Monitor the Control Plane

Learn how to monitor the control plane on your Juniper MX204, MX301, MX304, MX10004, or MX10008 router.

Use the monitor traffic command to capture packets on an interface. This command captures traffic at the Routing Engine after the Packet Forwarding Engine completes the forwarding decision.

This command displays only traffic sent to the control plane, such as routing protocol packets, ICMP, management traffic, and exception packets. It also captures traffic received on management interfaces such as fxp0.

Do not use this command to capture transit traffic, because it does not display packets forwarded in the data plane.

Important:

By default, the monitor traffic command captures all frames by placing the interface in promiscuous mode. Use the no-promiscuous option to capture only traffic addressed to the router, which is recommended for production environments.

The matching Filter Option

Use the matching option with a Berkeley Packet Filter (BPF) expression to limit captured packets to specific criteria. This option is required on busy interfaces to reduce output and focus on relevant traffic.

BPF expressions support logical operators such as and, or, and not. Common primitives include:

Primitive

Description

Example

host <ip>

Match packets to or from an IP address host 192.0.2.1

src host <ip>

Match packets from a specific source src host 10.0.0.1

dst host <ip>

Match packets to a specific destination dst host 10.0.0.2

net <prefix>

Match packets within a subnet net 198.51.100.0/24

proto <n>

Match by IP protocol number proto 89 (OSPF)

port <n>

Match TCP or UDP port port 179 (BGP)

tcp port <n>

Match TCP port specifically tcp port 22

udp port <n>

Match UDP port specifically udp port 123

icmp

Match ICMP packets icmp

arp

Match ARP frames arp

vlan <id>

Match 802.1Q-tagged frames with a specific VLAN ID vlan 100

Concrete Examples:

  • Monitor BGP session traffic with a specific peer—Captures all TCP port 179 packets exchanged with a BGP peer—useful to verify keepalive continuity or troubleshoot session flaps.

  • Monitor OSPF hello packets on an interface—OSPF uses IP protocol 89 and sends hellos to the multicast address 224.0.0.5. This filter isolates OSPF control traffic to verify hello intervals and neighbor reachability.

  • Monitor BFD control packets—BFD uses UDP ports 3784 (single-hop) and 4784 (multi-hop). This filter helps verify BFD PDU receipt during flap troubleshooting.

  • Monitor ICMP traffic from a specific source—Useful to verify if ICMP echo requests from a management host are reaching the RE, and whether replies are being generated.

  • Monitor SSH management traffic on OOB interface—Captures only SSH sessions (TCP port 22) initiated toward the router's management interface.

  • Monitor NTP sync traffic—Captures UDP port 123 to verify NTP request/response exchanges with configured NTP servers.

  • Capture and save to a file for offline analysis—The write-file option saves the capture in pcap format, which can then be opened in Wireshark or analyzed with tcpdump -r. Combine with count to limit capture size.

    To read back the capture:

Verbosity Options

The output verbosity can be combined with matching to control the level of protocol decode:

Option

Output Level

(default)

Single-line summary per packet: timestamp, protocol, src/dst, length

brief

Abbreviated one-line format

detail

Layer 3/4 header decode with flags and options

extensive

Full header decode + hexadecimal payload dump

print-hex

Full hexadecimal dump alongside decoded output

Example—full decode of OSPF packets:

For more information on control plane monitoring on MX devices, see the Monitoring, Sampling, and Collection Services Interfaces User Guide.