Perform Common Tasks

This topic provides tips for using Junos OS CLI.

This topic highlights lesser‑known Junos OS CLI commands and configuration options that improve day‑to‑day operational efficiency.

Operational Commands

Flap a Port Without Bouncing the Config

Use the bounce option to administratively cycle a port at a configurable interval instead of deactivating and reactivating the interface or reseating the cable.

The interval parameter specifies the down duration in milliseconds. Use it to force link renegotiation or reestablish BFD, LDP, or BGP sessions on a specific interface without modifying the configuration.

Auto-Refresh a Show Command

Append | refresh <seconds> to any operational command to have it re-execute automatically at the specified interval, similar to the Linux watch command.

If you do not specify an interval, the default is 1 second. Press Ctrl+C to stop. Use this option to monitor BGP session state during maintenance or convergence events.

Clear the Terminal Screen

Clears the terminal buffer—equivalent to the Unix clear command.

Resolve IP Addresses iin Command Output

Append | resolve to an operational command to have Junos OS perform reverse DNS resolution on IP addresses found in the output, replacing raw IPs with hostnames where available.

Enabling this option helps you read routing tables or BGP summaries more efficiently, provided the environment has well-maintained DNS PTR records.

Display Inherited Configuration without Comments

When you use apply-groups or apply-macro, the | display inheritance command shows the fully resolved configuration after group expansion. Appending the no-comments option strips the inline annotations that indicate the source group of each inherited line, resulting in a clean output.

This is essential when auditing the effective running configuration without the noise of /* inherited from group ... */ comments.

Live Traceroute with Continuous Refresh

Traceroute monitor combines traceroute with a continuous auto-refresh display, similar to MTR on Linux. It provides a live view of per-hop RTT and packet loss.

Use this option instead of a single traceroute to diagnose intermittent latency or path changes on a live network.

Show Interface Descriptions in Traffic Monitor

The standard monitor interface traffic output does not show interface descriptions. Adding detail reveals the configured description alongside traffic counters, making it much easier to identify interfaces at a glance.

This is especially useful on dense chassis like the MX10004 where interface names alone (e.g., et-3/0/15) carry little operational context without descriptions.

Properly Clear Log File

Do not delete or truncate a log file directly, because it leaves no record of the action. Use the clear log command to empty the file and create an audit entry that records the event.

The resulting clear-log syslog entry confirms the timestamp of the clear command, which is important for security information and event management (SIEM) correlation and audit trails.

Unlock the Configuration Database

If a user leaves an exclusive configuration session open, other users cannot commit. Identify the session and log out the user by using the following command:

This command terminates the blocking session and releases the exclusive configuration lock. Use this command with caution because it discards any uncommitted changes in that session.

Configuration Commands

Reset Root Auth Password

To reset the root authentication password on a Juniper MX device, use the following configuration command in configuration mode:

Disable Pagination for Scripting

By default, Junos OS paginates command output using the --more-- prompt. Setting screen-length 0 disables pagination entirely, which is essential when piping output to scripts or capturing the complete output of a show command over an SSH session.

This setting applies to the current CLI session only and does not modify the permanent device configuration.

Add a Timestamp to every CLI Output Line

Use this command to prepend a timestamp to each line of the CLI output. This is useful when capturing a live troubleshooting session to correlate events with system log entries.

After you enable this, the system prefixes every operational command output line with the current date and time. To deactivate this feature, run the cli timestamp disable command.

Protect a Configuration Branch

The protect and unprotect configuration mode commands lock a specific hierarchy branch against accidental modification or deletion. The system prevents changes to a protected stanza until you explicitly unprotect it.

This is useful for protecting critical configuration elements (e.g., protocols parent-level, OOB management interface, loopback, emergency ACLs) from being accidentally overwritten during bulk changes.

Replace Any Pattern in the Configuration

The replace pattern command performs a global search-and-replace using regular expressions (enclosed in quotation marks) across either the entire candidate configuration or a specific hierarchy level. This is particularly powerful for bulk renaming of policy names, communities, prefixes, or interface references.

Example—rename all occurrences of a routing policy:

CAUTION:

Always review the diff with show | compare before committing, as the replace operates globally across all configuration hierarchies.

Wildcard Range Operations

The wildcard range command applies a configuration operation—such as set, delete, deactivate, or protect—to a range of interfaces or objects simultaneously, eliminating the need for repetitive, individual modifications.

Example—deactivate a range of unit interfaces in one shot:

Example—set a description on a range of interfaces:

Assign an Alias to a Logical Interface

Junos OS allows you to assign a human-readable alias to a logical interface (IFL). You can then use this alias in place of the numeric unit name when executing operational commands.

After configuring the alias, you can use the alias directly in show commands:

This eliminates the need to remember or look up unit numbers for frequently accessed interfaces and is compatible with most variations of the show interfaces command.

Apply a Config Diff Directly with Load Patch Terminal

The load patch terminal command allows you to paste the output of a show | compare diff directly into another router's configuration session, applying only the delta rather than a full configuration replace. This is the cleanest way to replicate a specific configuration change from one device to another without touching the rest of the config.

The input uses the standard Junos OS unified diff format, with lines prefixed with a plus sign (+) for additions and a minus sign (-) for deletions. To terminate the input, press Ctrl+D on a new line.

Verify the result with show | compare before committing:

Verify the changes by confirming the applied configuration.

Typical workflow:

  1. On the source router: show | compare after staging a change, copy the diff output.
  2. On the target router: enter configuration mode, run load patch terminal, paste the diff, press Ctrl+D.
  3. Review with show | compare, then commit.
Note:

load patch also accepts a file path instead of terminal — useful when the diff has been saved to /var/tmp/:

This pairs naturally with show | compare | save /var/tmp/bgp-change.diff on the source device, enabling a clean file-based change transfer workflow via SCP.