Select a Techpost
Platforms / Line Cards Deepdive
Introducing the QFX5140
The HPE Juniper Networking QFX5140 is a 1RU fixed-configuration data center switch built on the Broadcom Trident 5 ASIC, delivering 16 Tbps of switching capacity in a single rack unit. It combines 24x 400GbE QSFP112 ports with native 112G PAM4 SerDes and 8x 800GbE OSFP800 ports, breaking out to up to 160x 100GbE interfaces.
By Nicole Henry
Security
HPE SRX-SSE Link
This TechPost provides an example of how to connect unmanaged users and systems behind an HPE SRX Firewall to HPE Security Services Edge (SSE) for security policy enforcement in the cloud. This facilitates a common cloud based policy for these systems as well as system with the SSE agent installed.
By Karel Hendrych
Scale and Convergence Tests
Long-Distance Lossless Scale-Across
Artificial Intelligence (AI) and Machine Learning (ML) training clusters can easily outgrow a single data hall. Power and cooling limits decide how many AI accelerators (XPUs) can be hosted in one building, and once that limit is reached, then the clusters need to be deployed across data halls.
By Kashif Nawaz
Security
Secure Active/Active Multivendor Fabrics with MNHA
Modern data center IP fabrics are built on VXLAN and EVPN. The technology is genuinely powerful: a decoupled underlay and overlay with multi-protocol BGP, Type-2 and Type-5 routes, distributed anycast gateways, etc.
By James Rathbun
Security
VXLANsec. Securing Modern Data Centers, One Tunnel at a Time
Modern data center networks are increasingly built around overlay technologies that enable scalability, workload mobility, and efficient network segmentation.
By Riti Sharma
Platforms / Line Cards Deepdive
Control and Data Plane Traffic Capture on QFX Switches
Packet capture on QFX switches enables visibility into control-plane and data-plane traffic for efficient troubleshooting, traffic analysis, and network diagnostics.
By Ridha Hamidi
Routing
Migrating Colored Resolution from inetcolor to Classful Transport
Junos is moving colored transport resolution away from service-family-specific inetcolor/inet6color mechanisms and toward classful transports (CT), where transport intent is modeled as transport classes, per-class transport RIBs, and configurable resolution schemes for service-to-transport mapping.
By Anton Elita
Platforms / Line Cards Deepdive
ORv3 Compliant QFX Series Switches
HPE–Juniper Networks QFX Series switch platforms support ORv3-compliant data center deployments, aligning with Open Compute Project (OCP) Open Rack Version 3 (ORv3) specifications. Compliance is achieved through mechanical and electrical adaptations to the QFX platform, enabling integration into ORv3 rack infrastructure.
By Ridha Hamidi
Routing
AI-Driven Brownfield Migration to Juniper Routing Director
Network service providers don't build their networks one router at a time — they scale them. The customer we worked with during this Professional Services engagement had hundreds of PE routers and, on top of them, thousands of VPN service instances.
By Weiguo Lu
Platforms / Line Cards Deepdive
WAN MACsec Inline Throughput Testing on MX Series
This Tech-Post validates WAN-MACSec over WAN on MX Trio 6 platforms, focusing on session scale and forwarding throughput under EAPOL/MKA operation. It provides configuration, verification commands, and practical observations from a 200-session testbed.
By Amin Ehtesham
Routing
Secure BGP with ASPA Preventing and fixing route leaks
BGP runs on trust, and route leaks and hijacks are what happen when that trust is misplaced.
By Anton Elita
Security
From SRX Chassis Cluster to MNHA Configurations side by side
After the techpost "SRX clustering: from Chassis Cluster to MultiNode High Availability", let's deep dive into their respective configuration side by side. Below a simplified diagram showing the same architecture with an SRX pair segmenting 2 networks:
By Laurent Paumelle
Routing
BNG Chassis Redundancy with DHCP Active Lease Query and EVPN VPWS
When a Broadband Network Gateway goes down, thousands of subscribers lose connectivity. Traditional BNG redundancy solutions often result in subscriber session loss, requiring DHCP reinitialization and leading to service disruption.
By Sathish Eruvala
AI for Networking for AI
Connecting AI The Network Behind Every Inference
When people think about Artificial Intelligence (AI), they usually think about models, GPUs, and applications. They picture chatbots answering questions, copilots generating content, recommendation engines personalizing experiences, or image generators creating artwork.
By Cherishma Potluri
Routing
Stitching Two Worlds IPv4 L3VPN Inter-AS (Option C) over an IPv6-Only SRv6 uSID Core
In L3VPN-over-SRv6 design, the metros and the core speak the same transport: IPv6 with Segment Routing. Production networks are rarely that tidy. Most operators run large, mature SR-MPLS metros and want to slide a modern SRv6 core underneath them: without a flag day and without rebuilding the metros.
By Pankaj Kumar
Various Other Topics
Precision Timing in Modern Data Center
With the rapid transition from traditional workloads to AI applications, data centers are undergoing a fundamental architectural change. Traditional compute-centric systems are unable to match the requirements of modern AI applications that need huge data mobility, parallel processing, and ultra-low latency.
By Ssatheesh
AI for Networking for AI
Next Generation Port Extender (NGPE) The Right Interface Speed on the Right Box, for the AI Era
The satellites' front-panel ports appear on the aggregation device as if they were native line-card ports. Add a satellite, and you've added 1G/10G ports: not another router to manage.
By Pankaj Kumar
Platforms / Line Cards Deepdive
Industry First 1.6T Liquid Cooled Switch: QFX5250-64OE-L
Extending HPE Juniper's innovation leadership from 800G to 1.6TbE AI data center fabrics.
By Riti Sharma
Various Other Topics
250 articles
Techpost reaches 250 published articles: a curated, category-by-category index of every post so far, from platform deepdives to routing, security, Apstra, AI networking and more.
By Nicolas Fevrier
Power Topics
Power Observability
Your routers and switches display power usage counters, but what are they representing and can you trust them? Let's try to answer these questions today.
By Nicolas Fevrier
Security
SRX Multi-Node High Availability (MNHA) with VRRP
This TechPost describes an alternative solution to the native SRX Multi Node High Availability (MNHA) Switching/Hybrid Layer 2 (L2) Virtual IP address (VIP) mechanisms using Virtual Router Redundancy Protocol (VRRP). MNHA combined with VRRP can offer more flexibility and speed up convergence in some failure scenarios.
By Karel Hendrych
AI for Networking for AI
MCP w/ context file part 6
Sixth and last part of the Series on the Context-Files and JMCP, covering hybrid LLM and Python Architecture.
By Christian Graf
Routing
SRv6 Explicit LSPs
There are several approaches to deploying SRv6 Traffic Engineering (TE) tunnels (LSPs), depending on the operational and automation requirements of the network.
By Ricardo Dominguez
Platforms / Line Cards Deepdive
PTX12008 Power Distribution and Optimization
Learn how the PTX12008 optimizes power consumption through automatic and operator-controlled mechanisms such as adaptive fan management, unused port shutdown, selective PFE offlining, MACsec clock gating, and dynamic fabric or line card power control to improve energy efficiency in high-capacity networks.
By Gurmeet Singh
AI for Networking for AI
Context-File Redis and High-Performance Storage
Fifth part of the Series on the Context-Files and JMCP, covering Redis and high-performance Storage.
By Christian Graf
Platforms / Line Cards Deepdive
Navigating the Front Panel Display
Let's explore the LCD module of the PTX12000 chassis. In this article, we will explain how it provides front-panel, touch-based, read-only monitoring of system health, FRU status, alarms, ports, and FPC information for simplified operational visibility and troubleshooting.
By Nagaraj Suresh
Security
Securing IPVPN Connectivity on Juniper MX Using Inline IPsec
This article provides an example of using the inline IPsec function available on Trio-6 based MX routers to secure IPVPN traffic over an MPLS core. After stepping through the configuration details of IPsec, verification is performed to validate proper operation and to reinforce the reader's understanding of the implementation.
By Victor Ganjian
Platforms / Line Cards Deepdive
Self Healing and Recovery Mechanisms For PTX12008
Modern core networks are expected to operate nonstop, even when components fail. In high-capacity chassis, fabric resiliency is fundamental requirement. This blog will describe in details the self-healing and recovery mechanisms built into the PTX12008 switching fabric.
By Abhishek A Jain
Various Other Topics
DHCP on MNHA: Back to Basics
Multi-Node High Availability (MNHA) is increasingly common as an alternative to chassis cluster. One operational question that surfaces quickly in MNHA deployments is Dynamic Host Configuration Protocol (DHCP). As of Junos 25.4R1, each node runs an independent DHCP process with no lease database synchronization between them.
By James Rathbun
Security
SRX MPLS in Flow - Part II
The Junos 25.4R1 release expanded the list of SRX platforms supporting MPLS L3 VPN to include the SRX4600 and SRX4700. This brief tech post extends the previous 'SRX MPLS in Flow' article by presenting performance test of the SRX4600 using the 25.4R1 VRF-to-zone-mapping--based security policies.
By Karel Hendrych
Routing
Testing BGP Roles (RFC 9234) with the JMCP Server
LLMs have improved significantly over the last few months with the advent of reasoning models. We are now at the point where a general-purpose LLM, in conjunction with the Junos MCP server, is capable of doing sizable chunks of work on a network triggered by a single prompt, saving the user significant amounts of time.
By Julian Lucek
AI for Networking for AI
Context Files: File Management and Data Collection Strategies
Fourth part of the Series on the Context-Files and JMCP, covering tokens, data formats, and memory management.
By Christian Graf
Routing
INET.0 -- What? MNHA, IPSec and Multiple Routing Instances
There is a lot of good documentation available on designing and implementing MultiNode High Availability (MNHA) and Virtual Private Networks (VPNs) on SRXs - even AI generated configuration snippets that might lead a novice or experience professional astray.
By James Rathbun
Platforms / Line Cards Deepdive
Deepdive in the Fabric Topology
Let's describes the PTX12008 chassis fabric topology and the bandwidth plumbing between Line Cards (LCs) and Switch Interface Boards (SIBs).
By Rahul Kulkarni
Platforms / Line Cards Deepdive
Fabric Design and Redundancy
Fabrics are considered internal components of the router and if one fails, there should be no performance degradation. This was the expectation for many years. But supporting it is not practical anymore. It is now time to reset the expectation, look at the problem again and address it differently.
By Dmitry Shokarev
Apstra
Implementing RBAC for Juniper Apstra Using ClearPass TACACS+ Server
How to integrate Juniper Apstra with Aruba ClearPass using TACACS+ to centralize authentication and implement role-based access control (RBAC)?
By Victor Ganjian
AI for Networking for AI
Context File Optimization and Alerting Strategies
Third part of the Series on the Context-Files and JMCP, covering tokens, data formats, and memory management.
By Christian Graf
Platforms / Line Cards Deepdive
Introducing the PTX10002-60MR
The Juniper PTX10002-60MR is a 2RU router built on the Express 5 ASIC, delivering up to 14.4 Tbps of forwarding capacity. It offers dense mix of 12x 800GE QSFP112-DD and 48x 100GE QSFP28 ports, native ZR/ZR+ support, and is perfect for space- and power-constrained core, WAN, and AI-driven data-center deployments.
By Santo K
AI for Networking for AI
Context-File Basics: Tokens, Data Formats, and Memory Management
Second part of the Series on the Context-Files and JMCP, covering tokens, data formats, and memory management.
By Christian Graf
Platforms / Line Cards Deepdive
DCI Edge for AI Front End Clusters with Juniper PTX
How Juniper PTX routers consolidate tunnel aggregation, DCI, and secure internet edge roles to simplify large-scale AI front-end networking. In this article, we will detail design choices and deployment considerations for using PTX at the DCI edge to provide scalable multi-tenant connectivity for thousands of DPU-based AI nodes.
By Kashif Nawaz
Platforms / Line Cards Deepdive
ACX 7020 Routers Deepdive
The ACX7020 is a HPE Juniper Networking product powered by Broadcom Qumran Q2N [BCM88295] and running Junos EVO modular software architecture. It offers a mix of 16 ports 1/10GbE and 4 ports 1/10/25GbE.
By Dominique Blanchard
Security
SRX Secure Fabric Entry Point
This Tech Post aims to address multi-tenant secure Remote Access of the HPE Juniper Networking SRX firewall. A demo setup that allows for direct breakout into an EVPN/VXLAN fabric VRF, where the SRX serves as a secure, user identity-aware fabric entry point is shown.
By Karel Hendrych
Platforms / Line Cards Deepdive
Juniper PTX Routers in Front-End Network
This publication looks at the implementation of an Overlay Tunnel Gateway Solution based on Juniper PTX Series routers. Although various overlay tunnelling technologies are available e.g.
By Kashif Nawaz
AI for Networking for AI
Managing Junos Devices with Context-File and JMCP Server
An introduction to LLM-driven network automation: how Model Context Protocol (MCP) and a Context-File let today's LLMs understand and operate Junos devices through the JMCP server. Part 1 of the Context-File series.
By Christian Graf
Platforms / Line Cards Deepdive
Introducing PTX12000 Chassis
It's not every day you unveil a brand-new series product line, so it's with a lot of excitement we launched the PTX12000 modular chassis in February 2026.
By Nicolas Fevrier
AI for Networking for AI
Overlay Networking in AI Era
How overlay networking evolved from kernel vRouters to DPDK, SmartNICs and DPUs, and why DPU-offloaded tunnel processing is key to isolating concurrent AI workloads on shared infrastructure. Part 1 of a three-article series.
By Kashif Nawaz
Security
SRX clustering: from Chassis Cluster to MultiNode High Availability
A simple guide for understanding the differences between Chassis Cluster (original CC) and MultiNode High Availability (MNHA) used on Juniper SRX.
By Laurentp
Routing
State, Signaling, and the Cost of Simplified Narratives
A critical look at the narrative that Segment Routing won by eliminating RSVP-TE signaling state: what RSVP's limitations really revealed about coupling, churn and intent, and how simplified stories shape design assumptions.
By Cbarth
Routing
Enhancing Route Manipulation
Advanced Junos OS route control techniques, such as rib-groups, vpn-global-import, and rib-export, enable selective sharing, controlled leaking, and cloning of routes across different RIBs while maintaining loop prevention for complex service-provider routing scenarios.
By Moshiko Nayman
Routing
L3VPN over SRv6 with JCNR
Do you need secure, isolated multi-tenant connectivity across Kubernetes and cloud infrastructures. JCNR supports SRv6 L3VPN with micro-Segment Identifiers (uSIDs) in various SRv6 endpoint behaviors (End.DT4, End.DT6, End.DT46).
By Lavanya Kumar Ambatipudi
Platforms / Line Cards Deepdive
MX301 A Powerful Filtering Gateway
Let's use the Juniper filtering tools in a more comprehensive and realistic use case in which MX301 will serve as a filtering routing gateway to protect peering points, critical cloud platforms, or any network infrastructure that requires large-scale security.
By David Roy
Platforms / Line Cards Deepdive
MX301 High-Performance FlowSpec Without Compromise
Explore how Juniper's MX301 router, using Junos 24.4 and its Trio 6 ASIC's specialized Fast Lookup Table (FLT), accelerates BGP FlowSpec rule processing so that even large and complex FlowSpec filters can be applied without degrading throughput by offloading 5-tuple matches to hardware.
By David Roy
Platforms / Line Cards Deepdive
Inline IPSec on MX Series
Juniper adds support for inline IPsec on MX-series routers, meaning that IPsec encryption/decryption is done directly by the router's Packet Forwarding Engine (PFE) ASIC instead of by a separate service card, resulting in much higher VPN throughput and lower latency.
By Suneesh Babu
Security
SRX Dynamic IP Objects aka Feed-server
For a long time, the SRX has been able to periodically download IPv4 and IPv6 prefixes from external sources and map them to objects used in firewall policies.
By Karel Hendrych
Platforms / Line Cards Deepdive
MX301 Deepdive
Let's explore the capabilities of the Juniper Networks MX301 Universal Routing Platform, a 1RU edge router built on Trio 6 silicon that delivers up to 1.6 Tbps full-duplex throughput, supports a broad range of interface speeds from 1GE to 400GE, and integrates features like hardware-accelerated MACsec/IPsec.
By David Roy
Various Other Topics
200 Articles on TechPost
Techpost celebrates its 200th article with a complete, organized index of all posts published so far, grouped by category to help you find the right deepdive quickly.
By Nicolas Fevrier
Routing
JCNR and Topology-Independent Loop-Free Alternates (TI-LFA)
The Juniper Cloud-Native Router (JCNR) integrates modern forwarding and resilience mechanisms, specifically Segment Routing with MPLS (SR-MPLS) and Topology-Independent Loop-Free Alternate (TI-LFA), to deliver sub-50 ms failover and full coverage in cloud-scale IP/MPLS networks.
By Lavanya Kumar Ambatipudi
Routing
Mastering Local AS - Private No-prepend-global-AS mode
A detailed breakdown of the private no-prepend-gloabal-AS option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering.
By Juhie Mohan Motiani
Routing
Mastering Local AS - No-prepend-global-AS mode
A detailed breakdown of the no-prepend-global-AS option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering.
By Juhie Mohan Motiani
Routing
Mastering Local AS - Private mode
A detailed breakdown of the Private option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering.
By Juhie Mohan Motiani
Routing
Mastering Local AS - Alias mode
A detailed breakdown of the alias option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering.
By Juhie Mohan Motiani
Routing
Mastering Local AS - Default mode
A detailed breakdown of the Default option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering.
By Juhie Mohan Motiani
Security
SRX4700 100Gbps Full Duplex IPSEC tunnel
The SRX4700 100Gbps Full Duplex IPSEC tunnel TechPost demonstrates the ability of the HPE Juniper Networking flagship 1RU firewall device to encrypt 100Gbps traffic patterns from a single system, such as a server or storage device, communicating within site-to-site tunnels.
By Karel Hendrych
AI for Networking for AI
Network Automation with AI and Junos MCP Server
How AI agents, connected via the open-source Model Context Protocol (MCP) server, can simplify and standardize network automation tasks on Junos OS devices (e.g., retrieving configurations, checking device health, provisioning) with natural-language prompts.
By Victor Ganjian
Various Other Topics
Red Hat and Juniper Merge Ansible Collections
Red Hat Ansible Automation Platform and Juniper Networks each have collections of Ansible modules for managing Junos devices. We are merging Ansible's collection into the Juniper Collection to provide a single collection of modules for our customers.
By Jessica Garrison
Routing
L2 Metro Ring-Access With EVPN-ELAN
EVPN technology provides native CE direct L2 multi-homing capabilities, in either Active-Active or Active-Standby scheme. However, there might be a need for certain L2 access domains to form a ring topology around the EVPN PE endpoints.
By Aris Georgakas
Platforms / Line Cards Deepdive
Training over 50km 800GE Links with PTX Routers
Can we run distributed training between clusters located 50 km apart? How do we interconnect these sites? Do we need to tweak the collectives library and the NIC settings to run training jobs? And provision anything special on the router side?
By Dmitry Shokarev
Observability, Sampling, Telemetry, SNMP
Enhancing Synchronization Networks with Passive Port Monitoring (PPM)
In the era of 5G, CRAN, cloud-native infrastructure, and ultra-low latency applications, precise time synchronization is foundational. Juniper Networks introduces a powerful tool to elevate the visibility, accuracy, and security of synchronization networks: Passive Port Monitoring (PPM).
By Kamatchi Gopalakrishnan
Silicon / PFE / Memories
Debugging PFE exceptions on Microkernel FPCs with Natural Language and MCP
The arrival of AI in networking is transforming the way we think about operations, automation, and troubleshooting. For years, the skill set of a network engineer has been defined by the ability to configure devices, interpret logs, and script repetitive tasks.
By Pablo Sagrera Garcia
AI for Networking for AI
Reimagining Network Operations with AI
What if you had an AI partner that could help you manage your network and troubleshoot any issues, learn from them, and continuously get smarter about preventing future incidents?
By Jose Miguel Izquierdo
Routing
MAP-E
This document provides an overview of MAP-E (Mapping of Address and Port using Encapsulation), a stateless IPv4-over-IPv6 transition technology supported by Junos OS. It explains key terminology, operational components, configuration guidelines, and deployment benefits for service providers.
By Moshiko Nayman
Routing
SRv6 Micro-SID (uSID) Basics
Learn all about SRv6 micro-SIDs (uSIDs), a compressed alternative to full-length SIDs in IPv6-based segment routing and how to configure it on Juniper MX Series.
By Krzysztof Szarkowicz
Platforms / Line Cards Deepdive
Differentiate with Filters
Learn why the Trio and Express "Firewall Filters" (ACL) are truly unique in this industry.
By Nicolas Fevrier
Routing
EVPN on the Stick
EVPN-On-A-Stick offers a fresh way to build networks by merging service functions directly into the main fabric. The result is simpler operations, faster performance, and a more scalable foundation for future growth.
By Francois Lecavalier
Routing
Optimize your Network with Routing Director
Automating the MPLS and SR network with Juniper Routing Director network optimization use case.
By Masagung Nugroho
Various Other Topics
Construction of a multi-geo multi-cluster
The procedure for building a multi-geography multi-cluster from three Red Hat OpenShift Container Platform (RHOCP) clusters. The constructed multi-cluster will be capable of supporting Broadband Edge (BBE) cloud-native applications such as BNG CUPS Controller and Address Pool Manager (APM) in a geo-redundant capacity.
By Steve Onishi
Routing
Large Enterprises WAN Landscape
Holistic design considerations for Large-Scale Enterprise WAN backbone networks, especially in the context of the evolving landscape shaped by connecting AI Clusters over the WAN Backbone.
By Kashif Nawaz
Platforms / Line Cards Deepdive
Microburst Detection and Avoidance on QFX5k
A comprehensive overview of microbursts and their impact on network performance, with a focus on Juniper's QFX5K EVO platforms (QFX5220, QFX5130, QFX5230, and QFX5240).
By Parthipan Ts
Routing
TreeDN - The Fix for Catastrophically Successful Live Streaming Events
Live streaming audiences are now routinely reaching tens of millions of concurrent viewers. Combined with increasing bitrates for 4K/8K/360deg video, is it time for a new approach to delivering this content?
By Lenny Giuliano
Platforms / Line Cards Deepdive
Introducing Express5 in PTX10K Chassis
In early 2025, we introduced a new line card for the PTX10000 Series: the LC1301. It comes completing the existing LC1201 and LC1202, respectively optimized for 400GbE and 100GbE/400GbE. The LC1301 offers an impressive high-speed port density with 36 ports 800GbE per slot.
By Nicolas Fevrier
Routing
Experience-First Networking By Routing Active Testing
Learn how APAC service providers are using Routing Active Testing to drive customer experience. We explore customers' motivations, Juniper's solution approach and key use cases.
By Henry Cheung
Technology and Features
SRX MPLS in Flow
Junos 24.2R1 brings improvement for selected Juniper SRX series devices, particularly on MPLS and packet-mode/flow-mode processing. This post includes a simple example of an MPLS-enabled SRX device processing 'family inet' in flow mode without relying on selective packet services, as was common previously.
By Karel Hendrych
Platforms / Line Cards Deepdive
MX10000 LC4802 Deepdive
The MX10000 is Juniper's leading multi-service edge routing chassis, and today we are very happy to complete the portfolio with the addition of a fourth line card: the LC4802.
By Eswaran Srinivasan
Various Other Topics
YAMS: Managing JCNR with Model Context Protocol
YAMS (Yet Another MCP Server) is a specialized Model Context Protocol server designed to address the operational complexities of managing JCNR deployments at scale.
By Lavanya Kumar Ambatipudi
Routing
Adaptive Resource Control with Container LSPs
Modern MPLS networks must support highly dynamic traffic patterns, especially in cloud and service provider environments. While RSVP-TE provides engineered path control, traditional single-LSP scaling is often insufficient.
By Kashif Nawaz
Routing
Adaptive Resource Control in TE Networks
In modern MPLS networks, managing traffic flows with precision is essential for maintaining performance and reliability. RSVP-TE provides a robust framework for establishing traffic-engineered paths that align with specific resource requirements. As network conditions fluctuate, static bandwidth reservations often fall short.
By Kashif Nawaz
AI for Networking for AI
LLM Connector: a Conversational AI Assistant for Your Network
There has been a lot of interest recently in Large Language Models (LLMs). One of the major applications of LLMs is conversational AI that enables natural language interactions between people and chatbots. In this article we'll talk about LLM Connector, which is a chatbot within Routing Director that leverages LLMs.
By Julian Lucek
Routing
FBF/CBF: Traffic-Engineering for Outstanding Services
While destination-based forwarding works well for most traffic, certain services require more tailored handling -- such as routing based on source's IP or DSCP values. Leveraging alternative traffic-engineered (TE) paths for such flows enhances network flexibility and creates a compelling business case.
By Anton Elita
Routing
Class Based Forwarding over RSVP LSPs Design Consideration
While Class of Service (CoS) ensures that priority traffic receives preferential treatment on congested interfaces, it does not inherently provide a mechanism to reduce transit latency for delay-sensitive traffic flows.
By Kashif Nawaz
Routing
Mist; Cradle Point and Site-to-Site IPSec Tunnels - an SRX Perspective
Configuring site-to-site IPSec tunnels for devices that fall outside of the seamless integration capabilities Mist provides may seem daunting at first. This article highlights the methods of configuring IPSec tunnels and failover scenarios in Mist with applicable configurations pushed to the SRX.
By James Rathbun
Routing
Wholistic Design Approach for MPLS Backbone Class of Service
Class of Service (CoS) on an MPLS backbone is essential to ensure differentiated traffic handling and maintain QoS across complex, high-throughput networks.
By Kashif Nawaz
Routing
Hybrid MNHA with eBGP
Let's highlight the flexibility of Multi-Node High Availability (MNHA) and JUNOS while providing design considerations when implementing MNHA in a hybrid deployment model.
By James Rathbun
Technology and Features
The Hidden Cost of Jitter in AI/ML Training Fabrics
Jitter is the hidden villain of AI/ML training fabrics: small packet-timing variations stall synchronized GPU collectives like AllReduce. Field observations, lab telemetry and strategies for building jitter-resilient fabrics.
By Mohan Kumar M V
Various Other Topics
Tap Aggregation
Network observability relies on extensive amounts of data to infer internal network states and KPIs from the observed outputs provided by telemetry and the collection of actual traffic from different network points.
By Ridha Hamidi
Routing
SR-TE LSPs Through a Multi-Domain Network
Establishing SR-TE (CSPF) LSPs through inter OSPF areas is a challenge, as these LSPs rely on TED, and this TED is per OSPF area or IS-IS level.
By Ricardo Dominguez
Forwarding, Load Balancing, Filtering
Open-Source Monitoring of Network Forwarding Exceptions: A Practical Approach
In Julian Lucek's blog post, Detection of Blackholes in Networks Using JRI, he explores how Juniper's JRI (Juniper Resiliency Interface) can be leveraged to detect blackholes in networks. Expanding on that idea, c
By Pablo Sagrera Garcia
Platforms / Line Cards Deepdive
Filter-Based Forwarding on MX
A detailed overview of Filter-Based Forwarding (FBF), also known as Policy-Based Routing (PBR), on MX Series routers (AFT), using common deployment scenarios to illustrate configuration methods.
By David Roy
Platforms / Line Cards Deepdive
QFX5K-Series Switches Packet Buffer Architecture
Packet Buffer Architecture on QFX5K-Series switches and various buffer tuning options available on these platforms to maximize the traffic burst absorption.
By Parthipan Ts
Security
com.android.ipsec IKEv2 vs SRX
Example settings for connecting a VPN from the native IKEv2 client on Android 13+ to a Juniper SRX firewall. Due to the client's nature, use cases may include basic remote access and embedded/IoT scenarios where additional software is undesirable.
By Karel Hendrych
Routing
Migrating from OSPF/LDP to OSPF/SR-MPLS
Migrating from a multi-area OSPF with LDP to SR-MPLS is a transition that can be achieved with ease, provided you have a clear understanding of the process and the options available. There are various ways to execute this migration, each with its own set of benefits and considerations.
By Ricardo Dominguez
Security
MACsec and L2PT over Non-Point-to-Point Networks in Junos
Junos 25.4R1 enhances Layer 2 Protocol Tunneling in VXLAN tunnels and traditional VLANs by introducing support for more protocols, allowing MACsec to traverse Layer 2 networks.
By Moshiko Nayman
Routing
BNG CUPS Controller and Geographical Redundancy
Juniper BNG CUPS (Control and User Plane Separation) Architecture supports the Broadband Forum TR-459 Issue 2 and 3 use cases. This blog announces the CUPS Controller deployment options, specifically the new development for geographical redundancy.
By Horia Miclea
Power Topics
Automate Juniper Apstra with PowerShell
Leverage Windows PowerShell to automate Juniper Apstra without installing PowerShell as a language or any libraries (like the HTTP client library).
By Shabbir Ahmed
Routing
SR Tactical Traffic Engineering in Junos
Junos OS 23.4R1 introduces Segment Routing Tactical Traffic Engineering (SR-TTE), a unique and innovative solution designed to address temporary network congestion by dynamically adjusting traffic flows in real-time, directly within the router.
By Moshiko Nayman
Various Other Topics
DNS64 and NAT64 on SRX Series
In this short post, we'll look at configuring the SRX for 6-to-4 NAT (NAT64) when using IPv6-only clients with an external DNS64 server. We'll also quickly examine how the mechanism to dynamically perform this translation works.
By Steven Jacques
Various Other Topics
Single Stage IBA with GaN Converters
Power density in modern networking equipment has been exploding exponentially in recent years. AI-driven, low latency, high bandwidth network architecture drives higher integration of front panel interconnects in data centre networking equipment.
By Sunil Mekad
Forwarding, Load Balancing, Filtering
SRX/CloudATP Multi-Tenant DNS Filtering
Describes the ability of the Juniper SRX, in conjunction with the CloudATP service, to enforce DNS query blocking through an API-driven, multi-tenant approach. Each tenant has its own virtual router, ingress zone, dedicated API token, and independent visibility for granular control and operational separation.
By Karel Hendrych
Routing
Monitoring PFE Resources on EVO Routers
Explore another use case of the Utility MIB feature in Junos and EVO. We previously discussed this feature in a separate Techpost in the context of the SRX platform. Today, we'll focus on its application on the ACX7000 platform.
By David Roy
Silicon / PFE / Memories
Multi-Node High Availability Basics
In this post, we'll take a technical dive into Multi-Node High Availability (MNHA) on Juniper's SRX platforms -- a flexible approach to providing redundancy on stateful network security devices.
By Steven Jacques
Routing Director (ex-Paragon)
Service Orchestration with Paragon Automation
How Paragon Automation (PA) automates workflow steps in provisioning L3VPN/EVPN/L2Circuit service based on declarative intent.
By Masagung Nugroho
Platforms / Line Cards Deepdive
MX10000 LC4800 Deepdive
We are very pleased to announce the addition of a new line card for Juniper's leading multi-service edge routing chassis, the MX10000.
By Eswaran Srinivasan
Routing
Navigating the Shadows of Dark Fiber Connectivity
Juniper's Converged Optical Routing Architecture -- Unamplified Links. Explore the solution for High-Capacity Transport using 400G OpenZR+ Optics.
By Jad Dimabuyu
Observability, Sampling, Telemetry, SNMP
IPv6 Observability
How can we monitor the SRv6 data plane, and collect statistics on the SRv6 SRH and tunnels with IPFIX option 315 / IMON?
By David Roy
Various Other Topics
SRX4600 CGN Configuration Breakdown
The SRX has been used as a Carrier Grade NAT (CGN) or mobile Gi/SGi firewall since the early days. Due to popular demand, this TechPost aims to describe the Junos configuration details and KPIs of a real-life SRX4600 CGN deployment for an operator serving fixed customers.
By Karel Hendrych
Routing
L3VPN to Global RIB Leaking
Leak remote L3VPN routes to the global internet table or other VRFs is now possible with the introduction of the vpn-global-import feature coming in Junos 24.2.
By Moshiko Nayman
Platforms / Line Cards Deepdive
Trio 6 Packet Walkthrough
A transit packet walkthrough inside an MX Series Trio 6 ASIC, with all the internal details on the different memory and components involved in the process.
By David Roy
Platforms / Line Cards Deepdive
Fast Lookup Tuple: an Innovative Filtering Feature
An innovative filtering solution for IPv4 traffic on MX Series, developed to handle five tuples matching criteria at scale.
By David Roy
Platforms / Line Cards Deepdive
From QFX5100 to QFX5120
Explore the software and hardware differences you will encounter regarding switch connectivity when transitioning from the end-of-life QFX5100-48S and QFX5100-48T switches to the replacement QFX5120-48T and QFX5120-48Y switches.
By Nicole Henry
Apstra
Micro-Segmentation in DC with Apstra and Junos
Discover how to implement micro-segmentation in your data center using Juniper Apstra and VXLAN Group-Based Policy. This comprehensive guide walks you through the process of deploying fine-grained security controls at the fabric level, offering a powerful solution for modern network security challenges.
By Adam Jarvis
Routing
BIER Overlay
Third part of the BIER series: how the multicast overlay (MVPN) maps onto BIER sub-domains on PTX10002-36QDD, solving the upstream-assigned label scaling issues of aggregate P2MP tunnels.
By Suneesh Babu
Routing
Secure Virtual Cell Site Router Solution with JCNR and cSRX
A secure virtual cell site router (CSR + SecGW) functionality using Juniper Cloud Native Router or JCNR and Containerized SRX or cSRX so that customers and readers can easily replicate this in their lab environment and get a feel of this solution.
By Vivek Shenoy
Routing
BIER Table Lookup
Second part of the 3-article series on BIER, detailing how is performed the lookup in the different BIER Tables.
By Suneesh Babu
Technology and Features
SRX AutoVPN / PSK with Linux strongSwan
An example of SRX AutoVPN functionality with Pre-Shared Keys in 3rd party mode; specifically with Linux/strongSwan spokes.
By Karel Hendrych
Routing
BGP Minimum ECMP
BGP Minimum ECMP is a new feature aiming at improving resiliency within DC networks.
By Himanshu Tambakuwala
Various Other Topics
Selective Dynamic Load Balancing
A new innovative feature called Selective DLB (Dynamic Load Balancing), improving RDMA traffic ECMP.
By Sanoop Rajan
Routing
BIER Introduction and Underlay
First part of the 3-article series on BIER, discussing fundamental concepts and BIER underlay.
By Suneesh Babu
Security
The Evolution of Network Security
A primer/survey for networking and cyber security enthusiasts interested in the evolution of this field.
By Sharada Yeluri
Platforms / Line Cards Deepdive
MAP-T with Junos
Junos OS 23.4R1 introduces Mapping of Address and Port using Translation (MAP-T) as an adaptive service on Juniper MX Series routers equipped with Trio Silicon. MAP-T is a stateless NAT64-based solution designed to facilitate seamless IPv4 to IPv6 transition within IPv6 domains.
By Moshiko Nayman
Platforms / Line Cards Deepdive
Junos Symmetrical Load Balancing
Efficient stateless load-balancing on Trio-based routers, offering optimal performance and reliability.
By Moshiko Nayman
Routing
Scalable BGP Route-Reflector
BGP Route-Reflector is part of many networks, serving PE routers with reachability information. For this critical role, it's important to have a robust and feature-rich software, able to serve route updates quickly and reliably, for both upstream and downstream directions. Let's see how to achieve this goal with cRPD.
By Anton Elita
Silicon / PFE / Memories
Flexible memory in Express5
Express5 fungible shared memory architecture provides the foundation for a flexible memory scheme which increases scale and efficiency of memory utilization.
By Swamy Srk
Platforms / Line Cards Deepdive
FIB Install Rate in PTX Express5
PTX10002-36QDD is the first router equipped with the new Juniper Express5 packet forwarding engine, a new deep-buffer 28.8Tbps package introducing a lot of innovations and improvements compared to its predecessor.
By Vivek Singh Sikarwar
BNG
Juniper BNG CUPS Address Pool Management
Another innovation for CUPS that enables unified Address Pool Management across CUPS controller(s) and Integrated BNGs. This use case simplifies the service provider operations and cost optimizes the public IPv4 address space usage.
By Horia Miclea
BNG
Juniper BNG CUPS Smart Load Balancing with High Availability
A Juniper BNG CUPS use-case that combines Smart Subscriber Load Balancing and High Availability Hot or Warm Standby across a group of User Planes based on Broadband Forum TR-459 Issue 2.
By Horia Miclea
Routing
SRX EVPN/VXLAN T5 oIPSEC
A practical yet simple demonstration of the SRX EVPN/VXLAN Type 5 ip-prefix-routes feature and related firewall policy processing across multiple tenants, including an example of communication between overlapping IP prefixes.
By Karel Hendrych
BNG
Juniper BNG CUPS Hitless User Plane Maintenance
A Juniper BNG CUPS use-case that enables hitless maintenance for the user planes based on Broadband Forum TR-459 Issue 2. It improves the subscriber experience and optimizes the service provide operations by removing maintenance downtimes.
By Horia Miclea
Routing
BGP Link-Bandwidth with JunOS
The BGP Link-Bandwidth extension introduces an improvement to the BGP multipath, providing the ability to convey port speeds and propagate this information across network devices.
By Moshiko Nayman
BNG
Juniper BNG CUPS Architecture
Juniper BNG CUPS (Control and User Plane Separation) is an emerging broadband architecture for control plane and user plane separation compliant with Broadband Forum TR-459 Issue 2.
By Horia Miclea
JVD Juniper Validated Designs
Introduction to Metro Ethernet Business Services Validated Design
Introducing our latest Juniper Validated Design (JVD), addressing Metro Ethernet Business Services (EBS) with Juniper MX Series, ACX Series, and PTX Series platforms.
By Kevin Brown
Platforms / Line Cards Deepdive
EANTC BIER InterOp Testing on PTX10002-36QDD
BIER Interoperability testing verified between PTX10002-36QDD and other vendors during the EANTC 2024.
By Suneesh Babu
Platforms / Line Cards Deepdive
BIER + MVPN in PTX Express 5
High-level functionality description of BIER as MVPN provider tunnels in the upcoming release of PTX Express 5.
By Jeffrey Zhang
Platforms / Line Cards Deepdive
Introducing the ACX7024X
Introducing the ACX7024X: same 1RU form factor, ports, ASIC and 360Gbps forwarding as the ACX7024, but with a more powerful CPU and more DRAM to address use cases where the original's control plane was the limiting factor.
By Nicolas Fevrier
Virtual Routers
vSRX on mini-PC with Linux/KVM
Using Juniper vSRX on hardware with constrained resources, typically a mini-PC serving as flexible Internet gateway. Those are lately very popular due to low footprint yet with capabilities making them suitable for running virtual machines.
By Karel Hendrych
Platforms / Line Cards Deepdive
SRv6 in PTX Express 5
PTX Express 5 ASIC has full support for SRv6 with up to 8 carrier segment identifiers (SIDs) in a packet. That translates to 48 micro-SIDs (uSIDs), enough to pass a packet around the world! Following is a description of how SRv6 was implemented in the ASIC.
By Nancy Shaw
Platforms / Line Cards Deepdive
FIB Scale in Express5
Express5 has leap frogged in terms of Route scale, thanks to a novel approach in implementing the route table memory.
By Chandrasekaran Venkatraman
Platforms / Line Cards Deepdive
Flex Offset Filters in Express5
Filter in Express5 supports Flex Key match on any field in the first 128 bytes of the packet. Using software defined templates, firewall term matches are done using flex-key construction. This can be used to specify matches on user-defined packet byte locations via CLI.
By Chandrasekaran Venkatraman
Platforms / Line Cards Deepdive
Flexible pipeline
High-level overview of packet processing, exploring the evolution of throughput demands for these processing units, and discussing various methods employed to execute these functions within networking chips.
By Sharada Yeluri
Observability, Sampling, Telemetry, SNMP
OpenJTS - Network Observability with Streaming Telemetry
In this article, we'll present a new open-source tool called OpenJTS (Juniper Telemetry Stack). Designed for effortless adoption, this all-in-one tool demystifies gRPC/gNMI Telemetry on Juniper routing products. We currently support PTX10K, MX (vMX, Neo, and 10K platforms) and ACX7K platforms.
By David Roy
Apstra
SP-style Config in Apstra Freeform for VLAN Overlap Use-Cases
In high multi-tenant environments such as Service Providers, Hosting Providers, or just large enterprises, having to deal with multiple internal customers, efficient utilization of infrastructure is top of mind for network operations teams.
By Elisabeth Rodrigues
Platforms / Line Cards Deepdive
PTX10002-36QDD Hardware Deepdive
The new Juniper PTX10002-36QDD is here. It's our first 800GigabitEthernet, deep-buffer, high-scale, router in the market, powered by Express 5. And we are very excited to share some details about this unique platform.
By Nicolas Fevrier
Platforms / Line Cards Deepdive
Express 5 Overview
Express 5 is Juniper's new ASIC for service providers and cloud networks, delivering 2x power efficiency, enhanced traffic insights, hardware-based sampling, value-added services, and supporting high-speed, high-scale routing applications including AI/ML training clusters with up to 16M IPv4/IPv6 routes and 8M counters using a…
By Dmitry Shokarev
Apstra
Introduction to Apstra Flow Data
With the popularity of distributed applications in systems using inter-process communication (IPC), troubleshooting network issues is crucial. With network flow monitoring, you can troubleshoot application issues in a DC fabric with distributed, cloud-native, virtualized, and containerized workloads.
By Adam Grochowski
Platforms / Line Cards Deepdive
Everything You Always Wanted to Know about ACX7000
The ACX7000 family is growing fast. Today, we try a different approach to present this update of the ACX7000 portfolio.
By Nicolas Fevrier
Platforms / Line Cards Deepdive
From sFlow to IMON Flow Sampling on MX10K Platforms
sFlow (sampled flow) is a protocol used for monitoring and collecting traffic data in devices, such as switches, routers, and other networking equipment. The specification of the sFlow protocol [is defined here:](https://sflow.org/sflow_version_5.txt).
By David Roy
Various Other Topics
LLM Inference - Hw-Sw Optimizations
Details of LLM inference workflow, how it differs from training, the many hardware/software optimizations that go into making inference efficient, and the Inference hardware landscape.
By Sharada Yeluri
Apstra
Apstra Day 2: Generic Systems
It is often stated that most network outages occur as a result of changes having been made to the system. There have been many notable examples of this, and they have all affected us. Precise management of network changes is, in fact, one of the key benefits of network automation solutions.
By Robert Lancaster
Scale and Convergence Tests
Operating MX/SRX Scale-Out System - Bulk Junos Config Changes
A minimalistic tool for bulk config changes in the scale-out system beyond options available in Auto-FBF CLI
By Karel Hendrych
Various Other Topics
LLM Inference - Hw-Sw Optimizations
Details of LLM inference workflow, how it differs from training, the many hardware/software optimizations that go into making inference efficient, and the Inference hardware landscape.
By Sharada Yeluri
Apstra
Apstra Day 2: Generic Systems
It is often stated that most network outages occur as a result of changes having been made to the system. There have been many notable examples of this, and they have all affected us. Precise management of network changes is, in fact, one of the key benefits of network automation solutions.
By Robert Lancaster
Observability, Sampling, Telemetry, SNMP
Using Junos SNMP utility MIB on Juniper SRX
Although good old Junos SNMP MIB is very rich on every platform, occasionally some specific stats could have been handy. For example, number of sessions per IP protocol on SRX. No problem! Blast from the past Junos utility MIB tooling allows expansion of MIB by anything retrievable using RPCs.
By Karel Hendrych
Various Other Topics
JCNR for Equinix Metal
JCNR brings a lot of value by providing seamless connectivity between workloads across locations, public cloud boundaries, and workload form-factor, by providing full router functionality.
By Vivek Shenoy
Platforms / Line Cards Deepdive
Operating 1Tbps MX304/SRX4600 Firewall Scale-Out System
Focusing on SRX firewall -- the scaled out device - operational aspects in terms of removing device from service and bringing it back.
By Karel Hendrych
Platforms / Line Cards Deepdive
ACX7000 Hardware Profiles
The ACX7000 routers are powered by Broadcom Jericho2 Series chipsets. These Packet Forwarding Engines (PFEs) are equipped with a substantial internal memory pool known as Modular DataBase (MDB).
By Nicolas Fevrier
Apstra
Upgrading Device Operating Systems with Apstra
Juniper Apstra supports Network Operating System (NOS) Upgrades for managed switches, allowing you to upgrade devices directly from the Apstra Server within a consistent workflow process.
By Adam Grochowski
Various Other Topics
Packets Lost in Transit?
Inline Monitoring allows to get forwarding status codes for transit packets, as well as a sample of the packet itself -- even if the packet was dropped for whatever reason.
By Anton Elita
Various Other Topics
Detection of Blackholes Using Juniper Resiliency Interface
Unfortunately, black-holes sometimes occur in networks -- packets disappear without trace for no apparent reason. Often the first symptom is when customers of the network complain about poor performance.
By Julian Lucek
AI for Networking for AI
GPU Fabrics for GenAI Workloads
GPU cluster scale, model partitioning, and traffic patterns between the GPUs for training workloads.
By Sharada Yeluri
Platforms / Line Cards Deepdive
Boosting Route Scale and Performance with JunOS
Strategies to enhance the scale and performance of routing, aiming for faster convergence, improved stability, and optimized hardware utilization.
By Moshiko Nayman
Various Other Topics
G.8275.1.enh: Juniper's Advancements in Timing and Synchronization
The benefits and versatility that Juniper brings with the PTP G.8275.1.ENH profile and the reasons behind its enhancements.
By Vladimir Moki
Apstra
Apstra Server Clustering
How Apstra clustering works with respect to Off-box agents and Probe processing units
By Mehdi Abdelouahab
Silicon / PFE / Memories
Liquid Cooling - The Inflection Point
The different thermal management solutions for cooling the high-power components in electronic systems (HPCs/Servers and network equipment), trends, and the future.
By Sharada Yeluri
Platforms / Line Cards Deepdive
BNG on MPC10
Starting in the 22.4R1 JUNOS release, MPC10E supports BNG subscriber access connections.
By Ricardo Dominguez
Apstra
Automating 3-stage Clos fabric with Terraform and Apstra
The Juniper Apstra SDK, written in Golang, integrates Apstra into the Terraform ecosystem, enabling an Apstra specific provider.
By Vivek V
Various Other Topics
To Spray or Not to Spray
Every networking vendor acknowledges this problem and tries to find a solution. Various techniques to redistribute flows away from congested paths are proposed by vendors: Dynamic Load Balancing / Global Load Balancing from Broadcom or Adaptive Load Balancing from Juniper.
By Dmitry Shokarev
Platforms / Line Cards Deepdive
MX304 FIB Install Rate
MX304 installs the full Internet tables at 47,000 routes per second, and we will show you how we are testing it.
By Suneesh Babu
Apstra
Using Apstra Drain Mode
Apstra supports Drain Mode for managed switches, allowing the operator to gracefully drain traffic from devices without simply shutting down the BGP neighbor relationships.
By Jeffrey Doyle
Platforms / Line Cards Deepdive
Monitoring PTX Power and Environment-s KPI through Telemetry
How Junos EVO implements the OpenConfig "platform" data model to expose many indicators/counters related to environmental data.
By David Roy
Apstra
Config Rendering in Juniper Apstra
A description of the different configurations that can be rendered based on the state of the devices in Apstra.
By Adam Jarvis
Apstra
Apstra Freeform Day-2 Configuration
Using Tags, Property Sets, and Jinja to simplify Apstra Freeform Day-2 Configuration.
By Andy Ford
Virtual Routers
Building Virtual Fabrics with vJunos-switch and Containerlab
How vJunos-switch is deployed as a VM, packaged within a container, on a bare metal server using the open source network emulation tool Containerlab.
By Aninda Chatterjee
Apstra
Introduction to Apstra Freeform
From the basic constructs Freeform uses -- Tags, Device Contexts, Property Sets, and Config Templates -- to creating a simple Freeform blueprint, to a number of advanced case studies.
By Bill Wester
Routing
Mastering BGP PIC on JUNOS
Optimizing Failover Convergence for Enhanced Network Resilience with BGP PIC implementation in JUNOS.
By Moshiko Nayman
Apstra
Using Apstra Policy Assurance
Apstra manages network security and workload isolation via the Policy Assurance feature. This feature allows you to create policies that are decoupled from enforcement mechanisms and will enable the specification of the intent in an implementation-independent way.
By Dj Spry
Silicon / PFE / Memories
Chiplet Post from Linkedin
Moore's law is an observation by Gordon Moore that the number of transistors in a computer chip doubles every two years. This law is often misinterpreted by many.
By Sharada Yeluri
Forwarding, Load Balancing, Filtering
ESI-LAG Made Easier with EZ-LAG
A detailed configuration example that shows how to dual-home data center servers to Juniper leaf switches by using EZ-LAG, a simplified version on ESI-LAG made for customers looking for a smooth transition from Multi-Chassis LAG without having to immediately learn all the features and complexities of EVPN-VXLAN technology.
By Ridha Hamidi
Various Other Topics
BIER Intro
As a revolutionary multicast technology that allows efficient replication without requiring per-tree states in the network, Bit Index Explicit Replication (BIER) is the perfect solution for multicast in SR networks. This article explains BIER technology and its implementation/deployment prospects.
By Jeffrey Zhang
Apstra
Apstra Device Replacement
An essential operation in a working data center network would be the need to replace a device that has either failed or just needs to be re-allocated/reused for other purposes. This document describes the steps needed to accomplish this task via the Apstra UI and the Apstra Terraform Provider.
By Bill Wester
AI for Networking for AI
ML Post from Linkedin
A brief introduction to the LLMs, the hardware challenges in training these models, and how the GPU and networking industry is evolving to optimize the hardware for the training workloads.
By Sharada Yeluri
Technology and Features
IP/VPN provision and operation with Apstra Freeform
Illustration of an IP/VPN MPLS network provisioned and operated with Apstra Freeform.
By Elisabeth Rodrigues
Various Other Topics
Suspicious Control Flow Detection
Juniper enhanced the initial DDoS protection feature with Suspicious Control Flow Detection (SCFD). It provides deeper analysis within a given protocol or packet-type: a solution that addresses the need for more granular flow policing, supported from Junos OS 17.1R1
By Moshiko Nayman
Technology and Features
Traffic Accounting with MX Features
How much traffic coming from Internet reach my different POPs? Can I monitor in real time the traffic coming from the "TOP Internet Talkers"? Is there an easy way to count traffic entering and leaving my VRFs?"... If you are part of a support or capacity planning team, you frequently got this questions.
By David Roy
Platforms / Line Cards Deepdive
Saving Power on ACX7000
How we can significantly reduce the power usage of the ACX7000 routers with basic configuration and simple best-practices.
By Nicolas Fevrier
Apstra
Apstra Configlets
Configlets allow the administrator to create custom configuration templates and automatically deploy them to devices based on intent.
By Wataru Nakamae
Platforms / Line Cards Deepdive
Guide to the EVPN VXLAN-based OISM on PTX
Guide to the EVPN VXLAN based Optimised Inter-subnet Multicast (OISM) on Express4 based PTX10k platforms.
By Ramdas Machat
Platforms / Line Cards Deepdive
Features Saving Power on PTX10000
Did you know: numerous built-in functionalities with Junos-EVO are enabled by default and help reducing the power usage and carbon foot-print of your PTX routers?
By Nicolas Fevrier
Routing
BGP CT Use-Cases
Key applications of BGP Classful Transport (BGP-CT), including path-diversity across multiple ASes, multi-AS paths that take into account sovereignty constraints, and paths that achieve the minimum end-to-end latency across ASes.
By Julian Lucek
Apstra
Creating Audit Trails with the Apstra Event Log
The Audit trail feature tracks a user's actions while using Apstra and can be very useful in investigating general usage, network outages, and possible suspicious activity.
By Bill Wester
Scale and Convergence Tests
Scale-Out Security Services with Auto-FBF
An alternative approach to scale-out of security services, specifically for CGN and Gi Firewall deployments called auto-fbf. Technologies in scope are MX, on-box automation and SRX/vSRX as scaled-out elements delivering services.
By Karel Hendrych
Apstra
Adding Device Profiles Using the Apstra UI
The capabilities of a specific switch hardware model are defined in the Device Profile and linked to the logical representation of the switch.
By Andy Ford
Apstra
Apstra IP Fabric Reference Design
Juniper Apstra's fundamental purpose is to minimize operational costs and maximize the speed of network operations by furnishing predefined, rigorously validated reference designs.
By Bill Wester
Various Other Topics
Centralized Deterministic CGNAT
All you need to know on Centralized Deterministic NAT configuration, scale and performance on MX routers.
By Ricardo Dominguez
Routing
Link Slicing with MPLS and SRv6 Underlays Part 2
Another use case for link slicing: instead of data plane identifiers, control plane identifiers are used. Control plane protocols exchange the information that allows to classify packets to link slices.
By Krzysztof Szarkowicz
Platforms / Line Cards Deepdive
Saving Energy on PTX with PFE Power Off
Let's test the real power saving on PTX platforms achieved when shutting down used and unused Packet Forwarding Engine (PFE).
By Ramdas Machat
Technology and Features
MPLS Label Anti-Spoofing
Solution to secure BGP Option B against MPLS label spoofing on MX Series routers.
By Moshiko Nayman
Routing
Optimizing Power Consumption in High-End Routers
A detailed review of the various components inside a high-end router and how they contribute to overall power consumption.
By Sharada Yeluri
Various Other Topics
Time Synchronization and Class D Clocks Support
Timing and synchronization requirements and capabilities are continually evolved to drive the ultra-low latency, mission critical and advanced radio applications for 5G and beyond. Satisfying the new enhanced ITU-T and other standards for time accuracy in network equipment requires careful planning of the timing architecture.
By Rafik P
Routing
BGP FlowSpec "Exclude Interfaces" on Express2 Platforms
BGP FlowSpec is one of the mechanisms that allows a network to protect itself against DDoS attacks. A common mitigation tactic is to redirect malicious traffic to a scrubbing center for further analysis. If any of the analyzed traffic is found to be legitimate, it can be re-injected into the network.
By Jordan Head
Platforms / Line Cards Deepdive
ACX7000 ERSPAN and Port Mirroring
Traffic mirroring is a useful method for debugging traffic patterns. The ACX7000 family of products supports both local port mirroring and ERSPAN. This article describes how to utilize these functionalities.
By Pankaj Kumar
Routing
BGP CT Interop Demo EANTC2023
BGP CT interoperability tests between Junos, Junos Evo and FreeRTR routers conducted in Berlin during the EANTC2023 event in March 2023.
By Kaliraj Vairavakkalai
Routing
Link Slicing with MPLS and SRv6 Underlays
The guaranteed link slicing feature, using MPLS and SRv6 as underlay transport.
By Krzysztof Szarkowicz
Various Other Topics
Deploying and Using vJunos in a Bare Metal EVE-NG server
vJunos-switch and vJunosEvolved deployed on EVE-NG and integrated with Juniper Apstra to build a complete Data Center fabric. Article co-written with Aninda Chatterjee and Shalini Mukherjee, TME in Juniper Networks Cloud-Ready Data Center team.
By Shalini Mukherjee
Various Other Topics
vJunos Deployment on KVM
A comprehensive user guide on how to successfully deploy and use vJunos-switch and vJunosEvolved on KVM (one of the most popular virtualized environments in the community, alongside EVE-NG and GNS3).
By Ridha Hamidi
Routing
New Subscriber QOS for Next Generation Broadband
Broadband services are evolving with cloud streaming and advanced video, a new BNG QOS model for subscribers is required to optimise latency, throughput and scale. This techpost introduces a new subscriber QOS model based on Hierarchical Policers.
By Horia Miclea
Various Other Topics
Mobile Backhaul Services Overlay
Fourth article of the Mobile Backhaul validation series, focusing on the services overlay: how Seamless MPLS decouples services from transport and how L2/L3 services were validated on ACX710, ACX5448 and MX10003.
By Kevin Brown
Platforms / Line Cards Deepdive
MX304 Deepdive
A detailed review of the latest router of the MX Series. Powered by Trio6 PFE, it offers unique form-factor and modularity, with interface spanning from 1GE to 400GE and control-plane redundancy.
By Reema Ray
Various Other Topics
MPC10E Deepdive
A detailed view of the MPC10E line cards used in MX240, MX480 and MX480.
By Deepak Tripathi
Routing
Sizing Router Buffers - Small is the New Big
Current practices and future trends on buffers in networking chips.
By Sharada Yeluri
Technology and Features
Building Border Agnostic Architectures with Seamless MPLS
Third part of the Juniper Validated Design series on basic Mobile Backhauling, with a focus on Seamless MPLS and BGP-LU.
By Kevin Brown
Routing
SRv6 L3VPN Inter-AS Option-C
Layer 3 Virtual Private Network Inter-AS option using SRv6 as underlay transport on MX and ACX7000 routers.
By Krzysztof Szarkowicz
Technology and Features
Service Mapping to Colored MPLS Paths
Mapping modern and legacy services to colored MPLS paths, achieving business differentiation.
By Anton Elita
Silicon / PFE / Memories
Longest Prefix Matching in Networking Chips
Basic concepts of Forwarding Information Base (FIB), the longest prefix match (LPM) for IP forwarding, and how its implementation has evolved over time. The emphasis is on various hardware implementation choices and how they compare with each other in die area/power and performance. This is intended as a high-level primer.
By Sharada Yeluri
Platforms / Line Cards Deepdive
EVPN E-Line on PTX10k platforms
Let's test EVPN ELINE/VPWS on Express4-based platforms playing the role of PE. In this article, we will describe the various approaches, the configurations and the instance scaling.
By Ramdas Machat
Platforms / Line Cards Deepdive
PTX10001-36MR FIB Install Rate
PTX10001-36MR installs the Internet routes at more than 27,000 routes per second, and we will show you how we are testing it.
By Suneesh Babu
Routing
SRv6 SID Encoding and Transposition
JUNOS 22.3 introduced several changes in the SRv6 infrastructure, this article covers them in details.
By Krzysztof Szarkowicz
Apstra
Juniper Apstra Introducing a True IBNS
What a true IBN system is? How relational and graph databases are different? And why graph databases are ideal for network infrastructure?
By Aninda Chatterjee
Platforms / Line Cards Deepdive
FIB programming speed validation - PTX10001-36MR
PTX10001-36MR installs the Internet routes at more than 27,000 routes per second, and we will show you how we are testing it.
By Suneesh Babu
Platforms / Line Cards Deepdive
ACX7100/ACX7509 Validation: L2MAC Learning Rate
We verify ACX7000 platforms support 700,000 MAC addresses with a learning rate of 14,000 entries per second.
By Suneesh Babu
Platforms / Line Cards Deepdive
ACX7100/ACX7509 Validation: VPLS
Let's verify we can support 8,000 VPLS instances in the ACX7000 products with 640,000 MAC addresses.
By Suneesh Babu
Platforms / Line Cards Deepdive
ACX7100/ACX7509 Validation: L2VPN
ACX7000 platform is tested with 8,000 Layer2 VPN Routing-instances for 99.9% line rate traffic.
By Suneesh Babu
Platforms / Line Cards Deepdive
ACX7509 Deepdive
The first centralized platform of the ACX7000 family. Based on a modular design, it offers control plane and forwarding plane redundancy with port density spanning from 1GE to 400GE, in just 5RU.
By Nicolas Fevrier
Platforms / Line Cards Deepdive
ACX7100/ACX7509 Validation: L3VPN/6VPE
ACX7000 platform has been tested successfully with 4,000 Layer3 VPN Routing-instances with BGPv4, BGPv6, OSPF, OSPFv3, ISISv4, ISISv6, Static-v4, Static-v6 as CE-PE protocols and with a total of 1.35M routes.
By Suneesh Babu
Platforms / Line Cards Deepdive
ACX7100/ACX7509 Validation: EVPN-VPWS
Junos EVPN-VPWS feature supports 8,000 instances with 4,000 VLAN-UnAware and 4,000 VLAN-Aware Service Types on ACX7000 Platforms.
By Suneesh Babu
Routing
VPLS (LDP/BGP) to EVPN migration
Techniques, configurations and best practices for migrating from legacy business services to EVPN on MX Routers.
By Ramdas Machat
Platforms / Line Cards Deepdive
ACX7100/ACX7509 Validation: EVPN MAC-VRF
JUNOS unified way of bringing up EVPN E-LAN using mac-vrf instance type supporting 6,000 instances on ACX7000 with 642,000 MAC scale.
By Suneesh Babu
Silicon / PFE / Memories
Silicon Photonics and Integrated Optics
SiPh (Silicon Photonics) is no longer SciFi (Science Fiction). Let's see where is the industry today with co-packaged optics...
By Sharada Yeluri
Routing
BGP RIB Sharding
Discover how BGP RIB Sharding can help improve routing performance and scale in JUNOS.
By Ravindran Thangarajah
Platforms / Line Cards Deepdive
PTX10001-36MR Introduction
Product manager's description of the PTX10001-36MR router. Product characteristics, port types and supported port combinations, architecture and the applications of the router are all outlined in the article.
By Dmitry Shokarev
Observability, Sampling, Telemetry, SNMP
Sampling Evolution
Are the flow caches effective to support IPFIX implementations today? What happens if we stop using them? Learn about the new IPFIX implementation in Juniper PTX and ACX7000 routers.
By Dmitry Shokarev
Platforms / Line Cards Deepdive
PTX10001-36MR L2 Circuit Scale
The PTX10001-36MR is well-known for its core, peering and DCI capabilities, but it's also a very performant L2 aggregation device. In this article, we will test and demonstrate L2 virtual circuits scale on Express4-based PTX routers.
By Dmitry Shokarev
Routing
SRv6 locator summarization
Let's discuss the multi-domain SRv6 network together with the concept of SRv6 locator summarization. SRv6 locator summarization allows for large-scale, multi-domain deployments with SRv6.
By Krzysztof Szarkowicz
Platforms / Line Cards Deepdive
PTX FIB Compression
Did you know the internet table can be compressed significantly? We explain how the PTX and ACX7000 routers running Junos EVO are currently implementing FIB compression.
By Nicolas Fevrier
Routing
Inter-domain On-demand SR-TE LSPs with BGP-LS
A standard-based approach to placing MPLS-based services with path constraints across multiple networks.
By Anton Elita
Platforms / Line Cards Deepdive
ACX7024 Deepdive
Everything about the new addition to the Cloud-Metro family, the ACX7024. A 1-RU router, with 360Gbps forwarding capacity.
By Pankaj Kumar
Routing
Seamless MPLS LDP-Signaled with OSPF IGP Underlay
Second profile of the Juniper Validated Design series on basic Mobile Backhauling, with a focus on LDP-signalled MPLS and OSPF IGP.
By Kevin Brown
Platforms / Line Cards Deepdive
ZR/ZR+ Coherent Optics in ACX7100-32C
How does the Juniper ACX7100-32C router handle a fully loaded 400GE ZR and 100GE ZR4, long reach, high power coherent optics configuration?
By Antu Chatterjee
Silicon / PFE / Memories
Tearing down the memory wall
The gap between processor and memory performance and density continued to increase - this is often referred to as the "Memory Wall".
By Sharada Yeluri
Platforms / Line Cards Deepdive
ACX7100 Routers Deepdive
In this post, you'll learn everything about the first two Juniper Cloud-Metro devices: ACX7100-32C and ACX7100-48L.
By Pankaj Kumar
Routing
L3VPN over SRv6
How unicast IPv4/IPv6 within L3VPN VRFs are implemented with Segment Routing v6 (SRv6) as underlaying transport technology.
By Krzysztof Szarkowicz
Various Other Topics
MX LC480 Deepdive
LC480 is a 48 port 1G/10G line card supporting Business Services(L2/L3) with rich OAM features, Broadband subscriber at scale, H-QoS, high filter scale and deep buffers. It's a perfect complement to the MX10K portfolio known for supporting highly dense 100G and 400G (LC9600) line cards.
By Deepak Tripathi
Various Other Topics
Let-s Talk About VOQ and DNX Pipeline
To understand the life of a packet in an ACX7000 Series router, you first need to understand the idea behind Virtual Output Queues.
By Nicolas Fevrier
Observability, Sampling, Telemetry, SNMP
Telemetry Collector and Graphical Frontend on Junos Evolved
Junos Evolved 21.4R1 is used here as an example. Streaming measurements out of a networking node can be performed in a few ways. In this guide, OpenConfig gRPC Network Management Interface (GNMI) is used for data encoding and transport. It is a widely adopted choice.
By Anton Elita
Silicon / PFE / Memories
Networking Chips vs GPUs/CPUs
In this era of CPUs, GPUs, and AI inference chips (often stripped-down versions of GPUs with a focus on matrix operations), where every other semiconductor start-up is trying to build either a CPU core or an AI chip, networking chips are not getting the fanfare they used to enjoy decades earlier.
By Sharada Yeluri
Platforms / Line Cards Deepdive
Layer 3 Solution for CDN Gateway
The world of CDN gateways is usually built around L2 domains and IRB, where a switch interconnects CDN servers, hosts and the L3 gateway. We propose a solution directly associating hosts and CDN servers at L3.
By Ramdas Machat
Routing
SRv6 basic: SRv6 locator and End SIDs
SRv6 (Segment Routing version 6) is a version of segment routing based on IPv6 tunneling mechanism, rather than on MPLS (MultiProtocol Label Switching) underlay. Therefore, with SRv6 underlying transport routers must be capable of forwarding IPv6 (Internet Protocol version 6) packets, and do not require MPLS support.
By Krzysztof Szarkowicz
Platforms / Line Cards Deepdive
Express 4 Filters - Foundation
This series of articles provides a guide to understanding the capabilities and operating principles behind the Filter block in the Express silicon architecture, deep insights into its mighty power and efficiency, and practical application to real world networking and security problems.
By Dmitry Bugrimenko
JVD Juniper Validated Designs
Overview results of jvd-mbh-base
Summary of the Juniper Validated Design series dedicated to 5G xHaul reference architecture (Fronthaul, Midhaul, and Backhaul network segments).
By Kevin Brown
Various Other Topics
MX LC9600 Deepdive
All you always wanted to know of the newest MX10k line card powered by Trio 6 PFE and optimised for 100GE and 400GE requirements.
By Deepak Tripathi
Various Other Topics
Introduction to the Validation Series
Short introduction to the validation articles. What you should expect from these blog posts, unit testing or extracts of the Juniper Validated Designs.
By Nicolas Fevrier
Platforms / Line Cards Deepdive
Building the ACX7000 Series: the PFE
First article "Behind The Scene" on the building of the ACX7000 Series, starting with the heart of the router: the Packet Forwarding Engine.
By Nicolas Fevrier