Quick reference guide โ models, specs & configuration basics
# Console in, login as root (no password on factory default)
cli
configure
set system root-authentication plain-text-password
# Enter password twice
set system host-name juniper-gw01
set system domain-name example.com
commit
# Configure out-of-band management
set interfaces fxp0 unit 0 family inet address 192.168.1.1/24
set routing-options static route 0.0.0.0/0 next-hop 192.168.1.254
# Enable SSH
set system services ssh root-login allow
set system services netconf ssh
commit
# WAN interface
set interfaces ge-0/0/0 unit 0 family inet address 203.0.113.2/30
# LAN interface
set interfaces ge-0/0/1 unit 0 family inet address 10.0.0.1/24
# Default route
set routing-options static route 0.0.0.0/0 next-hop 203.0.113.1
# OSPF (optional)
set protocols ospf area 0.0.0.0 interface ge-0/0/1.0
set protocols ospf area 0.0.0.0 interface lo0.0 passive
commit
# Define zones
set security zones security-zone trust interfaces ge-0/0/1.0 host-inbound-traffic system-services all
set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services ping
# NAT source (outbound)
set security nat source rule-set outbound from zone trust
set security nat source rule-set outbound to zone untrust
set security nat source rule-set outbound rule nat-all match source-address 0.0.0.0/0
set security nat source rule-set outbound rule nat-all then source-nat interface
# Allow trust -> untrust
set security policies from-zone trust to-zone untrust policy allow-all match source-address any destination-address any application any
set security policies from-zone trust to-zone untrust policy allow-all then permit
commit
# Basic eBGP peering
set routing-options autonomous-system 65001
set protocols bgp group upstream type external
set protocols bgp group upstream peer-as 65000
set protocols bgp group upstream neighbor 203.0.113.1
set protocols bgp group upstream export advertise-routes
# Export policy
set policy-options policy-statement advertise-routes term 1 from protocol direct
set policy-options policy-statement advertise-routes term 1 from route-filter 10.0.0.0/16 orlonger
set policy-options policy-statement advertise-routes term 1 then accept
commit
commit check before commit to validate config. Use commit confirmed 5 for risky changes โ auto-rolls back in 5 minutes unless you confirm with another commit.
# Show running config
show configuration | display set
# Compare candidate vs active
show | compare
# Rollback to previous config
rollback 1
commit
# Monitor traffic
monitor traffic interface ge-0/0/0
# Check routing table
show route
show route protocol bgp
# Interface status
show interfaces terse
show interfaces ge-0/0/0 extensive
# System health
show chassis alarms
show system uptime
show system processes extensive