TechPost

Byte-Sized Articles on Juniper Solutions by Network Engineers, for Network Engineers

This Tech Post aims to address multi-tenant secure Remote Access of the HPE Juniper Networking SRX firewall. A demo setup that allows for direct breakout into an EVPN/VXLAN fabric VRF, where the SRX serves ...
Juniper PTX Routers as Front-End Network Tunnel Aggregation and DCI Edge Router (Part 2 of "Overlay Networking in AI Era" series) Introduction In the previous article , we reviewed the evolution ...
An Introduction to LLM-Driven Network Automation Overview Using LLMs with MCP is a next-generation approach to network automation which is available today. Today's market-leading LLM's have a ...
All you need to know to get started. Let’s explore the latest addition to the PTX family, the 8 and 12-slot PTX12000 chassis. Introduction It’s not every day you unveil a brand-new series product ...
From Kernel Networking to DPU: Evolution of Data Processing and Gateway Tunneling Cloud providers run huge numbers of concurrent AI workloads across shared infrastructure without them stepping on each ...
A simple guide for understanding the differences between Chassis Cluster (original CC) and MultiNode High Availability (MNHA) used on Juniper SRX. Existing Techpost articles cover the method to understand ...
This article is not a comparison of protocols, nor an argument for or against any specific traffic engineering architecture. Instead, it is an examination of how architectural narratives form, how they ...
Advanced Junos OS route control techniques, such as rib-groups, vpn-global-import, and rib-export, enable selective sharing, controlled leaking, and cloning of routes across different RIBs while maintaining ...
Do you need secure, isolated multi-tenant connectivity across Kubernetes and cloud infrastructures. JCNR supports SRv6 L3VPN with micro-Segment Identifiers (uSIDs) in various SRv6 endpoint behaviors ...
Let's use the Juniper filtering tools in a more comprehensive and realistic use case in which MX301 will serve as a filtering routing gateway to protect peering points, critical cloud platforms, or ...
Explore how Juniper’s MX301 router, using Junos 24.4 and its Trio 6 ASIC’s specialized Fast Lookup Table (FLT), accelerates BGP FlowSpec rule processing so that even large and complex FlowSpec filters ...
Juniper adds support for inline IPsec on MX-series routers, meaning that IPsec encryption/decryption is done directly by the router’s Packet Forwarding Engine (PFE) ASIC instead of by a separate service ...
For a long time, the SRX has been able to periodically download IPv4 and IPv6 prefixes from external sources and map them to objects used in firewall policies. Essentially, this is the easiest way to automate ...

MX301 Deepdive

Let's explore the capabilities of the Juniper Networks MX301 Universal Routing Platform, a 1RU edge router built on Trio 6 silicon that delivers up to 1.6 Tbps full-duplex throughput, supports a broad ...
After three years of activity, we passed the 200 articles mark last month. Writers have been extremely prolific, let's try to build a page with links to all these posts with a short abstract. ...
Priority Flow Control (PFC) can be used in Ethernet fabrics to achieve lossless traffic—particularly important in AI/ML workloads and HPC—by pausing specific priority queues when congestion arises, avoiding ...
The Juniper Cloud‑Native Router (JCNR) integrates modern forwarding and resilience mechanisms, specifically Segment Routing with MPLS (SR‑MPLS) and Topology‑Independent Loop‑Free Alternate (TI‑LFA), to ...
The SRX4700 100Gbps Full Duplex IPSEC tunnel TechPost demonstrates the ability of the HPE Juniper Networking flagship 1RU firewall device to encrypt 100Gbps traffic patterns from a single system, such ...
A detailed breakdown of the private no-prepend-gloabal-AS option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering. It ...
A detailed breakdown of the no-prepend-global-AS option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering. It covers ...
A detailed breakdown of the Private option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering. It covers configuration ...
A detailed breakdown of the alias option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering. It covers configuration examples, ...
A detailed breakdown of the Default option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering. It covers configuration ...
How AI agents, connected via the open-source Model Context Protocol (MCP) server, can simplify and standardize network automation tasks on Junos OS devices (e.g., retrieving configurations, checking device ...
Red Hat Ansible Automation Platform and Juniper Networks each have collections of Ansible modules for managing Junos devices. We are merging Ansible’s collection into the Juniper Collection to provide ...
EVPN technology provides native CE direct L2 multi-homing capabilities, in either Active-Active or Active-Standby scheme. However, there might be a need for certain L2 access domains to form a ring topology ...
Can we run distributed training between clusters located 50 km apart? How do we interconnect these sites? Do we need to tweak the collectives library and the NIC settings to run training jobs? And ...
Juniper Networks introduces a powerful tool—Passive Port Monitoring (PPM)—to elevate the visibility, accuracy, and security of synchronization networks. An article co-written by Kamatchi ...
The New Role of the Network Engineer in the Age of AI: Context Is King. The arrival of AI in networking is transforming the way we think about operations, automation, and troubleshooting. For ...
What if you had an AI partner that could help you manage your network and troubleshoot any issues, learn from them, and continuously get smarter about preventing future incidents? Introduction ...

MAP-E with Junos OS

This document provides an overview of MAP-E (Mapping of Address and Port using Encapsulation), a stateless IPv4-over-IPv6 transition technology supported by Junos OS. It explains key terminology, operational ...
Learn all about SRv6 micro-SIDs (uSIDs), a compressed alternative to full-length SIDs in IPv6-based segment routing and how to configure it on Juniper MX Series. Introduction SRv6 (Segment Routing ...
Learn why the Trio and Express “Firewall Filters” (ACL) are truly unique in this industry. An article co-written by David Roy and Nicolas Fevrier Introduction Every vendor in the networking ...
EVPN-On-A-Stick offers a fresh way to build networks by merging service functions directly into the main fabric. The result is simpler operations, faster performance, and a more scalable foundation for ...
Automating the MPLS and SR network with Juniper Routing Director network optimization use case. Introduction Service providers and large enterprise networks nowadays offer multiple services with ...
The procedure for building a multi-geography multi-cluster from three Red Hat OpenShift Container Platform (RHOCP) clusters. The constructed multi-cluster will be capable of supporting Broadband Edge (BBE) ...
Holistic design considerations for Large-Scale Enterprise WAN backbone networks, especially in the context of the evolving landscape shaped by connecting AI Clusters over the WAN Backbone. Introduction ...
A comprehensive overview of microbursts and their impact on network performance, with a focus on Juniper's QFX5K EVO platforms (QFX5220, QFX5130, QFX5230, and QFX5240). Introduction In this article, ...
Live streaming audiences are now routinely reaching tens of millions of concurrent viewers. Combined with increasing bitrates for 4K/8K/360° video, is it time for a new approach to delivering this content? ...
A detailed description of the latest line cards, fabric cards, power supply modules and fan trays introduced in the PTX10000 chassis, enabling the power of the Express5 chipset and 800GbE interfaces in ...
Learn how APAC service providers are using Routing Active Testing to drive customer experience. We explore customers' motivations, Juniper’s solution approach and key use cases. Introduction Juniper ...

SRX MPLS in Flow

Junos 24.2R1 brings improvement for selected Juniper SRX series devices, particularly on MPLS and packet-mode/flow-mode processing. This post includes a simple example of an MPLS-enabled SRX device processing ...
A detailed description of the latest MX10000 Series line card LC4802, completing the existing LC4800 but with only QSFP ports. This new card is powered by three Trio 6 Forwarding ASICs. This article ...
YAMS (Yet Another MCP Server) is a specialized Model Context Protocol server designed to address the operational complexities of managing JCNR deployments at scale. Built specifically for network ...
Modern MPLS networks must support highly dynamic traffic patterns, especially in cloud and service provider environments. While RSVP-TE provides engineered path control, traditional single-LSP scaling ...
In modern MPLS networks, managing traffic flows with precision is essential for maintaining performance and reliability. RSVP-TE provides a robust framework for establishing traffic-engineered paths that ...
There has been a lot of interest recently in Large Language Models (LLMs). One of the major applications of LLMs is conversational AI that enables natural language interactions between people and chatbots. ...
While destination-based forwarding works well for most traffic, certain services require more tailored handling – such as routing based on source’s IP or DSCP values. Leveraging alternative traffic-engineered ...
While Class of Service (CoS) ensures that priority traffic receives preferential treatment on congested interfaces, it does not inherently provide a mechanism to reduce transit latency for delay-sensitive ...
Configuring site-to-site IPSec tunnels for devices that fall outside of the seamless integration capabilities Mist provides may seem daunting at first. This article highlights the methods of configuring ...
Class of Service (CoS) on an MPLS backbone is essential to ensure differentiated traffic handling and maintain QoS across complex, high-throughput networks. It is challenging due to the need for consistent ...

Hybrid MNHA with eBGP

Let's highlight the flexibility of Multi-Node High Availability (MNHA) and JUNOS while providing design considerations when implementing MNHA in a hybrid deployment model. Introduction Every ...
And Why It Matters More Than You Think... Introduction: A Hidden Villain in AI Data Centers In AI/ML training environments, speed isn’t just a competitive ...
Let's expand on the article on vSRX on mini-PC with details on another platform and use case. This time, the Juniper vSRX is deployed on a specific fanless, rugged, DIN-mountable, and DC-powered PC for ...
Validating VPLS on the PTX10002-36QDD with Junos Evolved 24.2R2 for Metro Aggregation or Cloud Enterprise use cases. Introduction The PTX10002-36QDD is a next-generation cloud-optimized 2U ...
Network observability is a crucial component of an AI data center network, and TAP aggregation is a primary building block of its ecosystem. Introduction Network observability relies on extensive ...
Establishing SR-TE (CSPF) LSPs through inter OSPF areas is a challenge, as these LSPs rely on TED, and this TED is per OSPF area or IS-IS level. In our previous tech post “ Migrating from OSPF/LDP ...
In Julian Lucek’s blog post, Detection of Blackholes in Networks Using JRI , he explores how Juniper’s JRI (Juniper Resiliency Interface) can be leveraged to detect blackholes in networks. Expanding on ...
A detailed overview of Filter-Based Forwarding (FBF), also known as Policy-Based Routing (PBR), on MX Series routers (AFT), using common deployment scenarios to illustrate configuration methods. Introduction ...
Packet Buffer Architecture on QFX5K-Series switches and various buffer tuning options available on these platforms to maximize the traffic burst absorption. Overview On QFX5K platforms all ...
Example settings for connecting a VPN from the native IKEv2 client on Android 13+ to a Juniper SRX firewall. Due to the client's nature, use cases may include basic remote access and embedded/IoT scenarios ...
Migrating from a multi-area OSPF with LDP to SR-MPLS is a transition that can be achieved with ease, provided you have a clear understanding of the process and the options available. There are various ...
Junos 25.4R1 enhances Layer 2 Protocol Tunneling in VXLAN tunnels and traditional VLANs by introducing support for more protocols, allowing MACsec to traverse Layer 2 networks. Overview Media Access ...
Juniper BNG CUPS (Control and User Plane Separation) Architecture supports the Broadband Forum TR-459 Issue 2 and 3 use cases. This blog announces the CUPS Controller deployment options, specifically the ...
It’s all built into Windows. Leverage Windows PowerShell to a utomate Juniper Apstra without installing PowerShell as a language or any libraries (like the HTTP client library). You can ...
Junos OS 23.4R1 introduces Segment Routing Tactical Traffic Engineering (SR-TTE), a unique and innovative solution designed to address temporary network congestion by dynamically adjusting traffic flows ...
In this short post, we’ll look at configuring the SRX for 6-to-4 NAT (NAT64) when using IPv6-only clients with an external DNS64 server. We’ll also quickly examine how the mechanism to dynamically perform ...
A brief overview of the challenges faced in next-generation networking and data communication equipment using older Intermediate Bus Architecture (IBA) and a description of a forward-looking Power Delivery ...
Describes the ability of the Juniper SRX, in conjunction with the CloudATP service, to enforce DNS query blocking through an API-driven, multi-tenant approach. Each tenant has its own virtual router, ingress ...
Explore another use case of the Utility MIB feature [1] in Junos and EVO. We previously discussed this feature in a separate Techpost [2] in the context of the SRX platform. Today, we’ll focus on its application ...
In this post, we’ll take a technical dive into Multi-Node High Availability (MNHA) on Juniper’s SRX platforms – a flexible approach to providing redundancy on stateful network security devices. Introduction ...
How Paragon Automation (PA) automates workflow steps in provisioning L3VPN/EVPN/L2Circuit service based on declarative intent. This article is written by Masagung Nugroho and Henry Cheung. Introduction ...
A detailed description of the latest MX10000 Series new line card, offering a mix of QSFP-DD and SFP-DD ports, and powered by three Trio 6 Forwarding ASICs. Article written by Eswaran Srinivasan, completed ...
Juniper’s Converged Optical Routing Architecture – Unamplified Links. Explore the solution for High-Capacity Transport using 400G OpenZR+ Optics. Introduction This TechPost will cover configurations, ...

SRv6 Observability

How can we monitor the SRv6 data plane, and collect statistics on the SRv6 SRH and tunnels with IPFIX option 315 / IMON? Introduction At Juniper, we have observed increasing customer interest ...
Junos configuration details and KPIs of a real-life SRX4600 CGN deployment for an operator serving fixed customers. The SRX has been used as a Carrier Grade NAT (CGN) or mobile Gi/SGi firewall since ...
Leak remote L3VPN routes to the global internet table or other VRFs is now possible with the introduction of the vpn-global-import feature coming in Junos 24.2. Introduction Junos OS 24.2 introduces ...

Trio 6 Packet Walkthrough

A transit packet walkthrough inside an MX Series Trio 6 ASIC, with all the internal details on the different memory and components involved in the process. This article has ...
An innovative filtering solution for IPv4 traffic on MX Series, developed to handle five tuples matching criteria at scale. The MX platform is one of the most powerful routers on the market for packet ...

From QFX5100 to QFX5120

Explore the software and hardware differences you will encounter regarding switch connectivity when transitioning from the end-of-life QFX5100-48S and QFX5100-48T switches to the replacement QFX5120-48T ...
Discover how to implement micro-segmentation in your data center using Juniper Apstra and VXLAN Group-Based Policy. This comprehensive guide walks you through the process of deploying fine-grained security ...

BIER Overlay

The series is composed of the following posts: Introduction to BIER and BIER Underlay BIER Table Lookup BIER Overlay (present article) In this TechPost, we talk in deeper detail ...
A secure virtual cell site router (CSR + SecGW) functionality using Juniper Cloud Native Router or JCNR and Containerized SRX or cSRX so that customers and readers can easily replicate this in their lab ...

BIER Table Lookup

Second part of the 3-article series on BIER, detailing how is performed the lookup in the different BIER Tables. The series is composed of the following posts: Introduction to BIER and BIER ...
An example of SRX AutoVPN functionality with Pre-Shared Keys in 3rd party mode; specifically with Linux/strongSwan spokes. While PKI-based AutoVPN in proprietary and interoperable modes has been prevalent ...

BGP Minimum ECMP

BGP Minimum ECMP is a new feature aiming at improving resiliency within DC networks. This article has been co-written by Himanshu Tambakuwala and Sanoop Ranjan. Introduction ...
A new innovative feature called Selective DLB (Dynamic Load Balancing), improving RDMA traffic ECMP. This article has been co-written by Sanoop Ranjan and Himanshu Tambakuwala. ...
First part of the 3-article series on BIER, discussing fundamental concepts and BIER underlay. The series is composed of the following posts: Introduction to BIER and BIER Underlay (present ...
A primer/survey for networking and cyber security enthusiasts interested in the evolution of this field. This article was initially published on LinkedIn: https://www.linkedin.com/pulse/evolution-network-security-survey-sharada-yeluri-cwglc ...

MAP-T with Junos

Junos OS 23.4R1 introduces Mapping of Address and Port using Translation (MAP-T) as an adaptive service on Juniper MX Series routers equipped with Trio Silicon. MAP-T is a stateless NAT64-based solution ...
Efficient stateless load-balancing on Trio-based routers, offering optimal performance and reliability. Introduction Junos OS 24.2 introduces an innovative feature on the Juniper ...
BGP Route-Reflector is part of many networks, serving PE routers with reachability information. For this critical role, it’s important to have a robust and feature-rich software, able to serve route updates ...

Flexible Memory in Express5

Express5 fungible shared memory architecture provides the foundation for a flexible memory scheme which increases scale and efficiency of memory utilization. Introduction Typically, a fixed pipeline ...
PTX10002-36QDD is the first router equipped with the new Juniper Express5 packet forwarding engine, a new deep-buffer 28.8Tbps package introducing a lot of innovations and improvements compared to its ...
Another innovation for CUPS that enables unified Address Pool Management across CUPS controller(s) and Integrated BNGs. This use case simplifies the service provider operations and cost optimizes the public ...
A Juniper BNG CUPS use-case that combines Smart Subscriber Load Balancing and High Availability Hot or Warm Standby across a group of User Planes based on Broadband Forum TR-459 Issue 2. With this innovation, ...
A practical yet simple demonstration of the SRX EVPN/VXLAN Type 5 ip-prefix-routes feature and related firewall policy processing across multiple tenants, including an example of communication between ...
A Juniper BNG CUPS use-case that enables hitless maintenance for the user planes based on Broadband Forum TR-459 Issue 2. It improves the subscriber experience and optimizes the service provide operations ...
The BGP Link-Bandwidth extension introduces an improvement to the BGP multipath, providing the ability to convey port speeds and propagate this information across network devices. Note: the new features ...
Juniper BNG CUPS (Control and User Plane Separation) is an emerging broadband architecture for control plane and user plane separation compliant with Broadband Forum TR-459 Issue 2. It dramatically improves ...
Introducing our latest Juniper Validated Design (JVD), addressing Metro Ethernet Business Services (EBS) with Juniper MX Series, ACX Series, and PTX Series platforms. In this profile, we’ll deliver over ...
BIER Interoperability testing verified between PTX10002-36QDD and other vendors during the EANTC 2024. Introduction BIER – Bit Index Explicit Replication provides a multicast ...
High-level functionality description of BIER as MVPN provider tunnels in the upcoming release of PTX Express 5. Introduction In Cheers! Have a BIER , we explained how BIER [RFC8279] works ...
What does differentiate the ACX7024X from the ACX7024 devices? In this short article, we will explain the differences and the motivation behind the creation of this new router. Introduction ...
Using Juniper vSRX on hardware with constrained resources, typically a mini-PC serving as flexible Internet gateway. Those are lately very popular due to low footprint yet with capabilities making them ...

SRv6 in PTX Express 5

PTX Express 5 ASIC has full support for SRv6 with up to 8 carrier segment identifiers (SIDs) in a packet. That translates to 48 micro-SIDs (uSIDs), enough to pass a packet around the world! Following is ...
Express5 has leap frogged in terms of Route scale, thanks to a novel approach in implementing the route table memory. This article is part of a series of publications ...
Filter in Express5 supports Flex Key match on any field in the first 128 bytes of the packet. Using software defined templates, firewall term matches are done using flex-key construction. This can be used ...
High-level overview of packet processing, exploring the evolution of throughput demands for these processing units, and discussing various methods employed to execute these functions within networking ...
Introduction In this article, we’ll present a new open-source tool called OpenJTS (Juniper Telemetry Stack). Designed for effortless adoption, this all-in-one tool demystifies gRPC/gNMI Telemetry ...
In high multi-tenant environments such as Service Providers, Hosting Providers, or just large enterprises, having to deal with multiple internal customers, efficient utilization of infrastructure is top ...
The new Juniper PTX10002-36QDD is here. It’s our first 800GigabitEthernet, deep-buffer, high-scale, router in the market, powered by Express 5. And we are very excited to share some details about this ...

Express 5 Overview

Express 5 is Juniper's new ASIC for service providers and cloud networks, delivering 2x power efficiency, enhanced traffic insights, hardware-based sampling, value-added services, and supporting high-speed, ...
With network flow monitoring, you can troubleshoot application issues in a DC fabric with distributed, cloud-native, virtualized, and containerized workloads. Introduction In modern networks, network ...
The ACX7000 family is growing fast. Today, we try a different approach to present this update of the ACX7000 portfolio. Introduction Trying to present each product ...
A Deepdive on sFlow and IMON/IPFIX315 on MX Routers. ...
A minimalistic tool for bulk config changes in the scale-out system beyond options available in Auto-FBF CLI Introduction This TechPost is continuation of “ Scale-Out Security Services with Auto-FBF ...
Details of LLM inference workflow, how it differs from training, the many hardware/software optimizations that go into making inference efficient, and the Inference hardware landscape. Article initially ...
It is often stated that most network outages occur as a result of changes having been made to the system. There have been many notable examples of this, and they have all affected us. Precise management ...
Although good old Junos SNMP MIB is very rich on every platform, occasionally some specific stats could have been handy. For example, number of sessions per IP protocol on SRX. No problem! Blast from the ...

JCNR for Equinix Metal

JCNR brings a lot of value by providing seamless connectivity between workloads across locations, public cloud boundaries, and workload form-factor, by providing full router functionality. Author ...
Focusing on SRX firewall – the scaled out device - operational aspects in terms of removing device from service and bringing it back. Introduction This TechPost article is continuation of “Scale-Out ...
An overview of the different hardware profiles available on the ACX7000 Sries, and what is changing in the latest Junos releases. Introduction The ACX7000 routers are powered by Broadcom ...
Juniper Apstra supports Network Operating System (NOS) Upgrades for managed switches, allowing you to upgrade devices directly from the Apstra Server within a consistent workflow process. This ...

Packets Lost in Transit?

Troubleshooting transit packet drops is not the easiest task for a network engineer. Sometimes, packets can be dropped in the forwarding ASIC at a very early stage, for example because of the wrong destination ...
GPU cluster scale, model partitioning, and traffic patterns between the GPUs for training workloads. Article initially published on LinkedIn at: https://www.linkedin.com/pulse/gpu-fabrics-genai-workloads-sharada-yeluri-j8ghc/ ...
Unfortunately, black-holes sometimes occur in networks – packets disappear without trace for no apparent reason. Often the first symptom is when customers of the network complain about poor performance. ...
Strategies to enhance the scale and performance of routing, aiming for faster convergence, improved stability, and optimized hardware utilization. Disclaimer: The RIB and FIB scales discussed ...
The benefits and versatility that Juniper brings with the PTP G.8275.1.ENH profile and the reasons behind its enhancements. Introduction This blog will ...
How Apstra clustering works with respect to Off-box agents and Probe processing units Introduction The Juniper Apstra standard implementation model is based on one virtual machine, a deployment model ...
The different thermal management solutions for cooling the high-power components in electronic systems (HPCs/Servers and network equipment), trends, and the future. Article initially published on ...

BNG on MPC10E

Starting in the 22.4R1 JUNOS release, MPC10E supports BNG subscriber access connections. Introduction Both MPC10E line card versions support subscriber management. MPC10E-10C has 2 Trio-5 PFEs, supporting ...
The Juniper Apstra SDK, written in Golang, integrates Apstra into the Terraform ecosystem, enabling an Apstra specific provider. Introduction This article explains the automated deployment of a 3-stage ...
Solving the low entropy problem of the AI/ML training workloads in the Ethernet Fabrics. Guess how many active IP flows a single GPU normally sends while synchronizing training data with other GPUs? ...

MX304 FIB Install Rate

MX304 installs the full Internet tables at 47,000 routes per second, and we will show you how we are testing it. Introduction If you test the MX304 in the lab in front of route/traffic generator, ...

Using Apstra Drain Mode

Apstra supports Drain Mode for managed switches, allowing the operator to gracefully drain traffic from devices without simply shutting down the BGP neighbor relationships. This article is derived ...
How Junos EVO implements the OpenConfig “platform” data model to expose many indicators/counters related to environmental data. Introduction Recently, we covered the PTX power optimization features ...
A description of the different configurations that can be rendered based on the state of the devices in Apstra. This article is derived from original work created by ...
Using Tags, Property Sets, and Jinja to simplify Apstra Freeform Day-2 Configuration. Introduction Alongside the Juniper ...
How vJunos-switch is deployed as a VM, packaged within a container, on a bare metal server using the open source network emulation tool Containerlab. We’ll start with instructions on how to install ...
From the basic constructs Freeform uses – Tags, Device Contexts, Property Sets, and Config Templates – to creating a simple Freeform blueprint, to a number of advanced case studies. Introduction ...
Optimizing Failover Convergence for Enhanced Network Resilience with BGP PIC implementation in JUNOS. Introduction This blog will delve into multiple Juniper features to enhance failover convergence, ...

Using Apstra Policy Assurance

Apstra manages network security and workload isolation via the Policy Assurance feature. This feature allows you to create policies that are decoupled from enforcement mechanisms and will enable the specification ...
A look at the semiconductor industry evolution, the inflection points, and how packaging and interconnect technologies evolved to make chiplets a viable alternative to monolithic dies to keep Moore's law ...
A detailed configuration example that shows how to dual-home data center servers to Juniper leaf switches by using EZ-LAG, a simplified version on ESI-LAG made for customers looking for a smooth transition ...
As a revolutionary multicast technology that allows efficient replication without requiring per-tree states in the network, Bit Index Explicit Replication (BIER) is the perfect solution for multicast in ...

Apstra Device Replacement

An essential operation in a working data center network would be the need to replace a device that has either failed or just needs to be re-allocated/reused for other purposes. This document describes ...
A brief introduction to the LLMs, the hardware challenges in training these models, and how the GPU and networking industry is evolving to optimize the hardware for the training workloads. Article ...
Illustration of an IP/VPN MPLS network provisioned and operated with Apstra Freeform. Introduction Juniper Apstra is our specialized intent-based networking ...
Juniper enhanced the initial DDoS protection feature with Suspicious Control Flow Detection (SCFD). It provides deeper analysis within a given protocol or packet-type: a s olution that addresses the need ...
How much traffic coming from Internet reach my different POPs? Can I monitor in real time the traffic coming from the “TOP Internet Talkers”? Is there an easy way to count traffic entering and leaving ...
How we can significantly reduce the power usage of the ACX7000 routers with basic configuration and simple best-practices. Introduction Power saving and carbon footprint reduction are top of mind ...

Apstra Configlets

Configlets allow the administrator to create custom configuration templates and automatically deploy them to devices based on intent. This document was developed from ...
Guide to the EVPN VXLAN based Optimised Inter-subnet Multicast (OISM) on Express4 based PTX10k platforms. This document is co-written by Ramdas Machat and Abdul ...
Did you know: numerous built-in functionalities with Junos-EVO are enabled by default and help reducing the power usage and carbon foot-print of your PTX routers? First we’ll try to briefly characterize ...

BGP CT Use-Cases

Key applications of BGP Classful Transport (BGP-CT), including path-diversity across multiple ASes, multi-AS paths that take into account sovereignty constraints, and paths that achieve the minimum end-to-end ...
The Audit trail feature tracks a user’s actions while using Apstra and can be very useful in investigating general usage, network outages, and possible suspicious activity. Introduction Juniper Apstra ...
An alternative approach to scale-out of security services, specifically for CGN and Gi Firewall deployments called auto-fbf. Technologies in scope are MX, on-box automation and SRX/vSRX as scaled-out elements ...
The capabilities of a specific switch hardware model are defined in the Device Profile and linked to the logical representation of the switch. Linking these together allows Apstra to build out the topology ...
Juniper Apstra’s fundamental purpose is to minimize operational costs and maximize the speed of network operations by furnishing predefined, rigorously validated reference designs. The reference design ...
All you need to know on Centralized Deterministic NAT configuration, scale and performance on MX routers. Introduction Internet Assigned Numbers ...
The Juniper Off Box Security Services Solution defines a common security services complex to be used in conjunction with MX Provider Edge (PE) deployments for Service Providers and Enterprises which leverage ...
Another use case for link slicing: instead of data plane identifiers, control plane identifiers are used. Control plane protocols exchange the information that allows to classify packets to link slices. ...
Let's test the real power saving on PTX platforms achieved when shutting down used and unused Packet Forwarding Engine (PFE). Introduction Power efficiency is key in today’s ever-growing Service ...
Solution to secure BGP Option B against MPLS label spoofing on MX Series routers. Introduction Solution to secure BGP Option B against ...
A detailed review of the various components inside a high-end router and how they contribute to overall power consumption. Article initially published on Linked here . Introduction The last ...
Timing and synchronization requirements and capabilities are continually evolved to drive the ultra-low latency, mission critical and advanced radio applications for 5G and beyond. Satisfying the new enhanced ...
BGP FlowSpec is one of the mechanisms that allows a network to protect itself against DDoS attacks. A common mitigation tactic is to redirect malicious traffic to a scrubbing center for further analysis. ...
Traffic mirroring is a useful method for debugging traffic patterns. The ACX7000 family of products supports both local port mirroring and ERSPAN. This article describes how to utilize these functionalities. ...
BGP CT interoperability tests between Junos, Junos Evo and FreeRTR routers conducted in Berlin during the EANTC2023 event in March 2023. Introduction The BGP Classful Transport tests have ...
The guaranteed link slicing feature, using MPLS and SRv6 as underlay transport. Link slicing is a way to share physical bandwidth on links between multiple tenants, ...
vJunos-switch and vJunosEvolved deployed on EVE-NG and integrated with Juniper Apstra to build a complete Data Center fabric. Article co-written with Aninda Chatterjee and ...

vJunos Deployment on KVM

A comprehensive user guide on how to successfully deploy and use vJunos-switch and vJunosEvolved on KVM (one of the most popular virtualized environments in the community, alongside EVE-NG and GNS3). ...
Olé, Olé, Overlays! Welcome back to the validation design series and today is all about that overlay! Introduction The previous blog Building Border Agnostic Architectures with Seamless ...
Broadband services are evolving with cloud streaming and advanced video, a new BNG QOS model for subscribers is required to optimise latency, throughput and scale. This techpost introduces a new subscriber ...

MX304 Deepdive

A detailed review of the latest router of the MX Series. Powered by Trio6 PFE, it offers unique form-factor and modularity, with interface spanning from 1GE to 400GE and control-plane redundancy. Introduction ...

MPC10E Deepdive

A detailed view of the MPC10E line cards used in MX240, MX480 and MX480. MX240/480/960 ...
Current practices and future trends on buffers in networking chips. Article initially published on LinkedIn . ...
Third part of the Juniper Validated Design series on basic Mobile Backhauling, with a focus on Seamless MPLS and BGP-LU. Introduction In the third Juniper Validated Design (JVD) article on the Mobile ...
Layer 3 Virtual Private Network Inter-AS option using SRv6 as underlay transport on MX and ACX7000 routers. Introduction This is the 5th blog post ...
Mapping modern and legacy services to colored MPLS paths, achieving business differentiation. Introduction People say there are no greenfield service providers (SPs). Some networks grow organically, ...
We validate EVPN E-LAN on Express4-based platforms playing the role of PE. In this article, we will describe the various approaches, the configurations and the instance scaling. Introduction In ...
Basic concepts of Forwarding Information Base (FIB), the longest prefix match (LPM) for IP forwarding, and how its implementation has evolved over time. The emphasis is on various hardware implementation ...
Let's test EVPN ELINE/VPWS on Express4-based platforms playing the role of PE. In this article, we will describe the various approaches, the configurations and the instance scaling. Introduction ...
PTX10001-36MR installs the Internet routes at more than 27,000 routes per second, and we will show you how we are testing it. Introduction PTX10001-36MR supports an internet route install rate of ...
JUNOS 22.3 introduced several changes in the SRv6 infrastructure, this article covers them in details. Introduction This is the 4th blog in ...
What a true IBN system is? How relational and graph databases are different? And why graph databases are ideal for network infrastructure? Introduction This post will look at what Intent-Based ...
We verify ACX7000 platforms support 700,000 MAC addresses with a learning rate of 14,000 entries per second. Introduction This is the sixth ...
Let's verify we can support 8,000 VPLS instances in the ACX7000 products with 640,000 MAC addresses. Introduction This is the fifth article in the ACX7k Metro Validation Series: ...
ACX7000 platform is tested with 8,000 Layer2 VPN Routing-instances for 99.9% line rate traffic. Introduction This is the third article ...

ACX7509 Deepdive

The first centralized platform of the ACX7000 family. Based on a modular design, it offers control plane and forwarding plane redundancy with port density spanning from 1GE to 400GE, in just 5RU. ...
ACX7000 platform has been tested successfully with 4,000 Layer3 VPN Routing-instances with BGPv4, BGPv6, OSPF, OSPFv3, ISISv4, ISISv6, Static-v4, Static-v6 as CE-PE protocols and with a total of 1.35M ...
Junos EVPN-VPWS feature supports 8,000 instances with 4,000 VLAN-UnAware and 4,000 VLAN-Aware Service Types on ACX7000 Platforms. Introduction This is the second article ...
Techniques, configurations and best practices for migrating from legacy business services to EVPN on MX Routers. Introduction Service providers started adopting ...
JUNOS unified way of bringing up EVPN E-LAN using mac-vrf instance type supporting 6,000 instances on ACX7000 with 642,000 MAC scale. Introduction This article is the first in a ...
SiPh (Silicon Photonics) is no longer SciFi (Science Fiction). Let's see where is the industry today with co-packaged optics... Article initially published on ...
Discover how BGP RIB Sharding can help improve routing performance and scale in JUNOS. Introduction Border Gateway Protocol (BGP) ...
Product manager’s description of the PTX10001-36MR router. Product characteristics, port types and supported port combinations, architecture and the applications of the router are all outlined in the article. ...

Sampling Evolution

Are the flow caches effective to support IPFIX implementations today? What happens if we stop using them? Learn about the new IPFIX implementation in Juniper PTX and ACX7000 routers. Introduction ...
The PTX10001-36MR is well-known for its core, peering and DCI capabilities, but it's also a very performant L2 aggregation device. In this article, we will test and demonstrate L2 virtual circuits scale ...
Let's discuss the multi-domain SRv6 network together with the concept of SRv6 locator summarization. SRv6 locator summarization allows for large-scale, multi-domain deployments with SRv6. Introduction ...
Did you know the internet table can be compressed significantly? We explain how the PTX and ACX7000 routers running Junos EVO are currently implementing FIB compression. TL;DR FIB Compression has ...
A standard-based approach to placing MPLS-based services with path constraints across multiple networks. Have you tried bringing up inter-domain ...

ACX7024 Deepdive

Everything about the new addition to the Cloud-Metro family, the ACX7024. A 1-RU router, with 360Gbps forwarding capacity. Introduction ACX7024 is 1RU Ethernet-only router with 360Gbps ...
Second profile of the Juniper Validated Design series on basic Mobile Backhauling, with a focus on LDP-signalled MPLS and OSPF IGP. Introduction In this section, we’ll walk through essential components ...
How does the Juniper ACX7100-32C router handle a fully loaded 400GE ZR and 100GE ZR4, long reach, high power coherent optics configuration? Introduction In this article, I want to talk about long ...
The gap between processor and memory performance and density continued to increase - this is often referred to as the "Memory Wall". Article initially published on LinkedIn. ...

ACX7100 Deepdive

In this post, you’ll learn everything about the first two Juniper Cloud-Metro devices: ACX7100-32C and ACX7100-48L. Article co-written by Nicolas Fevrier ...

L3VPN over SRv6

How unicast IPv4/IPv6 within L3VPN VRFs are implemented with Segment Routing v6 (SRv6) as underlaying transport technology. Introduction In the first blog ...
LC480 is a 48 port 1G/10G line card supporting Business Services(L2/L3) with rich OAM features, Broadband subscriber at scale, H-QoS, high filter scale and deep buffers. It’s a perfect complement to the ...
To understand the life of a packet in an ACX7000 Series router, you first need to understand the idea behind Virtual Output Queues. Introduction Many Network Processing Unit (NPU) architectures ...
You want to install a TIG (Telegraf, InfluxDB, Grafana) stack directly in your lab router? Most network engineers have heard of using streaming telemetry in modern networks. Trying it in the lab often ...
The world of CDN gateways is usually built around L2 domains and IRB, where a switch interconnects CDN servers, hosts and the L3 gateway. We propose a solution directly associating hosts and CDN servers ...
Networking chips (also called network processors) started getting momentum in the mid-90s, with Juniper at the forefront of the revolution, when we figured out how to do the longest prefix match lookups ...
This series of articles provides a guide to understanding the capabilities and operating principles behind the Filter block in the Express silicon architecture, deep insights into its mighty power and ...
SRv6 (Segment Routing version 6) is a version of segment routing based on IPv6 tunneling mechanism, rather than on MPLS (MultiProtocol Label Switching) underlay. Therefore, with SRv6 underlying transport ...
All you always wanted to know of the newest MX10k line card powered by Trio 6 PFE and optimised for 100GE and 400GE requirements. Introduction Juniper has established itself as a 400G leader with ...
Summary of the Juniper Validated Design series dedicated to 5G xHaul reference architecture (Fronthaul, Midhaul, and Backhaul network segments). Welcome to the Juniper Validated Design (JVD) series. ...
Short introduction to the validation articles. What you should expect from these blog posts, unit testing or extracts of the Juniper Validated Designs. Article co-written by Kevin Brown and Nicolas ...
First article “Behind The Scene” on the building of the ACX7000 Series, starting with the heart of the router: the Packet Forwarding Engine. Introduction With the introduction of the ACX7100 routers ...