Install or Recover Junos OS on SRX Series Firewalls by Using a PXE Boot Server

Learn how to install or recover Junos OS on SRX Series Firewalls (SRX1600, SRX2300, SRX4120, SRX4300, and SRX4700) using a PXE boot server.

A Preboot Execution Environment (PXE) prepares a client-server environment that enables a device to boot from the network, independent of local storage devices or any installed operating system. During a PXE boot, the device obtains network configuration information and downloads the files required to boot from a PXE server. You can perform a PXE boot to install the software over the network. PXE booting is commonly used to deploy operating systems to new devices, reimage or recover systems, perform centralized operating system installations, run diagnostic or recovery tools, or manage large-scale device provisioning in enterprise environments. PXE booting is especially useful when a device does not have a functioning operating system, lacks local installation media, or when organizations need a consistent and automated method for deploying and maintaining multiple systems.

Use Feature Explorer to confirm platform and release support for specific features.

PXE boot for the SRX1600, SRX2300, SRX4120, SRX4300, and SRX4700 Firewalls requires three servers working together:

  1. DHCP server—Assigns the device its management IP address and points it to the TFTP server and bootloader file.

  2. Trivial File Transfer Protocol (TFTP) server—Delivers the bootloader, GRUB, and the Linux kernel once the device has the TFTP server address.

  3. Application/NFS server—Hosts the Junos OS image that the device downloads and installs.

Note: Configure the DHCP, TFTP, and application/NFS servers before initiating the PXE boot process on the SRX Firewalls. Ensure that the IP addresses configured for the DHCP, TFTP, and application/NFS servers are reachable from the PXE client network and are assigned to the interfaces through which the PXE client communicates with these services.

Configure the DHCP Server

During PXE boot, the SRX Firewall sends a DHCP request to acquire its management IP address, the TFTP server address, and the bootloader file information. This example uses the ISC DHCPD server and its dhcpd.conf configuration file. If you use a different DHCP server implementation, configure the equivalent settings according to your DHCP server documentation.

To configure the DHCP server:

  1. Add an entry for the device in the dhcpd.conf file. For example:

    The entry uses the following parameters:

    Parameters Description
    Hostname The PXE server's hostname
    Hardware ethernet The MAC address of the interface that sends the DHCP request
    Fixed-address The management IP address of the SRX series
    Next-server The TFTP server address
    Filename The complete path to the bootloader on the TFTP server
    Option root-path The root path attribute—the path before the PXE directory
  2. Obtain the hardware ethernet (MAC) address of the management interface by running efibootmgr on the device and noting the ETH00 entry.
    Record the MAC address displayed for ETH00. You will use this value in the DHCP server configuration as the hardware ethernet value.
    Note: The vhclient efibootmgr command requires j-superuser privileges.
    Boot0005 is the ETH00 entry. The value shown in parentheses (74:29:72:0E:19:81) is the MAC address to use as the hardware ethernet value.

Set Up Trivial File Transfer Protocol (TFTP) Server on PXE Environment

Once the SRX gets the TFTP server IP address from the DHCP server, it loads the bootloader, GRUB, and the Linux kernel from the TFTP server.

To set up TFTP server, follow the below steps:

  1. Create the device directory and its PXE subdirectory on the TFTP server: /volume/tftpboot/swt/user/prog/pxe.
  2. Copy the PXE installation package junos-vmhost-install-net-*.tgz into the PXE directory.
  3. Untar the package:
  4. Untar the resulting vmhost-install-net-*_builder.tgz file:
    This adds vmlinuz, initramfs, bootx64.efi, and a secure-boot directory alongside the files extracted in the previous step.
  5. Move the secure-boot directory up one level so it sits alongside the pxe directory—not inside it.
  6. Create a symbolic link to secure-boot inside the pxe directory:
  7. Edit the grub-startup.cfg file in the secure-boot directory. Update the paths so they point to the actual PXE directory created in Step 2. The server_ip must be the IP address of the application/NFS server, and the linux and initrd paths must point to the PXE directory you created in step 2.
  8. Set the permissions on the TFTP device directory:

Set Up Application/NFS Server on PXE Environment

The Application (NFS) server hosts the Junos OS image. The SRX reads the application server's IP address from grub-startup.cfg, then mounts the application server's /var/install directory over NFS to fetch the image and other install components.

Before you begin, enable the NFS mount service on the application server and confirm that it allows the SRX to mount the /var/install directory.

To set up PXE environment on Application/NFS server:

  1. Navigate to the /var/install directory on the application server.
  2. Copy the junos-vmhost-install-*.tgz package from the TFTP server to the application server.
  3. Untar the junos-vmhost-install-*.tgz package.
    The package expands into the scripts, vm, vmhost, hostd, and junos directories, along with the vmhost and Junos OS install images that the SRX downloads during installation.

Initiate PXE Boot

Before you upgrade the software, configure the DHCP, TFTP, and application/NFS servers, and ensure that console access to the device is available. Once the three servers are ready, initiate the PXE boot from the SRX.

There are two ways to initiate the PXE boot on the SRX:

Initiate the PXE Boot Using the CLI

To initiate the PXE Boot using the CLI, perform the following steps:

  1. Log in to the device through the console and run request vmhost reboot network.

    The device shuts down Junos OS and reboots.
  2. During bootup, the device downloads the PXE bootloader over the network and then loads the kernel and initrd from the TFTP server.

  3. Confirm the installation when prompted.

    This installation erases the contents of both disks on the device. Confirm you are connected to the intended device before you respond y. The installer copies the vmhost image to the primary and secondary disks, and sets the boot order to boot from the newly installed disk.
  4. Confirm the reboot when prompted to complete the installation.

Initiate PXE Boot Using the Boot Manager

Before using the Boot Manager, ensure there is console access to the device. If the CLI is not available, power-cycle the device and start the PXE boot from the Boot Manager menu:

  1. When the prompt to access the boot options appears, press Esc.

  2. In the Boot Manager menu, navigate to EFI Boot Devices > Network, select ETH00, and press Enter.

The device starts the PXE boot over IPv4 and proceeds through the same installation steps described in Initiate PXE Boot Using the CLI, starting from the point where the device downloads the PXE bootloader over the network and then loads the kernel and initrd from the TFTP server.