Juniper JNCIA-Junos · 0 · Start here

Networking and Junos from zero

What a router and switch really do, how Junos differs from other CLIs, the Juniper product map, how JNCIA, JNCIS-ENT and JNCIP-ENT fit together and how to practise, before your first commit.

32 min read9 chapters0 labs15 quiz7 scenarios15 interview Q&A
Jump to chapter (9)
01

Welcome: what a network is and what you will learn

What you will learn in this module. This is the zero-level module of the JNCIA-Junos course (exam JN0-106). You need no networking experience. By the end you will know what a router, a switch and a packet are, how IP addresses and Ethernet work in plain words, why Junos feels different from other command lines, which Juniper product does what, how the JNCIA, JNCIS-ENT and JNCIP-ENT certifications connect, and how to practise in this simulator. There are no labs here: the goal is to remove fear before the first command.

Prerequisites. You should be able to use a computer, a browser and a text editor. That is all.

Start with an analogy: a network is a postal system

Imagine a country with houses, post offices and sorting centres. You write a letter, put the destination address on the envelope and drop it in a box. A local post office looks at the address and decides: deliver in this street, or send to the big sorting centre. The sorting centre looks at the city and sends it onward. Finally a postman delivers it to the right door.

A computer network works the same way. A host (laptop, phone, server) wants to send data. The data is cut into small pieces called packets, each with a destination address. Switches carry packets inside one building or floor, like the street postman. Routers carry packets between networks, like the sorting centres. Your job as a network engineer is to make sure every device knows where to hand the packet next.

Laptop Switch Router Router Server same street between networks between networks

A packet travels from a laptop to a server. The switch moves it inside the local network, the routers move it between networks.

Why Juniper and why JNCIA

Juniper Networks makes routers, switches, firewalls and wireless gear used by internet providers, data centres, universities and large companies. All of it runs one operating system family called Junos OS. Learn Junos once and you can work on a small branch switch and on a huge core router with the same commands. The JNCIA-Junos certification (Juniper Networks Certified Associate, exam JN0-106) proves you understand networking basics and the Junos way of working. It is the entry point of the Enterprise Routing and Switching track.

How this course is built

ModuleWhat it gives you
Start here (this one)Zero-level concepts, vocabulary, product map, exam path
FundamentalsAddressing, subnetting, longest match, TCP and UDP
Junos OSRouting Engine, forwarding engine, transit and exception traffic
CLI, setup, services, monitoringConfigure, commit, roll back, verify, maintain
Routing, policy, OSPF, filtersStatic and dynamic routing, firewall filters

Worked example. You open a website on your laptop at 192.0.2.10. Your laptop builds a packet addressed to the web server 203.0.113.50. The packet goes to your switch, then to your office router (your default gateway), then across two provider routers, and finally to the server. At no point does any device know the whole path. Each one only knows the next hop. That idea, hop-by-hop forwarding, is the heart of networking.

Common beginner mistake. Trying to memorise commands before understanding what the device is doing. Commands change between vendors, but the ideas (packet, address, next hop, table lookup) never change. Understand the idea first, then the command is easy.

The new joiner who froze

Ravi joined a support team as a fresher. On day one a senior asked him to check why a branch could not reach the head office. He opened a router CLI and froze: hundreds of commands, no map. His senior drew three boxes on paper: branch PC, branch router, head-office router, and asked, "Where does the packet stop?" Ravi then ran a ping from the PC, a ping to the router, a ping across the link, and found the break in ten minutes. The commands were new, but the question "where does it stop" needed only the postal-system picture.

Lesson: a mental map of how packets travel beats memorised commands.

"Explain in simple words what a router does."

Strong answer: a router connects different networks and forwards each packet toward its destination by looking up the destination IP address in its routing table and choosing the best next hop. Compare it with a switch, which forwards frames inside one network using MAC addresses. A one-line analogy (post office sorting centre) shows you can explain to non-technical people.

Key takeaways

  • A network moves small pieces of data called packets between hosts using addresses.
  • Switches connect devices inside one network; routers connect different networks.
  • Every device only decides the next hop; there is no single device that knows the full path.
  • Junos OS runs on all Juniper platforms, so one skill set covers many devices.
  • JNCIA-Junos (JN0-106) is the entry certification; this module needs no prior knowledge.
02

Routers, switches and packets in plain words

Before any command, you need a clear picture of three words: packet, switch and router. Everything in JNCIA-Junos is built on them.

What is a packet?

Sending a 2 GB video as one giant block would be slow and fragile. A network instead cuts data into small pieces. Each piece is wrapped in a header (like an envelope) that carries the source address, the destination address and some control information, followed by the payload (the actual data). At layer 3 this unit is called a packet. At layer 2 the same thing, wrapped again for one hop of the journey, is called a frame.

Frame (Ethernet header + trailer) MAC header IP header Payload (your data) FCS (check) The IP packet stays the same end to end; the frame is rebuilt at every hop

An IP packet rides inside an Ethernet frame. The frame changes at every hop; the packet does not.

What is a switch?

A switch connects devices that belong to the same network, such as all the PCs on one office floor. It works at layer 2 and looks only at the MAC address in the frame. It learns which MAC address lives behind which port and keeps this in a MAC table. When a frame arrives, the switch sends it out of the one port where the destination lives. If it does not know yet, it floods the frame to all other ports in the same VLAN. A VLAN is a virtual split of a switch into separate networks.

What is a router?

A router connects different networks. It works at layer 3 and looks at the IP address in the packet. It keeps a routing table: a list of destination networks and, for each, the next hop (the neighbour router to hand the packet to) and the exit interface. For each packet it finds the best matching entry and forwards. Routers do not forward broadcasts, so every router interface is a separate network.

SwitchRouter
Connectsdevices in one networkdifferent networks
Looks atdestination MAC addressdestination IP address
TableMAC tablerouting table
Layer2 (data link)3 (network)
Junos commandshow ethernet-switching tableshow route

Real Juniper boxes often do both. An EX switch can have an IRB (integrated routing and bridging) interface, so it switches inside a VLAN and routes between VLANs.

Worked example. PC1 (192.0.2.10) sends to PC2 (192.0.2.20) in the same network: PC1 builds a frame with PC2's MAC address, the switch looks up its MAC table and sends it out one port. No router is involved. Now PC1 sends to a server at 203.0.113.50 in another network: PC1 builds a frame with the router's MAC address (the gateway), the router receives it, strips the frame, looks up 203.0.113.50 in its routing table, and builds a new frame for the next hop.

Every device has two kinds of address: a MAC address (burned into the network card, used for one hop) and an IP address (assigned by an engineer, used end to end).

Common beginner mistake. Thinking the source and destination IP addresses change when a packet passes through a router. They do not (apart from NAT, covered later). What changes at each hop are the MAC addresses of the frame.

Two PCs, one cable, no ping

In a classroom lab two PCs were connected through a switch. PC1 was 192.0.2.10 and PC2 was 198.51.100.20. They could not ping each other even though cabling was perfect. The instructor asked: "Same network or different?" They were in different networks, so PC1 sent its traffic to its default gateway, but no router existed. Adding a router (or giving both PCs addresses from the same subnet) fixed it immediately.

Lesson: a switch alone only joins devices of one network. To cross to another network you need a router and a gateway.

"What is the difference between a switch and a router?"

Say: a switch forwards frames within a network using the MAC table at layer 2; a router forwards packets between networks using the routing table at layer 3 and does not pass broadcasts. Add that modern Juniper EX and QFX switches can route too, through IRB interfaces. Mentioning both tables and both commands shows hands-on knowledge.

Key takeaways

  • Data is cut into packets; each hop wraps the packet in a new Ethernet frame.
  • A switch uses MAC addresses and a MAC table within one network or VLAN.
  • A router uses IP addresses and a routing table between networks and picks a next hop.
  • IP addresses stay the same end to end; MAC addresses change at every hop.
  • Many Juniper switches also route using IRB interfaces.
03

IP addresses and Ethernet in plain words

Two address types appear in every network conversation: the MAC address (Ethernet) and the IP address. This chapter explains both without maths, and previews the one trick you will use all year: splitting an address into a network part and a host part.

Ethernet and MAC addresses

Ethernet is the standard way devices on a local network exchange frames over copper or fibre cable. Each network card has a 48-bit MAC address written in hex such as 2c:6b:f5:3a:10:c1. The first half identifies the manufacturer, the second half is unique to the card. The address ff:ff:ff:ff:ff:ff means "everybody on this network": a broadcast. MAC addresses only matter on one hop: they are used between a host and its switch or router, never across the internet.

IP addresses

An IPv4 address has four numbers from 0 to 255 separated by dots, for example 192.0.2.10. Technically it is 32 bits, and each number is 8 bits. IP addresses are given by the engineer, can change, and describe where a device sits in the network. That is why they can be used to route across the world.

An address has two parts: the network part (the street) and the host part (the house number). The prefix length or subnet mask tells you where the split is. In 192.0.2.10/24 the first 24 bits (192.0.2) are the network and the last 8 bits (10) are the host. All devices with the same network part can talk directly without a router.

192 . 0 . 2 10 Network part (24 bits) = the street Host part (8 bits) = the house 192.0.2.10/24 means: same street as 192.0.2.1 to 192.0.2.254

The /24 prefix says the first three numbers are the network. Subnetting in depth comes in the Fundamentals module.

Gateway, subnet and the golden rule

The default gateway is the router address on your own network that you hand packets to when the destination is somewhere else. The host makes one simple decision for every packet:

  1. Is the destination in my network (same prefix)? Send directly to its MAC address.
  2. If not, send to my default gateway's MAC address and let the router handle it.

To learn the MAC address of a neighbour whose IP it knows, a host uses ARP (Address Resolution Protocol): it broadcasts "who has 192.0.2.1?" and the owner answers with its MAC address.

Special addresses to recognise

RangeMeaning
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16Private ranges used inside organisations (RFC 1918)
127.0.0.0/8Loopback: the device itself
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24Documentation ranges used in this course
0.0.0.0/0Default route: "everywhere else"

IPv6 is the newer version with 128-bit addresses such as 2001:db8::1. It exists because IPv4 has only about 4 billion addresses. The exam covers both; Fundamentals teaches IPv6 in detail.

Worked example. A PC has 192.0.2.10/24 and gateway 192.0.2.1. It wants to reach 192.0.2.77: same network (first three numbers equal), so it ARPs for 192.0.2.77 and sends directly. It wants to reach 198.51.100.9: different network, so it ARPs for 192.0.2.1 (the router) and sends the frame there, with destination IP still 198.51.100.9.

Common beginner mistake. A wrong gateway or wrong mask. If a PC has 192.0.2.10/24 but the gateway is set to 192.0.3.1, the gateway is not in its own network and the PC cannot reach it. Local pings will work, internet pings will fail.

Only the local printer works

A user could print and open the file server in the same office but not browse the internet after a move to a new desk. The helpdesk saw IP 192.0.2.50 with mask 255.255.255.0 and gateway 192.0.2.254 (the old floor's router). The new network's gateway was 192.0.2.1. After fixing the gateway the internet worked. Local traffic had never needed the gateway, so the symptom pointed straight at it.

Lesson: "local works, remote fails" almost always means a gateway, mask or routing problem.

"What is the difference between a MAC address and an IP address?"

A MAC address is a 48-bit hardware address used at layer 2 for delivery on one link; it changes at every hop. An IP address is a layer-3 logical address assigned by configuration, used for end-to-end routing; it has a network part and a host part. Mention ARP as the bridge that maps one to the other on the local segment.

Key takeaways

  • MAC addresses (48 bits) work per hop; IP addresses (32 bits for IPv4) work end to end.
  • The prefix length splits an address into network and host parts.
  • Same network: send directly. Different network: send to the default gateway.
  • ARP finds the MAC address that belongs to an IPv4 address on the local segment.
  • Documentation ranges 192.0.2.0/24, 198.51.100.0/24 and 203.0.113.0/24 are used in examples.
04

Junos compared with other command lines

If you have seen a Cisco IOS or Linux prompt, Junos will feel different at first. This chapter explains the three ideas that make Junos special so that the later modules feel natural.

Idea 1: two modes, operational and configuration

When you log in you land in operational mode, shown by the > prompt. Here you look and test: show, ping, traceroute, monitor. You cannot change the configuration here. To change it you type configure and enter configuration mode, shown by the # prompt. You type exit to go back.

lab@R1> operational mode
lab@R1> configure
Entering configuration mode

[edit]
lab@R1# configuration mode

The [edit] line tells you where you are in the configuration tree.

Idea 2: the candidate configuration and commit

On many devices every command you type changes the running device at once. On Junos it does not. Your changes go into a candidate configuration, a private working copy. Nothing happens to traffic until you type commit. Then Junos checks the candidate for errors, and if it is valid it becomes the active configuration. If you make a mistake, rollback throws away the candidate or reloads an earlier version. Junos keeps the last 50 committed versions.

Your set / deletecommands Candidateconfiguration Activeconfiguration commit rollback 0 discards the candidate; rollback 1 loads the previous version

Safe changes: edit freely, check, then commit. Nothing reaches the network before the commit.

Idea 3: a hierarchy you can read

The Junos configuration is a tree. Top-level branches include system, interfaces, routing-options, protocols and firewall. The same configuration can be shown as nested braces or as flat set lines:

lab@R1# show interfaces ge-0/0/0
unit 0 {
    family inet {
        address 192.0.2.1/24;
    }
}

lab@R1# show interfaces ge-0/0/0 | display set
set interfaces ge-0/0/0 unit 0 family inet address 192.0.2.1/24

The set form is perfect for copy and paste and is what this course uses. You can also pipe output through filters such as | match and | count in the operational mode.

How it compares

TopicTypical other CLIJunos
Applying changesEach line is live immediatelyCandidate, then commit
UndoType the opposite command with "no"rollback or delete
Show running configFlat textshow configuration in tree or | display set
Safety netReload and hopecommit confirmed auto-rolls back
Config historyManual backups50 rollback versions on the box

Worked example. You give ge-0/0/0 the address 192.0.2.1/24. Type configure, then set interfaces ge-0/0/0 unit 0 family inet address 192.0.2.1/24. At that point show displays it but the interface still has no address. Type commit and it goes live. Typed the wrong address? Before committing, rollback 0 wipes your change.

Common beginner mistake. Typing set commands and forgetting commit, then wondering why nothing works. Another one: typing show interfaces terse in configuration mode. Use run show interfaces terse there, because run executes an operational command from within configuration mode.

Exam trap. commit check only validates; it does not apply. commit confirmed 5 applies but reverts in five minutes unless you commit again.

The remote change that saved the day

An engineer changed the management interface address on a router in another city. With a plain commit, a typo would have cut off his own SSH session and needed a site visit. He used commit confirmed 5 instead. The typo locked him out, but after five minutes Junos automatically rolled back and he reconnected.

Lesson: the candidate and commit model, plus commit confirmed, makes risky remote changes safe.

"What is different about the Junos configuration model?"

Changes go to a candidate configuration and take effect only on commit; commit does syntax and semantic checks; 50 previous versions are kept for rollback; commit confirmed gives an automatic safety net; and the configuration is a hierarchy that can be displayed as a tree or as set commands.

Key takeaways

  • Operational mode (>) is for show and test; configuration mode (#) is for changes.
  • Changes go into a candidate configuration and become active only after commit.
  • rollback and commit confirmed provide safe undo; Junos keeps 50 versions.
  • The config is a hierarchy; | display set turns it into flat set commands.
  • run lets you use operational commands inside configuration mode.
05

The Juniper product map: EX, QFX, MX, SRX, PTX and Mist

Juniper product names look like alphabet soup. Each family has one job, and once you know the job the name sticks. The exam expects you to recognise where each family sits, and interviewers love "which Juniper box would you use for...?" questions.

The families in one view

FamilyJobWhere you see it
EX SeriesEthernet switches for campus, branch and accessOffice floors, wiring closets, small server rooms
QFX SeriesData center switches, high speed (10G up to 400G)Top-of-rack and spine in data centers
MX SeriesUniversal routers for edge, WAN and service providerInternet edge, metro, peering, enterprise WAN
PTX SeriesPacket transport routers for very large coresProvider backbones, 100G/400G core links
ACX SeriesCompact access and aggregation routersMobile backhaul, cell sites, metro access
SRX SeriesFirewalls with routing, NAT, VPN and security servicesInternet perimeter, branch, data center edge
Mist AICloud-managed Wi-Fi, wired and WAN assurance with AIOffices and campuses managed from a cloud dashboard
Internet / WAN MX / PTX routers SRX firewall EX switchescampus / branch QFX switchesdata center Mist APsWi-Fi, cloud managed

A simplified network. Routers face the outside, the firewall protects, switches and access points serve users and servers.

One OS, many boxes

EX, QFX, MX, PTX, ACX and SRX all run Junos OS (some data center and campus models also run Junos OS Evolved, a Linux-based variant used on PTX and some QFX). The configuration language is the same. A set interfaces ... unit 0 family inet address line works on a branch switch and on a core router. Differences are in hardware, scale and features: an EX2300 has a few dozen 1G ports, a PTX can forward many terabits.

You may also meet virtual Junos: vMX (virtual router), vSRX (virtual firewall) and vJunos images used in labs. This simulator behaves like those: same CLI, no hardware.

Naming hints

Interface names show the hardware: ge- is Gigabit Ethernet, xe- is 10G, et- is 25G or faster, followed by fpc/pic/port such as ge-0/0/1. Special interfaces include lo0 (loopback), irb (routed VLAN interface), me0 or fxp0 (out-of-band management) and ae0 (aggregated Ethernet).

Worked example. A company with a head office, ten branches and a small data center. Head office edge: two MX routers. Perimeter: SRX firewalls. Office floors: EX switches with Mist access points. Data center: QFX leaf and spine switches. Branches: one SRX each as router and firewall. One OS family covers all of it, so one team can run everything.

Common beginner mistake. Mixing up EX and QFX. A simple rule: EX serves people (campus), QFX serves servers (data center). Another trap: assuming an SRX is "only a firewall". It also routes, does NAT and VPN.

Exam trap. JNCIA-Junos asks which platform fits which role and what the interface naming means. It does not ask for part numbers, but knowing SRX = security and MX = routing helps.

Picking the right box for a school

A school group with 40 classrooms asked for an upgrade. The proposal listed QFX switches for classrooms. A consultant pointed out that QFX is built for the data center and is overkill and over-priced for access. They switched to EX switches with PoE for access points, one SRX at the internet edge and Mist for Wi-Fi visibility. Same Junos, lower cost, easier management.

Lesson: match the family to the role: access and campus EX, data center QFX, edge routing MX, security SRX.

"What is the difference between EX, QFX, MX and SRX?"

EX is campus and branch switching, QFX is data center switching, MX is the multi-service edge and WAN router, SRX is security (firewall, NAT, VPN, with routing). Add that all run Junos OS with the same CLI, which makes skills portable, and mention Mist as the cloud-managed AI-driven wireless and wired layer.

Key takeaways

  • EX = campus/branch switches; QFX = data center switches.
  • MX = edge and WAN routers; PTX = very large core routers; ACX = access and aggregation.
  • SRX = firewall with routing, NAT and VPN; Mist = cloud-managed AI-driven Wi-Fi and wired.
  • All run Junos OS (or Junos OS Evolved), so the CLI skills transfer.
  • Interface names: ge, xe, et plus fpc/pic/port; lo0, irb, fxp0/me0, ae0 are special.
06

The certification path: JNCIA, JNCIS-ENT, JNCIP-ENT

A certification is a ladder. You do not need to see the top to start on the first step, but knowing where the ladder goes helps you plan your study and your career.

The Enterprise Routing and Switching ladder

JNCIA-JunosJN0-106 · Associate JNCIS-ENTSpecialist JNCIP-ENTProfessional JNCIE-ENTExpert (lab)

Each step builds on the one before. JNCIA-Junos is the base for every Juniper track.

LevelWhat it provesTypical topics
JNCIA-Junos (JN0-106)You understand networking basics and can operate JunosFundamentals, Junos OS, CLI, configuration, monitoring, routing basics, policy and filters
JNCIS-ENTYou can implement and troubleshoot enterprise LAN featuresLayer 2 switching and VLANs, spanning tree, OSPF, BGP basics, high availability, security, IPv6
JNCIP-ENTYou can design and troubleshoot larger enterprise networksAdvanced OSPF, BGP, multicast, advanced switching and policy
JNCIE-ENTExpert, hands-on lab examBuild and fix a full network under time pressure

The Juniper tracks run in parallel: Enterprise Routing and Switching (ENT), Service Provider, Data Center, Security and Automation. JNCIA-Junos is the common first step to most of them. Exam codes and details change over time, so always check the current exam page before booking.

What JN0-106 covers

The JNCIA-Junos exam is a multiple-choice test of roughly 65 questions in about 90 minutes, delivered in a testing centre or online. The blueprint is split into domains, and this course has a module for each:

  1. Networking fundamentals: collision and broadcast domains, addressing, subnetting, IPv6, TCP and UDP, CoS basics.
  2. Junos OS fundamentals: Routing Engine and Packet Forwarding Engine, transit and exception traffic.
  3. User interfaces: CLI modes, navigation, candidate configuration, commit, rollback, J-Web.
  4. Configuration basics: initial setup, users, login classes, groups, system services.
  5. Operational monitoring and maintenance: show, monitor, ping, traceroute, logs, upgrades, recovery.
  6. Routing fundamentals: routing and forwarding tables, static routes, OSPF.
  7. Routing policy and firewall filters.

Certifications are valid for a limited period (currently three years), after which you recertify.

A study plan that works

  • Weeks 1 to 2: this module and Fundamentals. Do not skip binary and subnetting practice.
  • Weeks 3 to 5: Junos OS, CLI, initial setup, services, monitoring. Type every command in the simulator.
  • Weeks 6 to 8: routing, OSPF, policy, filters. Then redo every quiz and interview set.
  • Final week: timed mock exams and the exam checklist at the end of each module.

Worked example. A fresher starting in January studies one hour on weekdays and three on Sunday: about 8 hours a week. Eight weeks gives roughly 64 hours, enough for JNCIA-Junos with practice. Next, JNCIS-ENT preparation adds Layer 2 and BGP over another two months.

Common beginner mistake. Studying only theory, or only dumps. The exam tests understanding of how Junos behaves, such as which command shows what, and what happens at commit. Hands-on practice makes the right answer obvious.

From helpdesk to network engineer

Priya worked at an IT helpdesk and wanted to move into the network team. She finished JNCIA-Junos in two months of evening study, practising every configuration in a lab. In the internal interview she was asked to explain candidate configuration and commit confirmed, and to trace a ping step by step. She got the role and later studied for JNCIS-ENT at work. The certificate opened the door; the lab habit won the interview.

Lesson: use the certification as a structured syllabus, and practise until you can explain every command.

"Why did you choose Juniper certifications and where do you want to go next?"

Say that JNCIA-Junos gave you vendor-neutral fundamentals plus the Junos configuration model, and that you plan to build on it with JNCIS-ENT for enterprise switching, OSPF and BGP, then JNCIP-ENT. Tie it to a skill you can demonstrate, such as safe changes with commit confirmed.

Key takeaways

  • Ladder: JNCIA-Junos, then JNCIS-ENT, then JNCIP-ENT, then JNCIE-ENT (lab).
  • JN0-106 is multiple choice with domains from fundamentals to routing policy and filters.
  • JNCIA-Junos is the base for the other Juniper tracks too.
  • Plan weekly study with hands-on practice, not only reading.
  • Always check the current exam objectives before booking.
07

Reading a Junos session before you type one

You will meet real Junos output in every later module. This chapter lets you read a short session line by line, so that your first real command does not feel strange. No lab is needed: just read and follow the logic.

The prompt tells you three things

lab@R1>

lab is the user, R1 is the host name, and the final character is the mode: > operational, # configuration. A root user would see root@R1:~ # in the shell and root@R1> after typing cli.

Help is built in

Press ? at any point to see what can come next, and Space or Tab to complete a word. You can shorten any command to a unique prefix, for example sh int te for show interfaces terse.

lab@R1> show ?
Possible completions:
  arp                  Show system's ARP table entries
  configuration        Show current configuration
  interfaces           Show interface information
  route                Show routing table information
  version              Display software information

A first look at a device

lab@R1> show interfaces terse
Interface               Admin Link Proto    Local                 Remote
ge-0/0/0                up    up
ge-0/0/0.0              up    up   inet     192.0.2.1/24
ge-0/0/1                up    down
lo0                     up    up
lo0.0                   up    up   inet     198.51.100.1        --> 0/0

How to read it: ge-0/0/0 is the physical interface; ge-0/0/0.0 is its logical unit 0, where the IP address lives. Admin up means not disabled by configuration. Link up means the cable and the far end are alive. ge-0/0/1 is admin up but link down: a cable or far-end problem, not a configuration one.

ge-0/0/0 (physical port) unit 0 = ge-0/0/0.0family inet 192.0.2.1/24 Read the name: ge = Gigabit Ethernet 0/0/0 = slot / PIC / port .0 = logical unit

An IP address never sits on the physical port itself on Junos; it sits on a logical unit under a family.

Showing the configuration

lab@R1> show configuration interfaces ge-0/0/0 | display set
set interfaces ge-0/0/0 unit 0 family inet address 192.0.2.1/24

lab@R1> show configuration | match 192.0.2
            address 192.0.2.1/24;

The pipe (|) sends output through a filter: match keeps matching lines, except removes them, count counts lines, find starts from a pattern, no-more turns off paging, and display set flattens the tree.

Your first change, read-only walkthrough

lab@R1> configure
[edit]
lab@R1# set system host-name EDGE-R1
lab@R1# show | compare
[edit system]
-  host-name R1;
+  host-name EDGE-R1;
lab@R1# commit
commit complete
lab@R1# exit

show | compare shows exactly what will change: - lines are removed, + lines are added. It is the habit of every careful Junos engineer. After commit the prompt changes to the new host name.

Worked example. You are told "interface ge-0/0/1 is not working". Read it like a doctor: show interfaces terse shows admin up, link down. Configuration is fine, so the problem is physical: cable unplugged, wrong port, or far end shut. You never needed to change anything to learn that.

Common beginner mistake. Forgetting that show in configuration mode shows the candidate, not the active configuration, and that it displays configuration, not interface status. Use run show interfaces terse for status.

The unlucky cable

A branch reported "the router is broken". The engineer opened show interfaces terse remotely and saw ge-0/0/0 admin up, link down. Someone had moved a patch cable during a cleaning visit. A site contact replugged the cable, the link came up, and the engineer confirmed with ping. No configuration change was made, no commit, no risk.

Lesson: learn to read output first. Many incidents are solved by reading, not typing.

"How do you quickly check which interfaces are up and what IP addresses they have?"

Run show interfaces terse; mention admin versus link state and that addresses are on logical units. Add | match inet to show only interfaces with IPv4, and show configuration interfaces | display set to see how it is configured.

Key takeaways

  • The prompt shows user, host name and mode (> operational, # configuration).
  • ? lists options, Tab completes, and any unique prefix works.
  • Interfaces have a physical name and logical units; IP addresses live on units.
  • Admin up and link down points to a physical problem, not a configuration one.
  • Use | match, | count, | display set and show | compare as daily habits.
08

How to practise in this simulator

Reading builds understanding, but typing builds skill. The labs in this course run in a simulated network with Junos routers and switches, virtual PCs and servers. The CLI behaves like real Junos: same prompts, same set syntax, candidate configuration and commit. This chapter shows the routine that gets the most out of every lab.

What a lab looks like

Each lab gives you a story (a ticket from a customer or a build request), a topology (devices and links), and a list of tasks. Some labs are configuration labs: build something new. Others are troubleshooting labs: something is broken and you must find and fix it. Tasks are checked automatically by looking at the devices, so you prove the result by the actual network state, not by typing a magic answer. Some tasks also ask a short question, such as "what is the broadcast address?", to make sure you understand what you see.

1. Read task 2. Look first 3. Configure 4. Verify wrong result? read the output, fix, verify again

The loop of every good engineer: look, change, verify. Verification is a step, not an afterthought.

A repeatable routine

  1. Read the whole task and sketch the topology on paper: devices, links, addresses.
  2. Look before you change. On each device run show interfaces terse, show route and show configuration | display set.
  3. Enter configuration mode with configure and type set commands, one idea at a time.
  4. Preview with show | compare, then commit. Use commit check if you are unsure.
  5. Verify from the outside: use run ping, run show route and from a PC use ping and trace.
  6. Roll back with rollback 1 then commit if it got worse.

Useful simulator habits

lab@R1> configure
lab@R1# set interfaces ge-0/0/0 unit 0 family inet address 192.0.2.1/24
lab@R1# show | compare
lab@R1# commit and-quit
lab@R1> ping 192.0.2.2 count 3

Virtual PCs have a simple CLI of their own: ip 192.0.2.10/24 192.0.2.1 sets address and gateway, then ping and trace test the path. Remember that the PC prompt is not Junos. Use hints when stuck, but try for five minutes first: the struggle is where learning happens. Every lab also has a model solution; study it after you finish, to compare approaches.

Worked example. A task says "PC1 must reach the server". You sketch PC1, SW1, R1, server. You check show interfaces terse on R1 and see ge-0/0/1 has no address. You add it, preview with show | compare, commit, then ping from PC1. It still fails, so you read show route: there is no route to the server's network. You add the route, commit, ping again, success. The fault was found by reading, not guessing.

Common beginner mistake. Typing the model solution from the hint without understanding it. You will pass the lab and fail the exam. Another trap: forgetting to commit, so the check cannot see your change.

The learner who stopped guessing

A learner kept failing a troubleshooting lab where a server was unreachable. He changed things at random: addresses, masks, routes. Each change made the picture muddier. A mentor told him to restore the lab, change nothing for five minutes and only run show commands. The output showed one wrong next-hop address in a static route. A single corrected line and a commit fixed it.

Lesson: observe, form one hypothesis, change one thing, verify. Random edits hide the real fault.

"Walk me through how you troubleshoot a connectivity problem."

Define the symptom and the path, check layer by layer: interface state, IP addressing, ARP, routing table, then filters. Change one thing at a time, verify after each, and keep a rollback ready. Name the Junos commands you would use at each layer.

Key takeaways

  • Labs are checked by the real device state, so commit and verify every change.
  • Routine: read, look, configure, preview with show | compare, commit, verify.
  • Virtual PCs use their own simple CLI for ip, ping and trace.
  • Use hints after trying, and study the model solution after finishing.
  • Troubleshooting means one hypothesis and one change at a time.
09

Summary and exam checklist

You now have the base for the whole JNCIA-Junos course. Use this chapter as a checklist: if you can do or explain every line, you are ready for the Fundamentals module.

Can-do checklist

  • Explain what a packet, a frame, a switch and a router are, using the post-office analogy.
  • State which table each device uses (MAC table, routing table) and the command that shows it.
  • Split 192.0.2.10/24 into a network part and a host part and say whether two addresses are in the same network.
  • Describe what a default gateway and ARP do.
  • List the three Junos ideas: two modes, candidate configuration with commit, and the configuration hierarchy.
  • Match EX, QFX, MX, PTX, ACX, SRX and Mist to a role.
  • Name the steps JNCIA-Junos, JNCIS-ENT, JNCIP-ENT and the seven JN0-106 domains.
  • Read show interfaces terse and tell an admin problem from a link problem.
  • Follow the practice routine: look, configure, show | compare, commit, verify.
Packets, hosts Switch / router MAC and IP Junos ideas Products Cert path Reading the CLI Practice routine

The eight chapters before this one, on a page.

Mini glossary

Packet
A layer-3 unit of data with source and destination IP addresses.
Frame
A layer-2 unit; carries a packet across one hop with MAC addresses.
Switch
Forwards frames inside a network using the MAC table.
Router
Forwards packets between networks using the routing table.
Next hop
The neighbouring router that gets the packet next.
Default gateway
The router a host uses to leave its own network.
ARP
Maps an IPv4 address to a MAC address on the local segment.
Candidate configuration
The working copy that becomes active only on commit.
Commit
Validates the candidate and makes it the active configuration.
Rollback
Restores the candidate to a previous committed version (0 to 49).
Logical unit
A sub-interface, such as ge-0/0/0.0, which carries the address.
Junos OS
The operating system shared by Juniper routers, switches and firewalls.

Most tested facts

FactRemember
Prompts> operational, # configuration
Make a change livecommit (nothing happens before it)
Safe remote changecommit confirmed minutes, auto rollback
Validate onlycommit check
Preview changeshow | compare
Flat viewshow configuration | display set
Rollback versionsrollback 0 to 49 (50 stored)
Product rolesEX campus, QFX data center, MX edge router, SRX security, PTX core
Interface namesge, xe, et plus fpc/pic/port; unit holds address

Command cheat-sheet

configure                           enter configuration mode
set / delete / rollback             change the candidate
show | compare                      preview the difference
commit / commit check / commit confirmed 5
run show interfaces terse           operational command from config mode
show route                          routing table
show ethernet-switching table       MAC table on EX
show configuration | display set

Common mistake to avoid in every module. Changing configuration without checking first, and forgetting to verify after commit.

Exam trap. A set command in configuration mode does not change traffic until commit. Also, an IP address belongs under a unit and a family, never straight under the physical interface.

Ready for the next step

A learner finished this module and was asked by his manager to explain to a new colleague why a switch cannot connect two networks. He drew two PCs in different subnets, one switch, then added a router and showed the gateway setting. In three minutes the colleague understood. That drawing is the whole module in one picture.

Lesson: if you can teach it with a simple drawing, you have understood it.

"Tell me about yourself and your Junos preparation."

Give a short story: you started from basics (packets, switches, routers), learned the Junos candidate and commit model, can read interface and route output, and practise every concept in a simulator with verification. End with the next step: addressing and routing on Junos and the JN0-106 exam.

Key takeaways

  • Packets travel hop by hop; switches use MACs, routers use IPs.
  • Junos has two modes, a candidate configuration, commit and rollback.
  • Know the product families and the certification ladder.
  • Read output first, change one thing, preview, commit, verify.
  • Next: the Fundamentals module on addressing, subnetting and longest match.
🎓 For educational purposes only — all devices are simulationsTerms of UsePrivacy Policy© 2026 Network Kings
CONFIG by Network Kings — an educational IT simulation platform for learning purposes only. It is not Cisco IOS, Junos, FortiOS or PAN-OS and contains no Cisco, Juniper, Fortinet or Palo Alto Networks software. Cisco, IOS, CCNA, CCNP, Juniper, JNCIA, JNCIS, JNCIP, Fortinet, FortiGate, FortiOS, NSE, Palo Alto Networks, PAN-OS and PCNSE are trademarks of their respective owners. Network Kings is not affiliated with or endorsed by Cisco Systems, Inc., Juniper Networks, Inc., Fortinet, Inc. or Palo Alto Networks, Inc.