Install or Recover Junos OS on SRX Series Firewalls by Using a PXE Boot Server
Learn how to install or recover Junos OS on SRX Series Firewalls (SRX1600, SRX2300, SRX4120, SRX4300, and SRX4700) using a PXE boot server.
A Preboot Execution Environment (PXE) prepares a client-server environment that enables a device to boot from the network, independent of local storage devices or any installed operating system. During a PXE boot, the device obtains network configuration information and downloads the files required to boot from a PXE server. You can perform a PXE boot to install the software over the network. PXE booting is commonly used to deploy operating systems to new devices, reimage or recover systems, perform centralized operating system installations, run diagnostic or recovery tools, or manage large-scale device provisioning in enterprise environments. PXE booting is especially useful when a device does not have a functioning operating system, lacks local installation media, or when organizations need a consistent and automated method for deploying and maintaining multiple systems.
Use Feature Explorer to confirm platform and release support for specific features.
PXE boot for the SRX1600, SRX2300, SRX4120, SRX4300, and SRX4700 Firewalls requires three servers working together:
DHCP server—Assigns the device its management IP address and points it to the TFTP server and bootloader file.
Trivial File Transfer Protocol (TFTP) server—Delivers the bootloader, GRUB, and the Linux kernel once the device has the TFTP server address.
Application/NFS server—Hosts the Junos OS image that the device downloads and installs.
Configure the DHCP Server
During PXE boot, the SRX Firewall sends a DHCP request to acquire its management IP address, the TFTP server address, and the bootloader file information. This example uses the ISC DHCPD server and its dhcpd.conf configuration file. If you use a different DHCP server implementation, configure the equivalent settings according to your DHCP server documentation.
To configure the DHCP server:
Set Up Trivial File Transfer Protocol (TFTP) Server on PXE Environment
Once the SRX gets the TFTP server IP address from the DHCP server, it loads the bootloader, GRUB, and the Linux kernel from the TFTP server.
To set up TFTP server, follow the below steps:
Set Up Application/NFS Server on PXE Environment
The Application (NFS) server hosts the Junos OS image. The SRX reads the application server's IP address from grub-startup.cfg, then mounts the application server's /var/install directory over NFS to fetch the image and other install components.
Before you begin, enable the NFS mount service on the application server and confirm that it allows the SRX to mount the /var/install directory.
To set up PXE environment on Application/NFS server:
Initiate PXE Boot
Before you upgrade the software, configure the DHCP, TFTP, and application/NFS servers, and ensure that console access to the device is available. Once the three servers are ready, initiate the PXE boot from the SRX.
There are two ways to initiate the PXE boot on the SRX:
Initiate the PXE Boot Using the CLI
To initiate the PXE Boot using the CLI, perform the following steps:
Log in to the device through the console and run
request vmhost reboot network. The device shuts down Junos OS and reboots.user@host> request vmhost reboot network Reboot the vmhost ? [yes,no] (no) yes
During bootup, the device downloads the PXE bootloader over the network and then loads the kernel and
initrdfrom the TFTP server.>>Start PXE over IPv4. Station IP address is 10.157.66.242 Server IP address is 10.82.97.28 NBP filename is /volume/tftpboot/swt/user/prog/pxe/bootx64.efi NBP file downloaded successfully. Secure Grub2 PXEboot Booting `net boot console' Loading kernel ... Loading initrd...platform is SRX4300
Confirm the installation when prompted.
This installation erases the contents of both disks on the device. Confirm you are connected to the intended device before you respond y. The installer copies the vmhost image to the primary and secondary disks, and sets the boot order to boot from the newly installed disk.Install vmhost and Junos software on Primary and Secondary disk [y/N]? y
Copying /var/install/vmhost/vmhost-x86_64-26.2R1-20260520_1003_builder.img.gz to tmp dir ... Upgrade Capsule BIOS Version: 00.29.01 setup ssd for nextboot BootOrder: 0000 Boot0000* HDD00.1
Confirm the reboot when prompted to complete the installation.
Reboot now? [y/N]? y Please remove boot USB key if any after reboot... Rebooting.
Initiate PXE Boot Using the Boot Manager
Before using the Boot Manager, ensure there is console access to the device. If the CLI is not available, power-cycle the device and start the PXE boot from the Boot Manager menu:
When the prompt to access the boot options appears, press Esc.
In the Boot Manager menu, navigate to EFI Boot Devices > Network, select ETH00, and press Enter.
The device starts the PXE boot over IPv4 and proceeds through the same installation steps described in Initiate PXE Boot Using the CLI, starting from the point where the device downloads the PXE bootloader over the network and then loads the kernel and initrd from the TFTP server.