JUNOS Cheat-Sheet

Quick Reference

Create Rollback (apply/restore)
request syst em configur ation rescue save [edit] rollback re scue

Login as root, run ezsetup OR Connect to ge-0/0/0, use DHCP and access (web or telnet/SSH) OR Choose Enter Ezsetup from LCD screen OR Connect to me0 and access (EX-series)
Set Root password


set system root-authentication plain-text-password

Enable SSH Disable Telnet Set Hostname

set system services ssh delete system services telnet set system host-name <name>

Juniper EX-series Cheat Sheet

Quick Reference
rted tances are suppo p and hierarchy (stp, rst Up to 64 MSTP ins t protocols] gure under [edi Confi mstp) over/ Gs) to have a fail Trunk Groups (RT Use Redundant use of STP out the ns] tch secondary link with hing-optio supported per swi rnet-switc Up to 16 RTGs are [edit ethe p { trunk-grou redundant0 { ge ; group rtg1 -tree brid ge-0/0/3.0 ng interface rface show spanni ; ace -tree inte ge-0/0/4.0 interface tics interf ow spanning is sh n -tree stat nfiguratio ow spanning sh } tp co ng-tree ms show spanni }

rie s
All ports are family ethernet-switching PoE is enabled on all PoE-capable ports LLDP and RSTP enabled Virtual chassis system ID is 0 (zero) mastership-priority of 128 load factory-default

Reset back to default



with a 200 comes Each EX 4 CB -meter V Up to 1 0( can be s ten) EX 4200 tacked into a V s CS

lane e backp form th s is Ports rconnect hass es inte Virtual C ne cabl Backpla Ps CS V VC hassis s into a r to Virtual C switche ses fibe orts u VCB tender P switches x hassis E ote le ect rem Virtual C k modu interconn n 10Gbps uplin o d d to s upporte use VCEP Only s rotocol ssages ontrol P assis C very me irtual Ch A-based disco CS V S V in a ge L exchan n PFEs sed to betwee ace u VCCP et interf t Ethern en tack anagem switch s Virtual M administer the ngine arding E PFEs Forw V ME 2 Packet 0s have EX 420 have 3 PFEs 24-port 00s EX 42 et 48-port PF E port s ure a V Config ME
reques vcassis ual-ch port <#> t virt ot <#> pic-sl

Up to 8 interfac es in a single LAG Max # LAGs: EX 3200 = 32 LAGs per sw itch EX 4200 = 64 LAGs per sw itch VCS = 128 LA Gs per VCS Trunks do no t have to have a native VLAN

If me0 isnt configured as a L3 interface, it is automatically assigned to the mgmt VLAN

show show show show show show

chassis hardware virtual-chassis status virtual-chassis active-topology virtual-chassis interfaces virtual-chassis member-config virtual-chassis protocol

default orts by at all p rts er th Rememb re access po a

uting. LAN ro inter-V . rovides n SVI on IOS P Like a

1. Set the port mode to trunk set interfaces <name> unit <#> family ethernet-switching portmode trunk

have to unit doesnt The VLAN LAN ID match the V ommend it s rec best-practice

] faces inter [edit { vlan 200 { net { 4 unit 1.1/2 y i famil ress 10.1. add } } } ] vlans [edit t { 0; tes .200; id 20 vlan- rface vlan te l3-in }

2. Set the VLAN membership on the trunk set interfaces <name> unit <#> family ethernet-switching vlan members <name(s)>
3. Set the native VLAN (optional) set interfaces <name> unit <#> family ethernet-switching native-vlan-id <name>

Juniper EX-series Cheat Sheet

Quick Reference

Ingress / Received Packet Port Firewall Filter (PACL) VLAN Firewall Filter (VACL)

Router Firewall Filter (RACL)

VLAN Firewall Filter (VACL)

Egress / Transmit Packet

Mitigate rogue D servers HCP !

show dhcp snooping binding clear dhcp snooping binding

Ex to a m i n vie e s w th e h o w Us M A et ec in h C te lea ta b e r n rf r le. etac et Lo sw he e it <n rn Li m ok at ch am et itin sh in e> -s g g v ow to w i t ta i ol cle ch a ti l o g bl ar on in e vio g me m e s l at ta s s sag ion bl ag es s. e es . fo r MA C

s in the DHCP mining entrie ooping Relies on exa es DHCP Sn table, so requir Snooping s by default led on all VLAN Disab N basis on a per-VLA d It is enabled red as a truste that is configu as a Any interface g is also setup DHCP Snoopin inspection) interface for passes ARP d interface (by DAI truste mmands:

Example: Configuration t-switching-options] it etherne

[ed ss-port { { secure-acce ge-0/0/0.0 interface ; dhcp-trusted } { vlan test ion; arp-inspect mine-dhcp; exa } }

Monitoring Co

ndings snnoping bi stics show dhcp tion stati arp inspec show

DHCP traceoptions are logged to /var/log/fud by default

ion Exam [edit ple: forwar ding-o descri ptions ption he Main server DHCP re lpers bootp] 10.0.4 lay; 0.2; maximu m-hopcount minimu 4; m-wait -time interf 1; ace { vlan.2 { no-lis ten; }

Configur at

Configuration Example:
[edit protocols dot1x authenticator] interface { ge-0/0/0.0 { guest-vlan test-guest-vlan; reauthentication 3600; supplicant single-secure; } ge-0/0/3.0 { no-reauthentication; } } Static { 00:00:00:00:00:01 { interface ge-0/0/0.0; } 00:00:00:00:00:02; }

Monitoring Commands:
show dot1x interface Show dot1x static-mac-address show dot1x authentication-failed-users

Juniper EX-series Cheat Sheet

Quick Reference

default to class 0 by are assigned All switch ports er pool from total pow Modes: rt is deducted x power for po Static ma matches class 0) tal power pool (only supports dgeted from to ic power bu Dynam m the total consumed is deducted fro actual power r class budget we Class max po age for each power pool rical power us s provide histo rie PoE Telemet e (PD) powered devic fault Disabled by de 5 minutes (1 to 30 mins) al is Default interv to 24 hrs) n is 1 hour (1 Default duratio

Fully in te 4200 s rchangeable eries s witche between EX 320W, s 3200 a 600W nd and 93 0W ca pacitie s are a vailable



Configu re CoS b Use vo ice VLA efore enabling N vo Use LL DP-ME on ports with IP ice VLAN D to sig to IP ph phone nal voic one e VLAN s ID and Configu 802.1p ration E value [edit xample ether :

Useful C

Design and Implementation

Juniper EX-series Cheat Sheet

Quick Reference

24 to 48-ports Basic model has 8 PoE ports Up to 48 PoE ports are supported Does not support VCS Intended for access layer usage Supports redundant power supplies (one internal, one via RPS port) Field-replaceable PS and fan tray Uplink modules: 4 x 1Gbps Ethernet (SFP) 2 x 10Gbps Ethernet (XFP) Line-rate switching (non-blocking)

24 to 48-ports Basic model has 8 PoE ports Up to 48 PoE ports are supported Supports VCS (up to 10 switches in a VCS) Intended for distribution and access layer usage Redundant (both internal), hot-swappable PS Field-replaceable fan tray (3 fans one can fail & not affect operations) Uplink modules: 4 x 1Gbps Ethernet (SFP) 2 x 10Gbps Ethernet (XFP) Line-rate switching (non-blocking)

Routing Engine (RE) Bridging Table (BT) Routing Table (RT) JUNOS Software Fwding Table (FT)

Control Plane Forwarding Plane

Packet Forwarding Engine (PFE)

Packet Flow

Bridging Table (BT)

Fwding Table (FT)

Packet Flow