Jump to chapter (9)
The big picture: collision and broadcast domains
What you will learn in this module. You will learn how a Junos network is addressed and how a router decides where to send a packet: Ethernet, MAC addresses and ARP, IPv4 and binary, subnetting with VLSM, supernetting, IPv6, longest-prefix match, TCP versus UDP and the basics of class of service. Two labs follow: you address a small office (the Nashik office) and you fix a routing mistake caused by a stale route.
Prerequisites. The module "Networking and Junos from zero" (packets, switch versus router, the candidate configuration and commit). You should be able to enter configure, type set commands and commit.
An analogy: apartments and shouting
Imagine a building. If everyone lives in one giant hall and talks at once, nobody can be heard: that is a collision domain on an old hub. If each family has its own flat with a private door, nobody interrupts anybody: that is one collision domain per switch port. Now think of a loudspeaker announcement: "Who owns the red car?" Everyone on the same floor hears it, but not people in other buildings. That announcement is a broadcast, and the floor is the broadcast domain.
The two definitions
A collision domain is the set of devices whose frames can collide because they share one half-duplex medium. A broadcast domain is the set of devices that receive each other's broadcast frames, for example ARP requests. Exam questions ask you to count them.
| Device | Layer | Collision domains | Broadcast domains |
|---|---|---|---|
| Hub | 1 | one for all ports | one for all ports |
| Switch (EX) | 2 | one per port | one per VLAN |
| Router (MX, SRX, vMX) | 3 | one per port | one per interface |
Two VLANs mean two broadcast domains. Only the router (or IRB) connects them, and it does not forward broadcasts.
What each device does on Junos
- A switch forwards frames by destination MAC address using its MAC table (
show ethernet-switching tableon EX). Unknown unicast and broadcast frames are flooded inside the VLAN. - A router forwards packets by destination IP address using its routing table (
show route). Every router interface is its own subnet and broadcast domain. - An EX switch with an IRB interface (for example
irb.10) is both: it switches inside VLAN 10 and routes between VLANs.
Worked example. An EX switch has 24 access ports: 12 in VLAN SALES and 12 in VLAN ENG, with no IRB. Collision domains: 24 (one per full-duplex port). Broadcast domains: 2. Connect the switch to a router with one link per VLAN: still 2 VLAN broadcast domains on the switch, and the router keeps them apart.
Common mistake. Answering "24 broadcast domains" for a switch with 24 ports. Ports make collision domains; VLANs make broadcast domains. Also remember that on a full-duplex switched link there are no collisions at all. Collisions or late collisions on a modern link usually point to a duplex mismatch.
The slow flat network
A small factory had 300 devices in one VLAN. Users complained that Wi-Fi scanners and printers were slow every morning. A capture showed thousands of ARP and other broadcasts per second reaching every device. The engineer split the network into four VLANs of about 75 devices, each with its own IRB gateway. Broadcast noise fell by about three quarters and the morning slowness disappeared.
Lesson: smaller broadcast domains mean less noise; routers or IRBs connect them.
"How many collision and broadcast domains does a 24-port switch with two VLANs have?"
Answer: 24 collision domains (one per port) and 2 broadcast domains (one per VLAN). Add that a router separates broadcast domains, a hub has one of each, and that collisions on a switched link suggest a duplex mismatch.
Key takeaways
- Collision domain = shared half-duplex medium; a switch gives one per port.
- Broadcast domain = devices that hear each other's broadcasts; one per VLAN, one per router interface.
- Switches use MAC addresses (layer 2); routers use IP addresses (layer 3).
- An IRB interface lets an EX switch route between VLANs.
- Collisions on a modern link usually mean a duplex mismatch.
Ethernet, MAC addresses and ARP
Every packet in your lab travels inside an Ethernet frame for each hop. To troubleshoot, you must know what is in that frame and how a device finds the MAC address of its next hop. This chapter covers the frame, the MAC address, the MAC table and ARP.
The Ethernet frame
Think of a courier envelope: it has a receiver, a sender, a label for what is inside, the contents, and a seal that shows if it was damaged. An Ethernet frame has the same parts.
The FCS lets the receiver detect corrupted frames; counters named CRC errors point to bad cables or optics.
MAC addresses
A MAC address is 48 bits written in hex, for example 2c:6b:f5:3a:10:c1. The first 24 bits are the vendor's OUI, the last 24 identify the card. ff:ff:ff:ff:ff:ff is the broadcast address. A MAC address has local meaning only: it is used on one link, between a device and its neighbour.
The MAC table of a switch
A switch learns by watching the source MAC of each frame and remembering the port. To forward, it looks up the destination MAC. If the entry is unknown, or the frame is a broadcast, it floods the frame to all other ports of the VLAN. On an EX switch:
lab@SW1> show ethernet-switching table Ethernet-switching table: 2 unicast entries VLAN MAC address Type Age Interfaces SALES 00:50:79:66:68:01 Learn 0 ge-0/0/1.0 ENG 00:50:79:66:68:02 Learn 0 ge-0/0/2.0
ARP: asking "who has this IP?"
A router knows the next-hop IP address but needs its MAC to build the frame. ARP (Address Resolution Protocol) solves that. The sender broadcasts "who has 10.50.0.194?", the owner replies with its MAC address, and both sides cache the answer.
lab@R1> show arp no-resolve MAC Address Address Interface Flags 2c:6b:f5:3a:10:c1 10.50.0.193 ge-0/0/0.0 none Total entries: 1
no-resolve stops Junos from converting addresses to names, which makes output faster and clearer. IPv6 does not use ARP: it uses Neighbor Discovery carried in ICMPv6.
Worked example. PC1 (10.50.0.20) pings 198.51.100.1, which is outside its /25. PC1 does not ARP for the far host. It ARPs for its gateway 10.50.0.1, gets the MAC of SW1's irb.10, and sends the frame to that MAC while the IP destination remains 198.51.100.1. SW1 then ARPs for its next hop 10.50.0.194 on the uplink. Each ARP is local to one segment.
Common mistake. Expecting to see the MAC address of a faraway server in the ARP table. ARP only holds directly connected neighbours. An incomplete or missing ARP entry for the next hop means a layer 1 or layer 2 problem (wrong VLAN, link down), not a routing problem.
Exam trap. The destination MAC of the frame leaving a PC for a remote host is the gateway's MAC, not the server's. And the broadcast MAC is ff:ff:ff:ff:ff:ff; the IPv4 limited broadcast is 255.255.255.255.
The router that could not ARP
After a switch change, R1 could not ping its neighbour 10.50.0.193 even though both interfaces were up. show arp had no entry for the neighbour. The engineer checked the switch port and found it was in the wrong VLAN, so the ARP broadcast never reached the neighbour. Moving the port to the right VLAN made ARP resolve and pings succeed. Routing was never the problem.
Lesson: no ARP entry for a connected next hop points to layer 1 or layer 2.
"A host pings a server in another subnet. What MAC and IP addresses are in the frame on the first hop?"
Source: the host's MAC and IP. Destination MAC: the default gateway's MAC, found through ARP. Destination IP: the server's address. Explain that the router rewrites the MAC addresses at each hop while the IP addresses stay the same.
Key takeaways
- An Ethernet frame holds destination MAC, source MAC, EtherType, payload and FCS.
- Switches learn source MACs and forward by destination MAC; unknown and broadcast are flooded in the VLAN.
- ARP maps a next-hop IPv4 address to a MAC on the local segment; IPv6 uses Neighbor Discovery.
- Use show ethernet-switching table and show arp no-resolve to verify.
- A missing ARP entry for a connected neighbour points to layer 1 or layer 2.
IPv4 addresses and binary made easy
Subnetting looks like magic until you see the bits. This chapter teaches IPv4 addressing and binary in small steps, using only the 8-column table you can draw in five seconds.
An IPv4 address is 32 bits
The address 192.0.2.10 is four numbers, called octets, each made of 8 bits (0 or 1). Each bit position has a place value, doubling from right to left:
| 128 | 64 | 32 | 16 | 8 | 4 | 2 | 1 | Decimal |
|---|---|---|---|---|---|---|---|---|
| 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 192 |
| 0 | 0 | 0 | 0 | 1 | 0 | 1 | 0 | 10 |
| 1 | 1 | 1 | 1 | 1 | 1 | 0 | 0 | 252 |
| 1 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 128 |
To convert, add the place values where the bit is 1: 192 = 128 + 64; 10 = 8 + 2; 252 = 128 + 64 + 32 + 16 + 8 + 4. To go the other way, subtract: 172 minus 128 = 44, minus 32 = 12, minus 8 = 4, minus 4 = 0, so 172 = 10101100.
Prefix length and mask
The prefix length (for example /26) says how many leading bits form the network part. The rest are host bits. The same idea is written as a subnet mask: the network bits set to 1.
A /26 keeps 26 bits for the network and leaves 6 bits for hosts.
| Prefix | Mask | Block size | Usable hosts |
|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /30 | 255.255.255.252 | 4 | 2 |
| /32 | 255.255.255.255 | 1 | one host (loopback) |
Usable hosts = 2host bits minus 2: the all-zeros host is the network address and the all-ones host is the broadcast address. (Point-to-point /31 links, RFC 3021, use both addresses; Junos supports them.)
Special and private ranges
- Private (RFC 1918): 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16.
- Loopback 127.0.0.0/8; link-local 169.254.0.0/16 (self-assigned when DHCP fails).
- Documentation: 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24.
- Multicast 224.0.0.0/4; OSPF uses 224.0.0.5 and 224.0.0.6.
- Default route 0.0.0.0/0 matches everything.
Putting addresses on Junos
An address always sits on a logical unit under family inet, written with a prefix length:
set interfaces ge-0/0/0 unit 0 family inet address 10.50.0.194/30 set interfaces lo0 unit 0 family inet address 198.51.100.1/32 set interfaces irb unit 10 family inet address 10.50.0.1/25
lab@R1> show interfaces terse ge-0/0/0
Interface Admin Link Proto Local Remote
ge-0/0/0 up up
ge-0/0/0.0 up up inet 10.50.0.194/30
Worked example. Is 10.50.0.140 inside 10.50.0.128/26? A /26 has block size 64, so subnets start at .0, .64, .128, .192. The address 140 falls between 128 and 191, so yes. Its network address is .128 and its broadcast is .191.
Common mistake. Assigning the network or broadcast address to a host, for example 10.50.0.128/26 as a PC address. Another: using a /24 mask on one side and /25 on the other of the same link, so the two sides disagree about what is local.
The off-by-one address
A technician typed 10.50.0.191/26 on a server. The server could ping some hosts but not others, and the switch logged strange ARP behaviour. The engineer converted the address: .191 is the broadcast of 10.50.0.128/26. Changing the server to .150 fixed it.
Lesson: always find the network and broadcast addresses of a subnet before assigning hosts.
"How many usable hosts are in a /27 and why?"
A /27 leaves 5 host bits: 2^5 = 32 addresses, minus the network and broadcast addresses, gives 30 usable hosts. Mention block size 32 and that the mask is 255.255.255.224.
Key takeaways
- IPv4 = 32 bits in four octets; place values 128, 64, 32, 16, 8, 4, 2, 1.
- Prefix length = number of network bits; the rest are host bits.
- Usable hosts = 2^host bits minus 2; block size = 256 minus the mask octet.
- Memorise RFC 1918, loopback, link-local and documentation ranges.
- On Junos, addresses go on a unit under family inet with a prefix length.
Subnetting and VLSM: planning the Nashik office
Subnetting means cutting one address block into smaller networks. VLSM (variable-length subnet masks) means the pieces can be different sizes, so you do not waste addresses. In the first lab you receive one block, 10.50.0.0/24, and plan the new Nashik office. This chapter shows the method.
Why not one big network?
Think of a land plot that you divide among a school, a shop and a gatehouse. You do not give each the same size: the school needs more, the gatehouse almost nothing. A router link between two devices needs only two addresses, but a Sales VLAN may need a hundred. VLSM lets you give each network just enough.
The four-step method
- List the requirements and add a small growth margin.
- Find the host bits: the smallest n where 2n minus 2 is at least the hosts needed.
- Allocate the largest subnet first, starting at the beginning of the block, then the next largest, and so on. Each subnet must start on a multiple of its block size.
- Write down network, usable range and broadcast for each.
Worked plan for the Nashik office
Requirements: Sales (VLAN SALES) needs 100 hosts, Engineering (VLAN ENG) needs 50 hosts, and the uplink between the EX switch SW1 and the edge router R1 needs 2 addresses.
| Need | Host bits | Prefix | Network | Usable range | Broadcast |
|---|---|---|---|---|---|
| Sales: 100 hosts | 7 (126) | /25 | 10.50.0.0 | .1 to .126 | 10.50.0.127 |
| Engineering: 50 hosts | 6 (62) | /26 | 10.50.0.128 | .129 to .190 | 10.50.0.191 |
| Uplink: 2 hosts | 2 (2) | /30 | 10.50.0.192 | .193 to .194 | 10.50.0.195 |
The whole /24 as a bar: /25 + /26 + /30, with room left for growth.
The block-size shortcut
Block size = 256 minus the mask octet. For /26 the mask octet is 192, so the block size is 64 and subnets start at .0, .64, .128 and .192. The broadcast is the next subnet start minus 1. The first usable is network plus 1 and the last usable is broadcast minus 1. Both the gateway and the hosts must come from the usable range. By convention the gateway takes the first usable address: 10.50.0.1/25 for Sales and 10.50.0.129/26 for Engineering.
Configuration on the EX switch
In the lab the VLANs already exist: SALES (id 10) and ENG (id 20), with access ports. You create one IRB (routed VLAN interface) unit per VLAN and bind each VLAN to its unit:
set interfaces irb unit 10 family inet address 10.50.0.1/25 set interfaces irb unit 20 family inet address 10.50.0.129/26 set vlans SALES l3-interface irb.10 set vlans ENG l3-interface irb.20 commit
lab@SW1> show interfaces terse irb Interface Admin Link Proto Local Remote irb up up irb.10 up up inet 10.50.0.1/25 irb.20 up up inet 10.50.0.129/26
The PCs were already addressed from the plan: PC1 is 10.50.0.20/25 with gateway 10.50.0.1 and PC2 is 10.50.0.140/26 with gateway 10.50.0.129. After the commit, both PCs can ping their gateway.
Another example. You need 25 hosts. 2^5 = 32 minus 2 = 30 is enough, so /27 (block size 32). If your block starts at 192.0.2.0, the subnets are .0, .32, .64 and so on; the first subnet runs .1 to .30 with broadcast .31.
Common mistakes. Counting the network and broadcast addresses as usable. Allocating the small subnets first and then finding that the big one cannot start on a valid boundary. Forgetting growth: a /26 for exactly 62 hosts leaves no spare address.
Exam trap. "How many usable hosts?" always subtracts 2 on ordinary subnets. And "which subnet does 10.50.0.140 belong to?" needs the block size, not guessing.
The plan that ran out
A branch received 192.0.2.0/24 and was split into four equal /26 subnets because it was easy. Later the guest Wi-Fi needed 100 hosts, but no /26 was big enough and the router links were wasting 62 addresses each. A redesign with VLSM used one /25, one /26 and /30 links, and freed room for two more networks.
Lesson: size each subnet to its need, largest first.
"You are given 10.50.0.0/24. Split it for 100, 50 and 2 hosts."
Sales /25 (10.50.0.0, 126 usable), Engineering /26 (10.50.0.128, 62 usable), link /30 (10.50.0.192). Explain host-bit maths, largest first, boundaries on block-size multiples, and the leftover space 10.50.0.196 onward for growth.
Key takeaways
- VLSM gives each network just the size it needs; allocate the largest subnet first.
- Hosts needed N: find smallest n with 2^n minus 2 at least N.
- Block size = 256 minus mask octet; broadcast = next network minus 1.
- Nashik plan: 10.50.0.0/25, 10.50.0.128/26 and 10.50.0.192/30.
- On EX, give each VLAN an irb unit and bind it with l3-interface.
Supernetting and a full walkthrough of the office build
Subnetting cuts a block into smaller pieces. Supernetting (also called summarisation or aggregation) does the opposite: it joins contiguous networks into one shorter prefix. Fewer routes mean smaller routing tables and faster convergence. In this chapter you learn the rule, then follow the complete first lab step by step: gateways, uplink, default route and summary route.
How to summarise
Write the networks in binary and count the leading bits that are identical in all of them. That count is the summary prefix length. Example: the three Nashik networks are 10.50.0.0/25, 10.50.0.128/26 and 10.50.0.192/30. The first three octets are identical, and in the last octet the highest bit changes (0 and 1 appear), so only the first 24 bits are shared. The summary is 10.50.0.0/24.
A second example for practice: 172.16.4.0/24, 172.16.5.0/24, 172.16.6.0/24 and 172.16.7.0/24. The third octets are 4 to 7: 00000100, 00000101, 00000110 and 00000111. The first six bits (000001) are shared, so the prefix is 16 + 6 = 22 and the summary is 172.16.4.0/22.
Common mistake. Summarising networks that are not contiguous. 172.16.4.0/24 and 172.16.6.0/24 summarise to 172.16.4.0/23 only if .5 is also yours; otherwise the summary would advertise addresses you do not own and attract traffic into a black hole.
The lab topology
R1 and SW1 share the /30 uplink. SW1 holds the two VLAN gateways.
Step 1: the gateways
lab@SW1> configure lab@SW1# set interfaces irb unit 10 family inet address 10.50.0.1/25 lab@SW1# set interfaces irb unit 20 family inet address 10.50.0.129/26 lab@SW1# set vlans SALES l3-interface irb.10 lab@SW1# set vlans ENG l3-interface irb.20
Step 2: the routed uplink
R1 already has 10.50.0.194/30 on ge-0/0/0. SW1 takes the other usable address, .193. A routed port on EX uses family inet instead of ethernet-switching:
lab@SW1# set interfaces ge-0/0/0 unit 0 family inet address 10.50.0.193/30 lab@SW1# commit lab@SW1# run ping 10.50.0.194 count 3 PING 10.50.0.194 (10.50.0.194): 56 data bytes 64 bytes from 10.50.0.194: icmp_seq=0 ttl=64 time=0.9 ms --- 10.50.0.194 ping statistics --- 3 packets transmitted, 3 packets received, 0% packet loss
Step 3: routing in both directions
SW1 does not know the outside world, so it needs a default route to R1. R1 does not know the office subnets, so it needs a route back. One summary route covers all three:
! on SW1 set routing-options static route 0.0.0.0/0 next-hop 10.50.0.194 ! on R1 set routing-options static route 10.50.0.0/24 next-hop 10.50.0.193
lab@R1> show route 10.50.0.0/24
inet.0: 6 destinations, 6 routes (6 active, 0 holddown, 0 hidden)
10.50.0.0/24 *[Static/5] 00:00:31
> to 10.50.0.193 via ge-0/0/0.0
Step 4: verify end to end
From PC1 and PC2: ping 198.51.100.1 must succeed. If a ping fails, the question "which direction is broken?" decides what to check: the outbound path needs the default route on SW1, the return path needs the summary on R1.
Longest match in practice. R1 now has 10.50.0.0/24 (Static) and 10.50.0.192/30 (Direct). To reach 10.50.0.193 it uses 10.50.0.192/30, the longer and more specific prefix. To reach PC1 at 10.50.0.20 only the /24 matches. We study this rule fully in the next chapter.
One route instead of forty
A company with 40 small branch /24 networks 10.60.0.0 to 10.60.39.0 allocated sequentially advertised each one to headquarters. Routing tables were large and changes reached every router. The team reallocated the space in aligned blocks and summarised each region: 10.60.0.0/21, 10.60.8.0/21 and so on. Headquarters needed only a handful of routes and a flapping branch no longer disturbed everybody.
Lesson: plan addresses in aligned, contiguous blocks so that they summarise.
"Why summarise routes, and what is the risk?"
Summaries shrink routing tables, reduce update load and hide flaps. The risk is summarising addresses you do not fully own, which can black-hole traffic; the more specific routes inside, where they exist, still win by longest match.
Key takeaways
- Supernetting joins contiguous networks into a shorter prefix; count the shared leading bits.
- 10.50.0.0/25 + /26 + /30 summarise to 10.50.0.0/24; 172.16.4-7.0/24 summarise to 172.16.4.0/22.
- A routed uplink on EX uses family inet; irb units plus l3-interface build VLAN gateways.
- Traffic needs a route in both directions: default on SW1, summary on R1.
- Verify with ping from the PCs and show route.
IPv6 addressing on Junos
IPv4 has about 4.3 billion addresses and they ran out. IPv6 has 128-bit addresses, about 3.4 x 1038 of them. You will use IPv6 more and more, and the JNCIA-Junos exam expects you to read, shorten and configure IPv6 addresses. Think of IPv4 as a telephone number with 10 digits and IPv6 as a number so long that every grain of sand could have its own line.
Format and shortening rules
An IPv6 address is eight groups of 16 bits, each written as up to four hex digits, separated by colons: 2001:0db8:0000:0000:0000:0000:0000:0050. Two rules make it short:
- Leading zeros in a group may be dropped:
0db8becomesdb8,0000becomes0. - One run of consecutive all-zero groups may be replaced by
::. This can be done only once in an address, otherwise it would be ambiguous.
So the address above becomes 2001:db8::50. Another: 2001:0db8:0000:0000:0a00:0000:0000:0001 can be 2001:db8::a00:0:0:1 or 2001:db8:0:0:a00::1; both are valid, but 2001:db8::a00::1 is not.
Prefixes and the /64 rule
Prefix notation is the same as IPv4: 2001:db8:50:10::/64 means the first 64 bits are the network. On LAN segments the standard is /64: the last 64 bits are the interface identifier. Point-to-point links often use /127 (or /64). A common site allocation is a /48, which holds 65,536 /64 subnets.
A typical layout: site prefix, subnet number, interface identifier.
Address types
| Type | Prefix | Use |
|---|---|---|
| Global unicast | 2000::/3 | Routable on the internet (2001:db8::/32 is documentation) |
| Unique local | fc00::/7 (fd00::/8 used) | Private, like RFC 1918 |
| Link-local | fe80::/10 | On every IPv6 interface, valid on one link only, used by neighbour discovery and routing protocol next hops |
| Multicast | ff00::/8 | One to many; replaces broadcast. ff02::1 all nodes, ff02::2 all routers |
| Loopback | ::1/128 | The device itself |
| Unspecified | ::/128 | "No address yet"; default route is ::/0 |
There is no broadcast in IPv6. Multicast, in particular the solicited-node address, does the job that ARP broadcasts did. Neighbour Discovery uses ICMPv6 messages Neighbor Solicitation and Neighbor Advertisement. Hosts can build their own address with SLAAC (stateless autoconfiguration) from router advertisements, or use DHCPv6.
Configuring IPv6 on Junos
IPv6 uses family inet6. A dual-stack interface carries both families on the same unit:
set interfaces ge-0/0/1 unit 0 family inet address 10.50.0.1/25 set interfaces ge-0/0/1 unit 0 family inet6 address 2001:db8:50:10::1/64 set interfaces lo0 unit 0 family inet6 address 2001:db8:ffff::1/128
lab@R1> show interfaces terse ge-0/0/1
Interface Admin Link Proto Local Remote
ge-0/0/1 up up
ge-0/0/1.0 up up inet 10.50.0.1/25
inet6 2001:db8:50:10::1/64
fe80::2e6b:f5ff:fe3a:10c1/64
The link-local address fe80::... appears automatically once family inet6 is enabled. IPv6 routes live in the table inet6.0: show route table inet6.0. Test with ping 2001:db8:50:10::10.
Worked example. Shorten 2001:0db8:0001:0000:0000:0000:0000:00ff. Drop leading zeros: 2001:db8:1:0:0:0:0:ff. Replace the single run of four zero groups with ::, giving 2001:db8:1::ff.
Common mistakes. Using :: twice. Forgetting that you cannot drop trailing zeros (a00 is not a). Using a /126 or /112 on a LAN that needs SLAAC, which requires /64.
Exam trap. fe80::/10 is link-local, fc00::/7 is unique local, 2000::/3 is global unicast, ff00::/8 is multicast. IPv6 has no broadcast and uses no ARP.
Dual-stack and the missing family
A branch added IPv6 and users reached websites over IPv4 but IPv6-only services failed. show interfaces terse showed only inet on the LAN interface: the engineer had configured the IPv6 address on the physical port name but never committed family inet6 on the unit. Adding family inet6 address 2001:db8:50:10::1/64 and committing brought up router advertisements and the hosts.
Lesson: verify with show interfaces terse that the protocol family you expect appears.
"What replaces broadcast and ARP in IPv6?"
Multicast replaces broadcast, and Neighbor Discovery (ICMPv6 NS/NA, using solicited-node multicast) replaces ARP. Mention link-local addresses fe80::/10 and /64 subnets.
Key takeaways
- IPv6 is 128 bits as eight hex groups; drop leading zeros and use :: once for one zero run.
- LAN prefixes are /64; types: global 2000::/3, unique local fc00::/7, link-local fe80::/10, multicast ff00::/8.
- No broadcast and no ARP in IPv6; Neighbor Discovery and multicast do that work.
- Junos uses family inet6; routes are in inet6.0.
- Dual stack means both families on the same unit.
Longest match and troubleshooting a stale route
Every time a Junos router receives a packet, it asks one question: which route in my table is the most specific one that contains this destination? This is the longest prefix match. It is the most important rule in IP routing, and the second lab in this module is a ticket that depends on it.
The rule in plain words
Think of a postal sorter with three instructions: "everything else goes to the main hub", "anything for this city goes to depot A", "anything for this exact street goes to depot B". A letter for that street matches all three, but the most specific instruction wins. Routers do the same with prefixes: the route with the longest prefix length wins. Preference (Static 5, OSPF 10, BGP 170 and so on) only decides between routes for the same prefix and never beats a longer prefix.
Routes nest like boxes. The packet uses the smallest box it fits in.
Direct and Local routes
Every configured interface address creates two routes automatically: a Direct route for the connected subnet (preference 0) and a Local /32 route for the router's own address. In the first lab R1 holds 10.50.0.192/30 (Direct) and the static 10.50.0.0/24; for 10.50.0.193 the /30 wins even though both match.
Commands to see which route is used
show route whole inet.0 table show route 172.20.9.10 the route this address actually uses show route 172.20.0.0/16 orlonger the /16 and everything more specific inside it show route protocol direct only Direct routes
If nothing matches and there is no default route, the packet is dropped and the sender receives an ICMP destination unreachable.
Lab 2: the payroll server that vanished
Ticket. R1 is the hub of a small campus. Internet traffic leaves through R2 (10.0.12.2), the campus block 172.20.0.0/16 is behind R3 (10.0.13.2), and R4 (10.0.14.2) is the old DR site retired last month. Since the migration, the office LAN (10.1.1.0/24 behind R1) cannot reach the payroll server 172.20.9.10, though other campus hosts work.
Step 1: observe. Do not change anything yet.
lab@R1-HUB> show route 172.20.0.0/16 orlonger
inet.0: 12 destinations, 12 routes (12 active, 0 holddown, 0 hidden)
172.20.0.0/16 *[Static/5] 00:40:12
> to 10.0.13.2 via ge-0/0/1.0
172.20.9.0/24 *[Static/5] 00:40:12
> to 10.0.14.2 via ge-0/0/2.0
lab@R1-HUB> show route 172.20.9.10
172.20.9.0/24 *[Static/5] 00:40:15
> to 10.0.14.2 via ge-0/0/2.0
lab@R1-HUB> show route 172.20.200.7
172.20.0.0/16 *[Static/5] 00:40:20
> to 10.0.13.2 via ge-0/0/1.0
The payroll server goes to 10.0.14.2 (the retired R4) because of a leftover /24. R3's management loopback 172.20.200.7 is inside the /16 but not the /24, so it works, which explains "other campus hosts work".
Step 2: fix. Either delete the stale /24 (the /16 then takes over) or repoint it to 10.0.13.2. Deleting is cleaner:
lab@R1-HUB> configure
lab@R1-HUB# delete routing-options static route 172.20.9.0/24
lab@R1-HUB# commit and-quit
lab@R1-HUB> show route 172.20.9.10
172.20.0.0/16 *[Static/5] 00:00:04
> to 10.0.13.2 via ge-0/0/1.0
Step 3: prove it. From PC1 (10.1.1.10): ping 172.20.9.10, ping 203.0.113.1 (the Internet test address on R2), and trace 172.20.9.10, which now shows the path through R3.
A troubleshooting workflow that scales
- Define the flow: source, destination, expected path.
- Layer 1 and 2:
show interfaces terse,show arp no-resolve. - Forward route: on each hop run
show route <destination>and read the next hop. - Return route: repeat for the source address; many failures are one-way.
- Look for a more specific route than expected, using
orlonger. - Change one thing, commit (confirmed if remote), verify, and document.
Worked example. Routes: 10.0.0.0/8 via A, 10.1.0.0/16 via B, 10.1.2.0/24 via C. Destination 10.1.2.55: all three match, /24 wins, go to C. Destination 10.1.9.9: /8 and /16 match, /16 wins, go to B. Destination 10.200.0.1: only /8 matches, go to A.
Common mistake. Looking only at the default or the summary route and forgetting that a leftover more-specific route is silently overriding it. Always use show route <dest> rather than reading the table by eye.
Exam trap. A route with a better preference but shorter prefix does not win. Longest prefix first; preference only breaks ties between identical prefixes.
The ghost of the old data center
After a data center move, one finance application kept failing for one department. The old /24 static route to the retired site was never removed, while the new /16 pointed correctly. Every other server worked because it matched only the /16. A single show route for the failing address exposed the stale /24 in seconds.
Lesson: after a migration, audit the specific routes, not only the summaries.
"A route with preference 5 and prefix /16 and another with preference 150 and prefix /24 exist. Which is used for an address in both?"
The /24 route, because longest prefix match comes first; preference only decides between routes for the same prefix. Show the command show route <address> as how you would confirm it.
Key takeaways
- The router picks the longest (most specific) matching prefix; preference only breaks ties for the same prefix.
- Every interface address adds a Direct and a Local /32 route.
- show route <address> shows the route actually used; orlonger lists more-specific routes.
- A stale more-specific static route can override a correct summary.
- Troubleshoot forward and return routes, change one thing, verify.
TCP, UDP and class of service basics
Addresses get a packet to the right device. Ports and transport protocols get the data to the right application on that device. And class of service decides whose packet goes first when the road is full. This chapter covers both, as required by the JNCIA-Junos blueprint.
Connection-oriented and connectionless
Think of two ways to send a document. TCP is registered courier: you agree with the receiver first, every parcel is numbered, and lost parcels are sent again. UDP is dropping a postcard in the box: fast and simple, but nobody promises it arrives.
| TCP (connection-oriented) | UDP (connectionless) | |
|---|---|---|
| Setup | Three-way handshake: SYN, SYN-ACK, ACK | None, just send |
| Reliability | Sequence numbers, acknowledgements, retransmission | No delivery guarantee |
| Flow control | Sliding window | None |
| Overhead | Higher | Lower, so good for real time |
| Examples | SSH 22, Telnet 23, HTTP 80, HTTPS 443, BGP 179 | DNS 53, DHCP 67/68, NTP 123, SNMP 161, syslog 514, traceroute probes |
TCP agrees on a connection first; UDP skips this step.
IP itself is connectionless: each packet is routed independently. Some protocols do not use TCP or UDP at all: OSPF runs directly on IP (protocol 89) and ICMP is protocol 1. A port number (0 to 65535) identifies the application; clients use a random high source port and servers listen on a well-known port such as 22 or 443.
Class of service (CoS)
Normally all packets are equal ("best effort"). When a link is congested, voice calls must not wait behind a large backup. CoS lets you treat traffic differently. The Junos CoS pipeline has four stages:
- Classification: a behaviour aggregate (BA) classifier reads the DSCP, IP precedence or 802.1p bits already in the packet, or a multifield (MF) classifier (a firewall filter) matches addresses and ports, and places the packet in a forwarding class.
- Policing: limits the rate of a class; excess traffic is dropped or re-marked.
- Scheduling: each forwarding class maps to an output queue; schedulers give each queue a share of bandwidth and a priority.
- Rewrite: marks outgoing packets so the next device can classify them.
Default Junos forwarding classes: best-effort (queue 0), expedited-forwarding (queue 1), assured-forwarding (queue 2) and network-control (queue 3). Voice is normally marked DSCP EF (46). CoS only matters during congestion; on an idle link every packet goes out immediately.
lab@R1> show class-of-service interface ge-0/0/0 Physical interface: ge-0/0/0, Index: 148 Queues supported: 8, Queues in use: 4 Scheduler map: <default>, Index: 2 Classifier: dscp-default, Code point type: dscp
Worked example. A branch link of 10 Mbit/s carries video backups and VoIP. Voice arrives marked EF and is classified into expedited-forwarding; the scheduler gives that queue strict priority so voice delay stays low. The backup is best-effort and fills the remaining bandwidth. Without CoS, a burst of backup packets would delay voice and calls would break up.
Common mistakes. Thinking CoS creates bandwidth; it only decides who is served first when there is a shortage. Trusting markings from untrusted ports without rewriting them at the edge.
Exam traps. TCP is reliable and ordered, UDP is not; DNS uses UDP 53 for normal queries. BA classifiers use packet markings, multifield classifiers use filters. The order is classification, policing, scheduling, rewrite.
Choppy calls at 4 pm
Every afternoon at 4 pm the sales team's IP phones were choppy. Interface counters showed a branch uplink running at 100 percent when the nightly software mirror started early. The team marked VoIP as DSCP EF at the phones, used a BA classifier on the router, and gave the expedited-forwarding queue priority. Calls became clear, and the backup simply took a little longer.
Lesson: CoS protects delay-sensitive traffic during congestion; it is not a substitute for adding bandwidth when links are always full.
"What is the difference between TCP and UDP, and when would you use each?"
TCP is connection-oriented with a three-way handshake, sequencing, acknowledgements and flow control, used for web, SSH and BGP. UDP is connectionless with low overhead, used where speed matters more than perfect delivery: DNS, voice, video, syslog. Add that applications on top of UDP can add their own reliability.
Key takeaways
- TCP: handshake, reliable, ordered, flow control. UDP: no setup, no guarantees.
- Ports identify applications; learn 22, 53, 80, 123, 161, 179, 443, 514.
- CoS pipeline: classify, police, schedule (queues), rewrite.
- BA classifiers read markings; multifield classifiers use filters.
- CoS matters only under congestion; EF (46) is typical for voice.
Summary and exam checklist
This chapter pulls the module together. Use it the week before the exam and again after the two labs. If you can do each item without looking, you are ready for the Junos OS module.
Can-do checklist
- Count collision and broadcast domains for any hub, switch, VLAN and router design.
- Describe the Ethernet frame, the MAC table and how ARP resolves a next hop.
- Convert between decimal and binary for an octet and read a prefix as a mask.
- Find network, first usable, last usable and broadcast for any IPv4 subnet using the block size.
- Plan VLSM for a given set of host counts, largest first.
- Summarise contiguous networks into one prefix.
- Shorten and expand IPv6 addresses and identify the address types.
- Configure family inet and inet6 on a unit, build an IRB gateway, and add static and default routes.
- Apply longest-prefix match to predict the next hop, and prove it with show route.
- Compare TCP and UDP, name the common ports and list the four stages of CoS.
The module in one picture: from broadcast domains up to how a router chooses a route.
Mini glossary
- Collision domain
- Devices sharing a half-duplex medium; one per switch port.
- Broadcast domain
- Devices that receive each other's broadcasts; one per VLAN or router interface.
- ARP
- Maps a next-hop IPv4 address to a MAC address.
- Prefix length
- Number of network bits in an address.
- VLSM
- Subnets of different sizes from one block.
- Summary route
- One shorter prefix covering many contiguous networks.
- IRB
- Integrated routing and bridging interface: a VLAN gateway on an EX switch.
- Link-local
- IPv6 address fe80::/10, valid on one link.
- Longest prefix match
- The most specific matching route is used.
- Preference
- Junos route trust value; lower wins between identical prefixes.
- Forwarding class
- CoS label that selects an output queue.
Most tested facts
| Topic | Fact |
|---|---|
| Domains | Switch: collision per port, broadcast per VLAN. Router: broadcast per interface. |
| Hosts per prefix | /24 254, /25 126, /26 62, /27 30, /28 14, /29 6, /30 2 |
| Block size | 256 minus mask octet (/26 gives 64) |
| Private IPv4 | 10/8, 172.16/12, 192.168/16 |
| IPv6 types | 2000::/3 global, fc00::/7 ULA, fe80::/10 link-local, ff00::/8 multicast |
| :: rule | Used once per address |
| Route choice | Longest prefix first, then preference (Static 5, OSPF 10, RIP 100, BGP 170) |
| Routes per interface | One Direct subnet route and one Local /32 |
| CoS order | Classify, police, schedule, rewrite |
| Default queues | best-effort 0, expedited-forwarding 1, assured-forwarding 2, network-control 3 |
Command cheat-sheet
set interfaces ge-0/0/0 unit 0 family inet address 10.50.0.193/30 set interfaces irb unit 10 family inet address 10.50.0.1/25 set vlans SALES l3-interface irb.10 set interfaces ge-0/0/1 unit 0 family inet6 address 2001:db8:50:10::1/64 set routing-options static route 0.0.0.0/0 next-hop 10.50.0.194 set routing-options static route 10.50.0.0/24 next-hop 10.50.0.193 show route 172.20.9.10 show route 172.20.0.0/16 orlonger show arp no-resolve show ethernet-switching table
The two labs at a glance
| Lab | Key facts |
|---|---|
| Address the Nashik office | /25 Sales, /26 Eng, /30 uplink; gateways .1 and .129; SW1 .193, R1 .194; default on SW1; summary 10.50.0.0/24 on R1; broadcast of Eng is 10.50.0.191; R1 uses /30 for 10.50.0.193. |
| Longest match wins | Stale 172.20.9.0/24 via R4 overrides the /16 via R3; payroll used 10.0.14.2; delete the /24; verify with show route and ping. |
Most common mistakes. Counting network and broadcast as usable; using :: twice; choosing a route by preference instead of prefix length; forgetting the return route.
Exam trap. Preference never beats prefix length. A switch has one collision domain per port, not one broadcast domain per port.
Putting it all together
A new branch needed addressing for 60, 28 and 10 hosts and two router links. The engineer chose /26, /27, /28 and two /30s from one /24, summarised them in one static route toward headquarters, added IPv6 /64 per VLAN, and confirmed with show route that the branch summary was used and not shadowed by an old specific route. The whole design went live in one commit confirmed window.
Lesson: addressing, summarisation, and longest-match verification are one skill.
"Design the addressing for a branch with 60, 28 and 10 hosts."
60 hosts needs 6 bits: /26 (62). 28 hosts needs 5 bits: /27 (30). 10 hosts needs 4 bits: /28 (14). Allocate largest first from a /24 on block boundaries (.0, .64, .96), use /30 for links, leave room to grow, summarise toward the core, and verify with show route.
Key takeaways
- Domains, framing and ARP explain how a local hop works.
- Binary and block size make subnetting and summarisation mechanical.
- IPv6: 128 bits, /64 LANs, no broadcast, family inet6 on Junos.
- Longest prefix match, then preference, picks the route; always verify with show route.
- Next: the Junos OS module on how the Routing Engine and Packet Forwarding Engine use these tables.