ON THIS PAGE
Perform Common Tasks
This topic provides tips for using Junos OS CLI.
This topic highlights lesser‑known Junos OS CLI commands and configuration options that improve day‑to‑day operational efficiency.
Operational Commands
- Flap a Port Without Bouncing the Config
- Auto-Refresh a Show Command
- Clear the Terminal Screen
- Resolve IP Addresses iin Command Output
- Display Inherited Configuration without Comments
- Live Traceroute with Continuous Refresh
- Show Interface Descriptions in Traffic Monitor
- Properly Clear Log File
- Unlock the Configuration Database
Flap a Port Without Bouncing the Config
Use the bounce option to administratively cycle a port at a
configurable interval instead of deactivating and reactivating the interface or
reseating the cable.
user@router> request interface bounce interval <ms> et-1/1/1
The interval parameter specifies the down duration in milliseconds.
Use it to force link renegotiation or reestablish BFD, LDP, or BGP sessions on a
specific interface without modifying the configuration.
Auto-Refresh a Show Command
Append | refresh <seconds> to any operational command to have it re-execute automatically at the specified interval, similar to the Linux watch command.
show bgp summary | refresh 5
If you do not specify an interval, the default is 1 second. Press Ctrl+C to stop. Use this option to monitor BGP session state during maintenance or convergence events.
Clear the Terminal Screen
Clears the terminal buffer—equivalent to the Unix clear command.
clear cli screen
Resolve IP Addresses iin Command Output
Append | resolve to an operational command to have Junos OS perform reverse DNS resolution on IP addresses found in the output, replacing raw IPs with hostnames where available.
show bgp summary | resolve
Enabling this option helps you read routing tables or BGP summaries more efficiently, provided the environment has well-maintained DNS PTR records.
Display Inherited Configuration without Comments
When you use apply-groups or apply-macro, the | display inheritance command shows the fully resolved configuration after group expansion. Appending the no-comments option strips the inline annotations that indicate the source group of each inherited line, resulting in a clean output.
show configuration | display inheritance no-comments
This is essential when auditing the effective running configuration without the noise of /* inherited from group ... */ comments.
Live Traceroute with Continuous Refresh
Traceroute monitor combines traceroute with a continuous auto-refresh display, similar to MTR on Linux. It provides a live view of per-hop RTT and packet loss.
traceroute monitor 10.0.0.1
Use this option instead of a single traceroute to diagnose intermittent latency or path changes on a live network.
Show Interface Descriptions in Traffic Monitor
The standard monitor interface traffic output does not show interface descriptions. Adding detail reveals the configured description alongside traffic counters, making it much easier to identify interfaces at a glance.
monitor interface traffic detail
This is especially useful on dense chassis like the MX10004 where interface names alone (e.g., et-3/0/15) carry little operational context without descriptions.
Properly Clear Log File
Do not delete or truncate a log file directly, because it leaves no record of the
action. Use the clear log command to empty the file and create an
audit entry that records the event.
clear log messages show log messages Apr 24 02:27:14 rtme-mx304-06 clear-log: logfile
The resulting clear-log syslog entry confirms the timestamp of the
clear command, which is important for security information and
event management (SIEM) correlation and audit trails.
Unlock the Configuration Database
If a user leaves an exclusive configuration session open, other users cannot commit. Identify the session and log out the user by using the following command:
show system configuration database status
Users currently editing the configuration:
lab terminal pts/0 (pid 78144) on since 2026-04-24 02:11:47 PDT, idle 00:07:22
exclusive [edit]
request system logout pid 78144
This command terminates the blocking session and releases the exclusive configuration lock. Use this command with caution because it discards any uncommitted changes in that session.
Configuration Commands
- Reset Root Auth Password
- Disable Pagination for Scripting
- Add a Timestamp to every CLI Output Line
- Protect a Configuration Branch
- Replace Any Pattern in the Configuration
- Wildcard Range Operations
- Assign an Alias to a Logical Interface
- Apply a Config Diff Directly with Load Patch Terminal
Reset Root Auth Password
To reset the root authentication password on a Juniper MX device, use the following configuration command in configuration mode:
set system root-authentication plain-text-password
Disable Pagination for Scripting
By default, Junos OS paginates command output using the --more-- prompt. Setting screen-length 0 disables pagination entirely, which is essential when piping output to scripts or capturing the complete output of a show command over an SSH session.
set cli screen-length 0
This setting applies to the current CLI session only and does not modify the permanent device configuration.
Add a Timestamp to every CLI Output Line
Use this command to prepend a timestamp to each line of the CLI output. This is useful when capturing a live troubleshooting session to correlate events with system log entries.
set cli timestamp
After you enable this, the system prefixes every operational command output line with
the current date and time. To deactivate this feature, run the cli timestamp
disable command.
Protect a Configuration Branch
The protect and unprotect configuration mode
commands lock a specific hierarchy branch against accidental modification or
deletion. The system prevents changes to a protected stanza until you explicitly
unprotect it.
[edit interfaces et-1/1/1] user@router# protect
This is useful for protecting critical configuration elements (e.g., protocols parent-level, OOB management interface, loopback, emergency ACLs) from being accidentally overwritten during bulk changes.
[edit interfaces et-1/1/1] user@router# unprotect
Replace Any Pattern in the Configuration
The replace pattern command performs a global search-and-replace using regular expressions (enclosed in quotation marks) across either the entire candidate configuration or a specific hierarchy level. This is particularly powerful for bulk renaming of policy names, communities, prefixes, or interface references.
replace pattern “<old-pattern-regex-supported>” with <new-pattern>
Example—rename all occurrences of a routing policy:
replace pattern EXPORT-OLD with EXPORT-NEW
Always review the diff with show | compare before committing, as the replace operates globally across all configuration hierarchies.
Wildcard Range Operations
The wildcard range command applies a configuration operation—such as set, delete, deactivate, or protect—to a range of interfaces or objects simultaneously, eliminating the need for repetitive, individual modifications.
wildcard range ? Possible completions: activate Remove the inactive tag from a statement annotate Annotate the statement with a comment deactivate Add the inactive tag to a statement delete Delete a data element protect Protect the statement set Set a parameter show Show a parameter unprotect Unprotect the statement
Example—deactivate a range of unit interfaces in one shot:
wildcard range deactivate interfaces et-0/0/0 unit [100-200]
Example—set a description on a range of interfaces:
wildcard range set interfaces et-0/0/<0-11> description "CORE-LINK"
Assign an Alias to a Logical Interface
Junos OS allows you to assign a human-readable alias to a logical interface (IFL). You can then use this alias in place of the numeric unit name when executing operational commands.
set interfaces et-0/0/8 unit 3000 alias coreif
After configuring the alias, you can use the alias directly in show commands:
show interfaces coreif
Logical interface coreif (Index 330) (SNMP ifIndex 567)
Flags: Up SNMP-Traps 0x4000 VLAN-Tag [ 0x8100.3000 ] Encapsulation: ENET2
Input packets : 206705
Output packets: 239138
Protocol inet, MTU: 9186
This eliminates the need to remember or look up unit numbers for frequently accessed interfaces and is compatible with most variations of the show interfaces command.
Apply a Config Diff Directly with Load Patch Terminal
The load patch terminal command allows you to paste the output of a show | compare diff directly into another router's configuration session, applying only the delta rather than a full configuration replace. This is the cleanest way to replicate a specific configuration change from one device to another without touching the rest of the config.
The input uses the standard Junos OS unified diff format, with lines prefixed with a plus sign (+) for additions and a minus sign (-) for deletions. To terminate the input, press Ctrl+D on a new line.
load patch terminal
[Type ^D at a new line to end input]
[edit protocols bgp]
group cluster-pod1 { ... }
+ group TEST {
+ type external;
+ peer-as 65001;
+ neighbor 172.16.0.1;
+ }
^D
load complete
Verify the result with show | compare before committing:
show | compare
[edit protocols bgp]
+ group TEST {
+ type external;
+ peer-as 65001;
+ neighbor 172.16.0.1;
+ }
Verify the changes by confirming the applied configuration.
show protocols bgp group TEST type external; peer-as 65001; neighbor 172.16.0.1;
Typical workflow:
- On the source router: show | compare after staging a change, copy the diff output.
- On the target router: enter configuration mode, run load patch terminal, paste the diff, press Ctrl+D.
- Review with show | compare, then commit.
load patch also accepts a file path instead of terminal — useful
when the diff has been saved to /var/tmp/:
load patch /var/tmp/bgp-change.diff
This pairs naturally with show | compare | save /var/tmp/bgp-change.diff on the source device, enabling a clean file-based change transfer workflow via SCP.