Configuration Pushed to Devices During Device Adoption
This topic lists the configuration pushed to the devices during device adoption.
When a device connects to Routing Director, specific commands are pushed to the device to enable management and telemetry collection. This topic lists those commands and provides a brief description of their purpose.
Configuration Applied During Adoption
- Event Generation
- Link Event Policies
- Configuration Change Monitoring
- System Event Monitoring
- Statistics Aggregation Policy
- Event Script Registration
- Enable Script Framework
- System Log Configuration
- Configuration for gNMI-over-TLS Connection
- Verification
Event Generation
The following commands are committed to:
-
Generate an event every 180 seconds to collect operational statistics from the device.
-
Generate an event daily to monitor the available disk space.
set groups jcloud-script event-options generate-event get-stats-every-three-minute time-interval 180 set groups jcloud-script event-options generate-event monitor-diskspace-now time-interval 86400
Link Event Policies
The following commands are committed to monitor change in the interface operational status.
set groups jcloud-script event-options policy log-on-snmp-trap-link-up events snmp_trap_link_up
set groups jcloud-script event-options policy log-on-snmp-trap-link-up within 90 not events chassisd_vchassis_member_update_notice
set groups jcloud-script event-options policy log-on-snmp-trap-link-up attributes-match "{$.interface-name}" matches "^[^.]+$"
set groups jcloud-script event-options policy log-on-snmp-trap-link-up then event-script jcloud_link_up_logger.py
set groups jcloud-script event-options policy log-on-snmp-trap-link-down events snmp_trap_link_down
set groups jcloud-script event-options policy log-on-snmp-trap-link-down within 90 not events chassisd_vchassis_member_update_notice
set groups jcloud-script event-options policy log-on-snmp-trap-link-down attributes-match "{$.interface-name}" matches "^[^.]+$"
set groups jcloud-script event-options policy log-on-snmp-trap-link-down then event-script jcloud_link_down_logger.py
Configuration Change Monitoring
The following commands configure an event policy that automatically runs the jcloud_acx_event_dispatcher.py script after a configuration is successfully committed on the device.
set groups jcloud-script event-options policy backup-cfg-after-commit events ui_commit_completed set groups jcloud-script event-options policy backup-cfg-after-commit then event-script jcloud_acx_event_dispatcher.py
System Event Monitoring
The following commands configure an event policy within the
jcloud-script configuration group to run a script
jcloud_acx_event_dispatcher.py when any of the
following events occur:
-
A
commit confirmoperation is not confirmed within a specified timeout period, causing Junos OS to roll back the configuration. -
When the device or Routing Engine is restarted.
-
High availability (HA) events such as:
-
HA control link failure or the recovery of the HA control link.
-
HA node health falls below the configured threshold.
-
HA node health has recovers above configured threshold.
-
Change in the state of the HA node (for example from primary to secondary and secondary to primary).
-
A critical HA-related process or redundancy daemon fails.
-
-
Mismatch in Services Processing Unit (SPU) count between HA peers
-
Failure and recovery in Service Redundancy Group (SRG) health
-
Change in state of SRG (active to standby and standby to active)
-
Change in the state of redundancy group (primary to secondary and secondary to primary)
set groups jcloud-script event-options policy log-on-system-events events ui_commit_not_confirmed set groups jcloud-script event-options policy log-on-system-events events snmpd_trap_cold_start set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_control_link_down set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_control_link_upset groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_health_weight_low set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_health_weight_recovery set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_node_status_change set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_re_daemon_failed set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_spu_num_mismatch set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_srg_health_down set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_srg_health_up set groups jcloud-script event-options policy log-on-system-events events jsrpd_ha_srg_state_chang set groups jcloud-script event-options policy log-on-system-events events jsrpd_rg_state_change set groups jcloud-script event-options policy log-on-system-events then event-script jcloud_acx_event_dispatcher.py
Statistics Aggregation Policy
The following commands are committed to generate an event to collect statistics every three minutes and execute the jcloud_acx_event_dispatcher.py script whenever statistics is collected.
set groups jcloud-script event-options policy events-aggr-policy events get-stats-every-three-minute set groups jcloud-script event-options policy events-aggr-policy then event-script jcloud_acx_event_dispatcher.py
Event Script Registration
The following commands register the Junos OS and Junos OS Evolved event scripts,
specify the local user account that will run the scripts, and apply the
jcloud-script group so that all the policies defined during
adoption and script settings become active.
set groups jcloud-script event-options event-script file jcloud_acx_event_dispatcher.py python-script-user jcloud-dev
set groups jcloud-script event-options event-script file jcloud_acx_event_dispatcher.py checksum sha-256 01a667f53dd74d3fc1aaa7de142b86609386d042645f2468241b5274ae425d02
set groups jcloud-script event-options event-script file jcloud_link_up_logger.py python-script-user jcloud-dev
set groups jcloud-script event-options event-script file jcloud_link_up_logger.py checksum sha-256 c67ea293da84c0940a858dfcc5a2a94c48387f37542bc19f69685e5ebf0fd8c4
set groups jcloud-script event-options event-script file jcloud_link_down_logger.py python-script-user jcloud-dev
set event-options event-script file jcloud_link_down_logger.py checksum sha-256 ed1005fde300ba09a1ad84f044a7c281ab51e4f3c042ef3029ca02f93bbe093d
set groups jcloud-script event-options event-script file jcloud_backup_cfg.py python-script-user jcloud-dev
set event-options event-script file jcloud_backup_cfg.py checksum sha-256 63bbf28cef709fe1dcc2ea57fd698a230475e26bcc51946689c4c955c41d3697
set groups jcloud-script event-options event-script file jcloud_link_event_capturer.py python-script-user jcloud-dev
set event-options event-script file jcloud_link_event_capturer.py checksum sha-256 c1caa54bb815265fd237c5b9feba8513874b6109a962f303c6111042752a5577
set groups jcloud-script event-options event-script file jcloud_event_aggregator.py python-script-user jcloud-dev
set event-options event-script file jcloud_event_aggregator.py checksum sha-256 834334b120e41a645e05cd93d5cbb8e8257818852c34715f4094eb2b3ae3d31c
## Apply Configuration Group ##
set apply-groups jcloud-script
Dual-Routing Engine Devices
The following command is committed to apply the configuration groups
global, re0, re1, and
jcloud-script to the device's active configuration, causing
all settings defined in those groups to take effect.
set apply-groups [ global re0 re1 jcloud-script ]
Virtual Chassis systems:
The following command is committed to apply the configuration groups
global, member0, and
jcloud-script to the device's active configuration, making
all settings defined within those groups effective.
set apply-groups [ global member0 jcloud-script ]
Enable Script Framework
Junos OS devices
The following commands are committed to enable Python scripting on the devices running Junos OS and Junos OS Evolved ensure that script files are automatically replicated across redundant Routing Engines.
set system scripts language python set system scripts synchronize
Junos OS Evolved and newer EX and QFX devices
The following commands are committed to enable Python-3 based automation scripts on devices running Junos OS Evolved and newer EX and QFX devices to ensure that files are automatically replicated across redundant Routing Engines.
set system scripts language python3 set system scripts synchronize
Dual-Routing Engine devices
The following command is committed to synchronize configuration changes on both the Routing Engines of a dual-Routing Engine device.
set system commit synchronize
System Log Configuration
The following commands are committed to configure log files, define log rotation, and specify what events are recorded in the logs. Log files are rotated after reaching 2MB size and up to five log files are retained.
set system syslog file escript.log archive size 2m
set system syslog file escript.log archive files 5
set system syslog file interactive-commands match "!(.*mist.*)"
set system syslog file interactive-commands archive size 2m
set system syslog file interactive-commands archive files 5
set system syslog file jcloud-syslog-messages any warning
set system syslog file jcloud-syslog-messages structured-data
set system syslog file jcloud-syslog-messages archive size 2m
set system syslog file jcloud-syslog-messages archive files 5
set system syslog file op-script.log archive size 2m
set system syslog file op-script.log archive files 5
set system syslog file snapshot archive size 2m
set system syslog file snapshot archive files 5
The following additional commands are committed on EX and QFX Series devices to configure the standard messages log file. This log file records all events related to authorization. For example, user login attempts, authentication successes or failures, privilege changes, SSH access, user account activities, and TACACS+ and RADIUS authorization events.
All severity levels are logged and the log file is rotated after reaching 2MB size. Up to five log files are archived.
set system syslog file messages authorization any set system syslog file messages archive size 2m set system syslog file messages archive files 5
Configuration for gNMI-over-TLS Connection
The following commands are committed to create a PKI Certificate Authority (CA)
profile named jcloud_gnmi_ca and associate it with a CA
certificate identified as jcloud_gnmi_ca for enabling a
gNMI-over-TLS connection between Routing Director and the device.
## PKI Configuration if gNMI TLS authentication is required:
# Device TLS Identity
set security certificates local gnmi-terminator.juniper.net "PRIVATE-KEY-AND-CERTIFICATE"
# Trusted Certificate Authority
set security pki ca-profile jcloud_gnmi_ca ca-identity jcloud_gnmi_ca
Verification
The following commands are committed to view and list the configured event policies, event scripts, system scripts, configuration groups, and view contents of escript.log and op-script.log.
show event-options policy show event-options event-script show system scripts show configuration groups jcloud-script show log escript.log show log op-script.log
Telemetry and Monitoring RPCs Executed After Device Adoption
This section provides a list of the remote procedure calls (RPCs) executed on devices to gather operational statistics and monitor device health after device adoption.
- Interface Statistics Collection
- Alarm Monitoring
- Environment Monitoring
- Switched Virtual Interfaces (SVI) Discovery
Interface Statistics Collection
The following RPC is executed to retrieve the output of the show
interfaces extensive command in a structured XML format.
<request-shell-execute>
<command>
/usr/sbin/cli -c 'show interfaces ... extensive | display xml'
</command>
</request-shell-execute>
Supported Platforms: ACX, MX, and PTX
Alarm Monitoring
The following RPCs are executed to retrieve the alarm information from the device.
<get-alarm-information/>
<get-system-alarm-information/>
Supported Platforms: ACX, MX, and PTX
Environment Monitoring
The following RPCs are executed to discover hardware inventory and verify device health.
<get-environment-information/> <get-chassis-inventory/>
Supported Platforms: ACX, MX, and PTX
Switched Virtual Interfaces (SVI) Discovery
The following RPCs are executed to retrieve routing information learned through
the Local routing protocol and stored in the device.
get-route-information destination=0.0.0.0 active-path get-route-information protocol=local
Supported Platforms: ACX and MX