r/Juniper • u/blongwe • 9h ago
Question Juniper Route Server + IXPManager
Is anyone here using a Junos based Route Server with IXPManager and if so, how are you handling pulling/pushing of config from IXPManager to the RS?
r/Juniper • u/AutoModerator • 6d ago
It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!
Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.
Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.
r/Juniper • u/blongwe • 9h ago
Is anyone here using a Junos based Route Server with IXPManager and if so, how are you handling pulling/pushing of config from IXPManager to the RS?
r/Juniper • u/taemyks • 20h ago
I have an ex2300-24f and ex-2300-c that I'm trying to connect via fiber and having no luck.
Both of these switches are factory default with no config, they are supposed to be dumb as hell. This is the requirement.
If a SFP is used the connection comes up on the 24 port switch, but never on the 12 port switch. Tried multiple SFPs, and fiber patches. Tried both sfp ports on the 12p, and 3 on the 24p. Always the same, the 24p switch shows port up and packets exiting, 0 packets incoming.
On the 12p there are no packets received, none sent. Port down hard
If i attach them with random copper ports it works as expected.
I'm running out of ideas here
Edit: here's the solution https://supportportal.juniper.net/s/article/EX2300-C-uplink-ports-issue-with-1g-fiber-connection
r/Juniper • u/Holiday-Bridge-9429 • 1d ago
Hello everyone, I hope I am not violating any rules.
I am facing a rather unusual situation (please note that this is a lab environment).
The topology consists of three devices:
The original configuration was working correctly with the following setup:
/interface vlan
add interface=sfp-sfpplus2 name=vlan2000 vlan-id=2000
add interface=vlan2000 name=vlan10 vlan-id=10
/ip address
add address=10.10.10.1/24 comment="Test QFX" interface=vlan10 network=10.10.10.0
set interfaces xe-0/0/1 description "LINK TO CE-2 MX204"
set interfaces xe-0/0/1 flexible-vlan-tagging
set interfaces xe-0/0/1 encapsulation extended-vlan-bridge
set interfaces xe-0/0/1 unit 2000 description "Q-IN-Q TRANSPORT CE-2"
set interfaces xe-0/0/1 unit 2000 vlan-id-list 10
set interfaces xe-0/0/1 unit 2000 input-vlan-map push
set interfaces xe-0/0/1 unit 2000 output-vlan-map pop
set interfaces xe-0/0/2 description "LINK TO CE-1 MIKROTIK"
set interfaces xe-0/0/2 flexible-vlan-tagging
set interfaces xe-0/0/2 encapsulation extended-vlan-bridge
set interfaces xe-0/0/2 unit 2000 description "Q-IN-Q TRANSPORT CE-1"
set interfaces xe-0/0/2 unit 2000 vlan-id 2000
set vlans V2000 description "PROVIDER VLAN 2000"
set vlans V2000 interface xe-0/0/2.2000
set vlans V2000 interface xe-0/0/1.2000
set interfaces xe-0/1/1 description "LINK TO PE-1 QFX"
set interfaces xe-0/1/1 vlan-tagging
set interfaces xe-0/1/1 unit 10 description "L3 VLAN 10"
set interfaces xe-0/1/1 unit 10 vlan-id 10
set interfaces xe-0/1/1 unit 10 family inet address 10.10.10.2/24
With this configuration, the MikroTik and MX204 were able to communicate correctly.
However, the customer connected to the MikroTik side had to enable the use-service-tag option.
The MikroTik configuration was therefore changed to:
/interface vlan
add interface=sfp-sfpplus2 name=vlan2000 vlan-id=2000
add interface=vlan2000 name=vlan10 use-service-tag=yes vlan-id=10
/ip address
add address=10.10.10.1/24 comment="Test QFX" interface=vlan10 network=10.10.10.0
After this change, the MX204 and MikroTik are no longer able to communicate.
The QFX configuration has remained unchanged.
My question is:
How can I modify only the Juniper QFX5110 configuration to make the MikroTik and MX204 communicate again?
I suspect the issue is related to the different VLAN tagging behavior introduced by use-service-tag=yes on the MikroTik side (802.1Q vs 802.1ad/service tag handling), but I am unsure how to adapt the QFX QinQ configuration correctly.
Any advice or example configuration would be appreciated.
Thank you.
r/Juniper • u/WittyOnDemand • 2d ago
Hello,
Is there any official communication on the EX3400 EOL timelines? When it was announced, last order date, end of support date etc? I have a customer who wants to upgrade to a newer equivalent switch, and they have the budget for it, but need some sort of formal announcement for a final CFO approval.
Many thanks!
r/Juniper • u/deutchschuler • 4d ago
I have a MX240 router. I would like to send the IPV4 lease information(MAC address, IP assignment) when a lease is bound and unbounded. Is this possible to do via a script on Juniper routers?
r/Juniper • u/Suitable_Dot_6999 • 6d ago
Hello there, I hope this post finds everyone in great mood, and it will stay like after reading this.
I'm looking for your wisdom on ex4100's IGMP configuration, where the switches run on 1.4a, and no additional licenses installed.
We have 4 ex41000 switches in ring topology with VLANs for multicast traffic. The goal is to be able to join any multicasts using IGMPv3 on any switch from the other ones. Within one switch, flooding the broadcast domain stops,and IGMPv3 joins work, if I enable igmp-snooping within a given VLAN, but I couldn't join devices connected on another switch within same VLAN.
As we do not have an L3 router, may I just attempt to configure a querier on any of these switches in the given VLAN, should that work? If yes, should that work without igmp-multicast license?
Thank you in advance for constructive comments
r/Juniper • u/VictimOfAReload • 7d ago
I've got an MX480 I'm looking to add 1-2 100G ports to. (Upgrading a transit provider to 20G on a 100G port). Box is not under support. Gear will be purchased on the grey market. So no juniper sales help either.
What's everyone's goto for 100G on MX?
I'm not fond of CFP optics and would rather go something QSFP28 based. Seems like the MPC7E-MRATE FPC fits the bill. Anybody have any issues with this card or a better recommendation?
r/Juniper • u/SalsaForte • 9d ago
Am I crazy (or a bit stupid), we need to reboot an HA cluster (both members at once). But, I can't find any clear documentation.
"request system reboot" isn't explicit about the behaviour. Says it will reboot the device, but we want/need to reboot the cluster (both members).
When I search Juniper or Google, I have plenty of example of sequential reboots, but no all members must go down at once.
r/Juniper • u/louisyoung7911 • 9d ago
folks, I have been trying to get this working.
I built a wifi network using AP43s but the throughput is very low, I've already confirmed that they are using 1GE uplink, so my expectation should be at least 500Mbps download and above with 5Ghz
However when connecting to this mist AP's SSID, speedtest.net says only around 250Mbps download rate.
I also have VZ FIOS WIFI router and WIFI extender enabled another SSID for testing and comparison, exactly same spot I get 690Mbps download, and the neither the WIFI router nor the WIFI extender is closed to me (WIFI router in different floor, WIFI extender is like 35 feet away.
I wonder if it is a configuration problem(I'm not a wifi expert), can you please help?
Things I did
- tried different AP versions (13.x, 12.x, 14.x), no difference
- tried setting to 40Mhz on 5Ghz, speed get worse
- already confirmed the APs I connected has physical direct uplink ethernet wire to the switch(not a juniper switch)
- tried to directly connect to the switch using wired connection, speed is 910Mbps download
- WIFI 6 or 7 disabled, as AP43 does not support these


edit: uploaded speed test snapshot
r/Juniper • u/PlanEx_Ship • 12d ago
I have two distribution layer network consisting of EX4300 in VC, 2 or 3 units per VC.
Two sets of VC consists one VRRP router, runs its own OSPF area and PIM-Sparse for about 1000 IP cameras each. The network consists of about ~ 200 OSPF routes, ~2,000 end devices (ARP entries), ~2,000 PIM routes/IGMP groups, ~60 VLANs, and ~5Gbps traffic flows through each layer at any given time.
Technically it should be well within the hardware specification of the switch, but I find the switches are sluggish when I connect to SSH, and users also complain (little bit, not much) about random slow network response especially during the day when there are most users.
I hooked up an NMS (Zabbix) and monitored the switches for past few months, and the CPU of main routing engine is almost constantly at 80%+ in both cases. Spikes very often to 100%.
I am thinking, maybe 4300s are not meant to be used as a full blown router for this kind of setup.. but maybe I could be missing something and just some optimisation is needed? I stormed my brain hard digging through every config elements but cannot find anything useful that seem to reduce the load in any meaningful way.
I'd love to hear any other real world experiences with EX4300s in the field.
r/Juniper • u/Amazing_Falcon • 12d ago
Need some thoughts on the setup. Our internet come in on the Stack (A), Stack (B), Stack (C), and finally Stack (D). The fiber between Stack (A) and Stack (D) is turned off right now. When the Stack (A) and Stack (D) are connected and is turned on the network traffic shuts down. My AD is on Stack (D). The link between Stack (A) and Stack (D) is the shortest single jump. The other way traffic has to go between multiple hops to get to AD. I would like to get the Stack (A) to Stack (D) traffic going and use the other as the backup traffic. Any ideas on what I need to check and how would be the best way to determine issue.
Thanks for the help.

r/Juniper • u/DonFazool • 13d ago
Hello everyone,
We use Secure Connect with our SRX1500. We have a number of Mac users (myself included) who are seeing warnings that the current Secure Connect will cease to function in upcoming Mac OS update (Which I believe is next year).
The app is currently complied only for Intel binaries. We are running the latest build from Jan 2025.
Curious if anyone has knowledge if they will release a proper Apple Silicon build ?
r/Juniper • u/Background_Box_1726 • 13d ago
Hi everyone,
I'm currently evaluating the Juniper ACX6360 and would like to check if anyone has experienced similar Layer 2 forwarding behavior.
Lab Topology:
QFX5110 ---- ACX6360 ---- ACX6360 ---- QFX5110
The goal is simply to bridge Ethernet traffic end-to-end between the two QFX switches.
The following have been verified:
- Physical interfaces are up and stable.
- Optics, fiber, and FEC are all healthy.
- Layer 3 routing works perfectly across the ACX6360s.
- Direct IP connectivity between the ACX6360s has 0% packet loss.
- Static ARP entries were configured on the QFX5110s to eliminate ARP resolution as a possible issue.
However, the following Layer 2 issues were observed:
- Dynamic MAC learning never occurs on the ACX6360.
- ARP broadcasts are received on the ingress interface but are not forwarded to the remote ACX6360.
- Unknown unicast traffic is not flooded.
- Static MAC entries can be configured and appear correctly in the Ethernet switching table, but traffic is still not forwarded.
- Local CCC (interface-switch) testing also failed to forward Ethernet frames.
The platform is running Junos 19.4R2-S2.4.
Has anyone encountered this before?
I'm trying to determine whether this is:
- a platform limitation of the ACX6360,
- a Junos 19.4 software limitation,
- or if I'm missing a specific configuration required for Layer 2 Ethernet switching.
Has anyone successfully used the ACX6360 as a pure Layer 2 Ethernet switch or bridge (without MPLS/EVPN), or is it really intended to operate primarily as an IP/MPLS transport router?
Any insights or experiences would be greatly appreciated. Thanks!
r/Juniper • u/AutoModerator • 13d ago
It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!
Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.
Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.
r/Juniper • u/Affectionate-Cook321 • 14d ago
We have a large fleet of APs purchased from Juniper/Mist. We have a handful of second-hand APs bought through used channels.
There is a new behavior that APs that have been released by the previous owner can be claimed, but will not join the cloud. When we open a trouble ticket - Mist comes back and asks the provenance and will not allow us to use the AP as it was purchased by a different organization.
I actually have 1 AP that was in production for 3 years and stopped working - I finally realized it had been purchased on eBay as a single fill-in in 2023.
Additionally, the "Global 1" Cloud is full. New organizations have to go into other clouds and APs cannot move between clouds even after being released. So now I can't even move APs between 2 organizations that I manage.
Anyone else seeing this? It is frustrating and problematic for me because it also means that when I retire 200 APs in a couple of years, I will have to throw them out as there is no second-hand market.
r/Juniper • u/AutoModerator • 20d ago
It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!
Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.
Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.
r/Juniper • u/Illustrious-Wash3905 • 23d ago
Any idea when more info will be posted about this platform? I saw the press release a few months ago but there is no other mention of the srx400 series on the juniper or hpe websites. Not even a datasheet let alone a release timeframe. I have been expecting to see the srx300 eol announcement for years.
r/Juniper • u/ThiccStevie • 26d ago
Hello everyone! I work on a airgapped system with a bunch of internal wire walls. I’m curious how to automate my signatures. I know that I have to manually move the files onto the network but from there could I automate the file pull to the firewall and the installation of the package?
r/Juniper • u/Few_Description_7647 • 27d ago
Hello everyone,
I am planning to upgrade a Juniper SRX1500 chassis cluster from 23.4R2-S5.5 to 23.4R2-S7.4 via CLI. Could you advise on the best upgrade approach to ensure minimal downtime?
Thank you
r/Juniper • u/Qvosniak • 27d ago
Hey guys,
I can't find this being discussed anywhere.
Let's focus on a single SRX for now
The STX connects to two l2 Aruba Switches (which are connected via VSX)
I originally planned to have two interfaces that belongs to fab0, one link connects to SW1 whilst the other connects to SW2.
I thought for some reason they would establish LACP with the switches, I even configured both Switches interfaces to be a lag interface with LACP active
When I check the switches, the LACP is of course down. they are acting as access ports btw.
Does this mean it's not allowed using fabric links as LACP!?
I know you can do it with RETH interfaces and this works just fine, but fabric links tho?
r/Juniper • u/AutoModerator • 27d ago
It's Thursday, and you're finally coasting into the weekend. Let's open the floor for a Weekly Question Thread, so we can all ask those Juniper-related questions that we are too embarrassed to ask!
Post your Juniper-related question here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer.
Note: This post is created at 00:00 UTC. It may not be Thursday where you are in the world, no need to comment on it.
r/Juniper • u/PP_Mclappins • 29d ago
Hey all, I wanted to ask about a config knob, the one that makes up the subject line.
For clarification, I'm hoping to find out what it's actually used for.
I ask this because at our primary HQ, I'm working on some issues with the LACP link back to our core switch from the 5-member access chassis in the MDF.
We have 10g multimode links using identical SFPs, Patches, Etc between the two.
The Core switch seems to be killing the link on xe-0/2/0 of the access switch, I'm seeing on that side that the link is just going down and then coming back up. On the core side, I'm seeing the link timeout according to the mist switch insights, I'm also seeing these timeouts on other aggregate links as well. The one thing I noticed, is that on the core, the aggregated devices knob is not setup at all. Which is weird to me, because in my experience, I've always needed to add that to the config for LACP to work properly. Essentially, I want to fix these timeouts, because I think they are related to some end user issues, and complaints we gotten, but I don't want to break my network lol

r/Juniper • u/Additional_Gap1057 • Jun 21 '26
I have this setup
end devices -> juniper access -> cisco access -> cisco core switch
I have this setup to test out juniper switch, I have 2 end devices connected to the Juniper Switch, and I know exactly which interfaces they are connected to.
I have been testing a NAC solution to verify whether dynamic VLAN assignment works correctly on Juniper Switch. Initially, NAC was able to change the VLAN assignment, but there was a problem with IP assignment from DHCP server. I would see that end PCs are having the APIPA IP instead.
To keep it short, It might be related to SNMP traps, because it would assign IP if I do L2 polling in the NAC.
Until then I decided to shut both ports (physical and logical) in Juniper Switch, because I don't even see the MAC addresses in the ether-swtich table.
However, the mac address of one end device is still exist in the Cisco Access Switch and it never disappears. How's that even possible? I am about to go crazy.
Thank you in advance. I am new to Juniper Swtiches. (please be kind )
r/Juniper • u/Banan1803 • Jun 19 '26
Hello. After updating my EX2300-24P to JunOS 23.4R2-S8 I am seeing an alarm - "FPC 0 PoE device manager 2 failed". I think PoE is working correctly, but the alarm is unexpected. I tried updating PoE controller using request system firmware upgrade poe fpc-slot 0 and cold restart, but alarm is still present on the device.
I have Type1 PoE controller. Before the controller update it was 1.6.1.21.1 firmware, now it is 2.1.1.19.3.
I read that this alarm says about version BT of PoE and this version isn't exist on EX2300-24P.
Is there a way to hide or suppress this alarm? Maybe someone has the same problem?