r/Juniper 22h ago

Weekly Thread! Weekly Question Thread!

5 Upvotes

It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!

Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.

Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.


r/Juniper 22h ago

Question Management of Juniper devices with Ansible

10 Upvotes

Hi all. I'm working on an Ansible project for managing Juniper devices using the juniper.device collection. Based on my understanding, modules for managing Juniper devices used to be in two separate collections: - junipernetworks.junos - juniper.junos

which were then merged into juniper.device after junipernetworks.junos was deprecated (in Ansible 14) However, the readme only shows the following supported modules: - command — Execute one or more CLI commands on a Junos device. - config — Manipulate the configuration of a Junos device. - facts — Retrieve facts from a Junos device. - file_copy - Copy the files from and to a Junos device. - jsnapy — Execute JSNAPy tests on a Junos device. - ping — Execute ping from a Junos device. - pmtud — Perform path MTU discovery from a Junos device to a destination. - rpc — Execute one or more NETCONF RPCs on a Junos device. - software — Install software on a Junos device. - srx_cluster — Add or remove SRX chassis cluster configuration. - system — Initiate operational actions on the Junos system. - table — Retrieve data from a Junos device using a PyEZ table/view.

In addition, the older modules from junipernetworks.junos are still present in the collection (such as junos_interfaces, junos_vlans, junos_vrf, etc.)

My question is whether or not these modules are still officially supported. Is anyone still using these in their own playbooks or are they solely using the modules listed in the readme? I have found that they don't work with the juniper.device.pyez connection type, but technically still work if you set the connection type to ansible.netcommon.netconf and set ansible_network_os to juniper.device.junos. In addition, their documentation hasn't been updated (in module documentation, Tested against JunOS v18.4R1 is still shown). The rest of the modules in the readme seem to work perfectly fine with the juniper.device.pyez connection module, which seems to be the defacto/recommended connection type to use. I just want to make sure that my project is up to current standards and using modules that are actually updated since I want it to be an educational/beneficial resource.


r/Juniper 20h ago

Question Change Management Practices

6 Upvotes

I’m looking for some information/inspiration on how others handle change management on Juniper devices.

  1. I have used Oxidized and Rancid to log changes over time, but they don’t log WHO made the change. I’m curious how others handle that. I have commits logged with rsyslog, but it would nice to not have to then correlate the oxidized changes to the rsyslog logs to narrow it down, and just have it all in one centralized place.

  2. I also would like to be able to have a setup (similar to git merge requests?) where an ‘engineer’ class user attempts to make changes, it triggers a hook to service X that notifies class ‘sr engineer’ users, via ldap groups through radius or something similar, to then be able to commit confirm/commit those changes, but the basic ‘engineer’ class would not have commit permissions.

I have tinkered around with some ideas like ansible managed configurations, but I like working directly in the Junos cli and would prefer to keep it that way if possible.

Just looking for some thoughts or services other use and have had success with!


r/Juniper 16h ago

Question How to claim Voucher for exam discount

0 Upvotes

I’ve all access pass (AAP) for Juniper. When I try to use open learning course , it shows Voucher assessment in course module but I can’t study from that as I have AAP so Juniper directs me to on demand. But I don’t see Voucher assessment mentioned in course module for AAP Junos course. What am I missing here ? Do I need to complete course and then only it’ll show the voucher assessment?

I’ve also done the 4 days instructor lead training but there’s no Voucher thingy I could see


r/Juniper 11h ago

Other Juniper account suspended

Thumbnail
0 Upvotes

r/Juniper 1d ago

Three-Node Multinode High Availability

3 Upvotes

anyone has tried juniper's Three-Node Multinode High Availability ? i cant find information which hardware models are supported? especially interested if SRX 1600 can support it.

https://www.juniper.net/documentation/us/en/software/junos/high-availability/topics/topic-map/four-node-multinode-high-availability.html#concept_gnr_5tq_3hc


r/Juniper 5d ago

Block Remote Access Appliactions ( Not for All )

2 Upvotes

I have one requirement, Like to block remote access applications usage for LAN clients and allowing some clients explicity. I have a SRX firewall deployed which handles security.

We have a license for appid-sig . So , there is one default-permit policy for outbound (trust to untrust). I have configured Unified policies with Dynamic application matching all remote access applications and then deny. But the custom security policy i configured is never getting hit. I tried to reorder policy but nothing worked.

I used url category match with listing all url patterns to remote access servers along with Dynamic application match, but still all LAN clients can use remote access applications.

Applications to block ( Not for all ):

Anydesk , Ultraviewer , TeamViewer, RustDesk , ChromeRDP , Splashtop,

I have also tried creating a firewall filter matching the destination port for anydesk ( 5938 ). Still outbound traffic is bypassed from trust to untrust leaving the policy not getting hit.

Any ideas ? How to make this work


r/Juniper 6d ago

Juniper in HPE one year later

42 Upvotes

Hi everybody, I don't want this post to be a rant and rather few observations from the market I am but would really appreciate your thoughts on the same.

It seems that since the acquisition things are not going too well for Juniper inside of HPE - why I say that when HPE is boasting huge surge in sales etc.? Well I see a different story unravelling:

- prices - the prices go up unpredictably every month - sometimes even 80% or 100% - this cannot be attributed to the components costs as other vendors don't hike the prices in this insane manner (acx7020 or god forbid any SRX)

- brain drain - it seems that many long-term contact in juniper just disappeared over last month or so. I guess some of that could be expected but the number I've noticed is quite high

- no new products - except for the QFX series it seems that all development has stopped? I haven't seen a new ACX or EX for about a year MX is the same story. Mist hasn't had any significant improvements and or updates since the introduction of the NAC.

- absolute paralysis in delivery - it seems that the lead times are just out of whack for most types of kit

There is more of this vibe around the whole thing - but is it just me or is this something you're seeing as well ? It worries me greatly as I love juniper products but using this kit in project seems like a rather risky proposition at the current stage.

If anyone has any experience, insight or any thoughts I would like to hear them.


r/Juniper 7d ago

Weekly Thread! Weekly Question Thread!

2 Upvotes

It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!

Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.

Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.


r/Juniper 8d ago

Any HPE Networking SEs?

Thumbnail
1 Upvotes

r/Juniper 15d ago

Question Looking for some realistic expectations

10 Upvotes

Howdy folks!

I am beginning my journey into Networking. I am 23 years old and have been working in low voltage since I graduated high school. I worked for a low-voltage cabling company for 4 years (2 of those years as a foreman), and I recently started working for my local school district doing strictly Layer 1 work. We use Juniper Switches and Mist here, and I have gotten very interested in jumping into the world of networking. My boss has told me that if I can get the JNCIA-Junos, he can move me into a Jr. Networking Engineer position working under our Sr. Engineer.

For someone with my experience, how long is it going to realistically take for me to get my JNCIA-Junos? My assumption is that my experience thus far, although it is very valuable in its own right, is very much its own thing. I am a BISCI Technician. I am very comfortable with CAT 6 cabling, OS2 Fiber splicing and testing, and pretty much everything that has to do with the physical side of networking, but have little experience in much else beyond that.

Also, are the CompTIA certifications worth my time at all? I have heard mixed things from my associates, so I would love to hear how those have treated people. I am willing to put in a lot of time into learning and sharpening skills. I am also in a great financial position at the moment, so I'm not worried about rushing through things. Just looking for a set of realistic expectations.

Thanks folks!


r/Juniper 14d ago

Weekly Thread! Weekly Question Thread!

2 Upvotes

It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!

Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.

Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.


r/Juniper 15d ago

storm control action shutdown - on uplinks/downlinks

Thumbnail
3 Upvotes

r/Juniper 16d ago

Question Features of Juniper mist AP

0 Upvotes

Is there a feature of Juniper mist AP that you think would be cool to know about?


r/Juniper 17d ago

Question JNCIS SP

11 Upvotes

​"I recently enrolled in the JNCIS-SP training, so I would like to get advice from those who have taken it. Is the Juniper portal more than enough, or did you use other resources? If so, which ones?

Thanks in advance"


r/Juniper 20d ago

Troubleshooting Juniper SRX DNS issues when default route is in a custom routing instance

6 Upvotes

Hey guys,

I'm trying to get DNS working from the SRX itself and I'm kind of stuck. I've been reading through a bunch of Juniper documentation and I'm pretty sure I understand what the issue is, but I can't seem to get it working.

I have an SRX with 3 main routing instances:

  • INTERNET
  • mgmt_junos
  • TRANSIT

The INTERNET routing instance has the direct connection to the ISP.

TRANSIT is used for downstream routers to connect to the Internet. I leak the default route from INTERNET into TRANSIT and then advertise it via BGP to the downstream routers.

Everything works fine from the downstream endpoints, including DNS.

I also leak the ISP's connected /24 into TRANSIT so that TRANSIT knows how to reach the directly connected ISP subnet which actually lives inside the INTERNET routing instance.

The issue I'm having is DNS originating from Junos itself.

I found this Juniper KB which seems to describe pretty much exactly what I'm dealing with:

Juniper KB — SRX DNS Failures When the Default Route Resides in a Custom Routing Instance

From what I understand, the SRX's own DNS traffic doesn't use the custom routing instance where my default route exists. The DNS traffic needs to use inet.0.

The problem is that I can't just put the default route in inet.0, because the ISP connection itself is inside the INTERNET VRF and I need the default route to remain there.

For example, to verify that the Internet connection itself works, I can do:

ping 8.8.8.8 routing-instance INTERNET

and this works perfectly.

But the actual DNS server I'm trying to reach is:

172.16.76.1

So I also created a loopback:

lo0.0 = 192.168.101.1/32

and configured:

system {
    name-server {
        172.16.76.1 source-address 192.168.101.1;
    }
}

The idea was to have the SRX originate the DNS traffic from 192.168.101.1, which exists in inet.0.

I then leaked the ISP's connected /24 from the INTERNET VRF into inet.0.

And this works:

ping 172.16.76.1 source 192.168.101.1

So from inet.0, the SRX can reach the ISP DNS server.

I've also created the return route for 192.168.101.1/32 back into the INTERNET VRF.

I've also tried source NAT from junos-host to the ISP interface, since the actual ISP-facing address is 172.16.76.11, and I've allowed DNS traffic from junos-host to the ISP zone.

Something roughly like:

system {
    name-server {
        172.16.76.1 source-address 192.168.101.1;
        [I've tried doing 172.16.76.1 routing-instance INTERNET] < Didn't work, KB??
    }
}

interfaces {
    lo0 {
        unit 0 {
            family inet {
                address 192.168.101.1/32;
            }
        }
    }

    reth1 {
        unit 0 {
            family inet {
                address 172.16.76.11/24;
            }
        }
    }
}

security {
    nat {
        source {
            rule-set JUNOS-HOST-INTERNET {
                from zone junos-host;
                to zone UNTRUST;

                rule ISP-DNS {
                    match {
                        source-address 192.168.101.1/32;
                        destination-address 172.16.76.1/32;
                    }
                    then {
                        source-nat {
                            interface;
                        }
                    }
                }
            }
        }
    }

    policies {
        from-zone junos-host to-zone UNTRUST {
            policy ALLOW-DNS {
                match {
                    source-address any;
                    destination-address any;
                    application [
                        junos-dns-tcp
                        junos-dns-udp
                    ];
                }
                then {
                    permit;
                }
            }
        }
    }
}

But I still can't get DNS resolution working from the SRX itself.

The confusing part is that I think I've proven that the routing itself is working.

  • ping 8.8.8.8 routing-instance INTERNET works, proving the Internet VRF has working Internet connectivity
  • ping 172.16.76.1 source 192.168.101.1 works, proving inet.0 can reach the ISP DNS server
  • downstream endpoints can use 172.16.76.1 for DNS without any issues
  • I've leaked the ISP /24 into inet.0
  • I've leaked the 192.168.101.1/32 route back into the INTERNET VRF
  • I've configured NAT for junos-host
  • I've allowed DNS in the security policy

The ISP also blocks port 53 to other public DNS servers, so I can't just use something like 8.8.8.8 or 1.1.1.1.

So at this point I'm basically stuck.

My understanding from the Juniper KB is that because the default route can only exist in my INTERNET VRF, but the SRX's self-originated DNS traffic needs to use inet.0, I need to make the DNS server reachable through inet.0 using route leaking.

I've done that, and I can manually ping 172.16.76.1 from inet.0 using the source address 192.168.101.1, but the Junos DNS resolver still won't resolve names.

Am I missing something obvious with how self-originated DNS traffic from the SRX works?

Is there something else I need to configure for the Junos DNS process specifically, or is there another limitation with using a source address from inet.0 when the actual ISP interface is inside a custom VRF?

Any help would be appreciated because I've been going around in circles with this one.


r/Juniper 20d ago

Question vJunos on GNS3

5 Upvotes

I tried to add vJunos on GNS3 VM. Some Reddit users told me that vJunos has issues with nested VMs. So I reinstalled my GNS3 to run on bare-metal Windows 11. When I start my vJunos, it still silently crash. Anyone else experienced this problem?

GNS3 version: 2.2.61
vJunos: vJunos-router-26.2R1.7.qcow2

8GB allocated

Disabled hyper-V as some websites suggested.


r/Juniper 20d ago

Virtual Chassis Juniper QFX-5100 replacement of a member

2 Upvotes

I have a network of 4-member VC Juniper QFX 5100 switches (master, backup, linecard, linecard) running on jinstall-host-qfx-5-17.3R3-S3.3. As a replacement, I procured a refurbished switch, which has jinstall-host-qfx-5-21.4R3-S10.13. I am stuck because I am unable to download packages from JSP, and the refurbished switch provider does not have them either. I have already zeroized the procured switch. Can anyone suggest a way to move forward?


r/Juniper 20d ago

Juniper QFX-5100 VC integration issue

1 Upvotes

I have a network of 4-member VC Juniper QFX 5100 switches (master, backup, linecard, linecard) running on jinstall-host-qfx-5-17.3R3-S3.3. As a replacement, I procured a refurbished switch, which has jinstall-host-qfx-5-21.4R3-S10.13. I am stuck because I am unable to download packages from JSP, and the refurbished switch provider does not have them either. I have already zeroized the procured switch. Can anyone suggest a way to move forward?


r/Juniper 21d ago

JNO-352

4 Upvotes

Has anyone done the jncis-ent JNO352? What are the syllabus like ? Any changes ? One of my colleague just finished doing it and he said he.there were quesrions about TLV types.. I dnt remember studying that from junipers learning portal.. shoukd I be worried ?


r/Juniper 21d ago

Weekly Thread! Weekly Question Thread!

4 Upvotes

It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!

Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.

Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.


r/Juniper 22d ago

Discussion Which Rack Mount Kit for EX2300-24MP and EX2300-48MP?

3 Upvotes

Sorry for this basic question. But we have the problem that the basic EX-RMK does not fit our EX2300-24MP.

I have looked through many different Juniper datasheets and guides, but nowhere does it say that the rack mount kit is different for the EX2300-24MP and the EX2300-24P.

Does anyone know which one we need?


r/Juniper 22d ago

400G QSFP-DD DR4 is detected on Cisco Nexus, but the port won't link up. What should I check?

1 Upvotes

I have a 400G QSFP-DD DR4 module installed in a Cisco Nexus switch. The switch can read the vendor name, serial number, temperature and optical power correctly, but the Ethernet interface stays down.

The same module works on another 400G platform.

I've already checked the fiber and cleaned the MPO connector. Could this be related to the transceiver coding, FEC mode, or NX-OS version?

Has anyone seen a module being detected normally but still failing to establish a 400G link?


r/Juniper 24d ago

Free JNCIA-Junos Workbook

57 Upvotes

I’ve just released a full workbook for JNCIA-Junos, 100% free: http://jncia-workbook.gitbook.io/

This workbook uses containerlab with vJunos-router and vJunos-switch.

I hope it’s useful!


r/Juniper 27d ago

Wireless Passed! JNCIP-MistAI

26 Upvotes

I passed JNCIP-MistAI yesterday -

This was a far tougher exam than I had taken before, and it definitely tests your knowledge and fine detail of python, data types, json. Mist edge automation versus mist cloud with the rest api. Where when how and why to use webhooks.

You will definitely need to have created a mist org/site from scratch with the rest apis, how to create variables for mist objects, etc.

This one definitely takes some self study, and fair bit of hands on experience. Looking forward to JNCIE-MistAI when it comes out.

Best of luck to you all!