๐ŸŒฟ Juniper Routers

Quick reference guide โ€” models, specs & configuration basics

Router Lineup

SRX300 Series

Branch / Small Office
Next-gen firewalls for small branches. Integrated routing, switching, and security in a single device.
1 Gbps FW 8 GbE ports Junos OS UTM

SRX1500

Mid-Range Campus
Medium enterprise firewall with advanced threat protection, IPS, and application visibility.
9 Gbps FW 16 GbE + 4x10G AppSecure HA

SRX4600

Data Center Edge
High-performance security gateway for data center and large enterprise deployments.
80 Gbps FW 8x10G + 4x100G Express Path Redundant PSU

MX204

Universal Routing
Compact fixed-form universal router for peering, aggregation, and edge routing.
8x10G + 4x100G Memory 32GB BGP/MPLS MACsec

MX960

Core / Service Provider
Modular chassis router for service provider core, peering, and broadband edge deployments.
Up to 96x100G Trio 5 NPU Segment Routing EVPN-VXLAN

ACX7100-48L

Cloud Metro / 5G
Cloud-metro router optimized for 5G transport, access, and aggregation with 400G support.
48x25G + 8x400G SyncE/PTP ZTP Junos Evolved

Configuration Basics

1. Initial Access & Root Password

# Console in, login as root (no password on factory default)
cli
configure
set system root-authentication plain-text-password
# Enter password twice
set system host-name juniper-gw01
set system domain-name example.com
commit

2. Management Interface

# Configure out-of-band management
set interfaces fxp0 unit 0 family inet address 192.168.1.1/24
set routing-options static route 0.0.0.0/0 next-hop 192.168.1.254

# Enable SSH
set system services ssh root-login allow
set system services netconf ssh
commit

3. Interfaces & Routing

# WAN interface
set interfaces ge-0/0/0 unit 0 family inet address 203.0.113.2/30

# LAN interface
set interfaces ge-0/0/1 unit 0 family inet address 10.0.0.1/24

# Default route
set routing-options static route 0.0.0.0/0 next-hop 203.0.113.1

# OSPF (optional)
set protocols ospf area 0.0.0.0 interface ge-0/0/1.0
set protocols ospf area 0.0.0.0 interface lo0.0 passive
commit

4. Security Zones (SRX)

# Define zones
set security zones security-zone trust interfaces ge-0/0/1.0 host-inbound-traffic system-services all
set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services ping

# NAT source (outbound)
set security nat source rule-set outbound from zone trust
set security nat source rule-set outbound to zone untrust
set security nat source rule-set outbound rule nat-all match source-address 0.0.0.0/0
set security nat source rule-set outbound rule nat-all then source-nat interface

# Allow trust -> untrust
set security policies from-zone trust to-zone untrust policy allow-all match source-address any destination-address any application any
set security policies from-zone trust to-zone untrust policy allow-all then permit
commit

5. BGP Peering (MX)

# Basic eBGP peering
set routing-options autonomous-system 65001
set protocols bgp group upstream type external
set protocols bgp group upstream peer-as 65000
set protocols bgp group upstream neighbor 203.0.113.1
set protocols bgp group upstream export advertise-routes

# Export policy
set policy-options policy-statement advertise-routes term 1 from protocol direct
set policy-options policy-statement advertise-routes term 1 from route-filter 10.0.0.0/16 orlonger
set policy-options policy-statement advertise-routes term 1 then accept
commit
๐Ÿ’ก Pro tip: Always use commit check before commit to validate config. Use commit confirmed 5 for risky changes โ€” auto-rolls back in 5 minutes unless you confirm with another commit.

Useful Commands

# Show running config
show configuration | display set

# Compare candidate vs active
show | compare

# Rollback to previous config
rollback 1
commit

# Monitor traffic
monitor traffic interface ge-0/0/0

# Check routing table
show route
show route protocol bgp

# Interface status
show interfaces terse
show interfaces ge-0/0/0 extensive

# System health
show chassis alarms
show system uptime
show system processes extensive