platform: `show chassis hardware`, `show chassis alarms`, `show system alarms`, `show chassis routing-engine`, `show system storage`
- Monitoring interfaces: `show interfaces terse`, `extensive`, `monitor interface`, `monitor traffic interface`
- Network tools: ping, traceroute, SSH, telnet from the CLI
- System logging (`/var/log/messages`, `show log`) and protocol traceoptions
- Managing files: `file list`, `file show`, `request system storage cleanup`
- Software installation and upgrades with `request system software add`; snapshots
- Rebooting, halting and powering off safely: `request system reboot`, `halt`, `power-off`
- Root password recovery from the console using recovery (single-user) mode
- Saving and restoring a rescue configuration
- NTP, SNMP and remote syslog for ongoing operations
Domain 6: Routing fundamentals
- Packet forwarding decisions: longest-prefix match, next hops, active vs inactive routes (`*`)
- Routing tables: inet.0, inet6.0, inet.3, and instance tables such as vr1.inet.0
- Route preference values: direct/local 0, static 5, OSPF internal 10, RIP 100, aggregate/generated 130, OSPF external 150, BGP 170
- Routing instances: virtual-router, forwarding and VRF types
- Static routes: `routing-options static`, next-hop, qualified-next-hop with preference (floating routes), discard and reject
- Default routes and summarization (aggregate routes)
- Dynamic routing concepts: why IGPs and EGPs exist, OSPF and BGP at a high level
- Reading `show route`, `show route detail`, `show route protocol`, `show route table`
Domain 7: Routing policy and firewall filters
- Routing policy uses: import (into the routing table) and export (out of the routing table)
- Default policies: BGP accepts and advertises active BGP routes; OSPF import accepts all and export rejects all; RIP export rejects all
- Policy structure: terms, `from` match conditions, `then` actions; terminating vs flow-control actions (next term, next policy)
- Policy chains and evaluation order, falling through to the default policy
- Route filters and match types: exact, orlonger, longer, upto, prefix-length-range; prefix lists
- Testing with `test policy`
- Firewall filters: stateless, term order, match conditions, implicit discard at the end
- Filter actions: terminating (accept, discard, reject) and non-terminating (count, log, syslog, policer)
- Applying filters to interfaces (input/output) and to lo0 to protect the RE
- Unicast reverse path forwarding (uRPF) checks: strict and loose