Monitor the Control Plane
Learn how to monitor the control plane on your Juniper MX204, MX301, MX304, MX10004, or MX10008 router.
Use the monitor traffic command to capture packets on an interface. This
command captures traffic at the Routing Engine after the Packet Forwarding Engine completes
the forwarding decision.
This command displays only traffic sent to the control plane, such as routing protocol
packets, ICMP, management traffic, and exception packets. It also captures traffic received
on management interfaces such as fxp0.
Do not use this command to capture transit traffic, because it does not display packets forwarded in the data plane.
regress@rct3-mx10004-a> monitor traffic interface et-1/1/1
By default, the monitor traffic command captures all frames by placing
the interface in promiscuous mode. Use the no-promiscuous option to
capture only traffic addressed to the router, which is recommended for production
environments.
The matching Filter Option
Use the matching option with a Berkeley Packet Filter (BPF) expression to
limit captured packets to specific criteria. This option is required on busy interfaces to
reduce output and focus on relevant traffic.
BPF expressions support logical operators such as and,
or, and not. Common primitives include:
|
Primitive |
Description |
Example |
|---|---|---|
|
|
Match packets to or from an IP address | host 192.0.2.1 |
|
|
Match packets from a specific source | src host 10.0.0.1 |
|
|
Match packets to a specific destination | dst host 10.0.0.2 |
|
|
Match packets within a subnet | net 198.51.100.0/24 |
|
|
Match by IP protocol number | proto 89 (OSPF) |
|
|
Match TCP or UDP port | port 179 (BGP) |
|
|
Match TCP port specifically | tcp port 22 |
|
|
Match UDP port specifically | udp port 123 |
|
|
Match ICMP packets | icmp |
|
|
Match ARP frames | arp |
|
|
Match 802.1Q-tagged frames with a specific VLAN ID | vlan 100 |
Concrete Examples:
-
Monitor BGP session traffic with a specific peer—Captures all TCP port 179 packets exchanged with a BGP peer—useful to verify keepalive continuity or troubleshoot session flaps.
regress@rct3-mx10004-a> monitor traffic interface et-1/1/1 matching "host 10.0.0.1 and tcp port 179"
-
Monitor OSPF hello packets on an interface—OSPF uses IP protocol 89 and sends hellos to the multicast address
224.0.0.5. This filter isolates OSPF control traffic to verify hello intervals and neighbor reachability.regress@rct3-mx10004-a> monitor traffic interface et-1/1/1 matching "proto 89" detail
-
Monitor BFD control packets—BFD uses UDP ports 3784 (single-hop) and 4784 (multi-hop). This filter helps verify BFD PDU receipt during flap troubleshooting.
regress@rct3-mx10004-a> monitor traffic interface et-1/1/1 matching "udp port 3784 or udp port 4784"
-
Monitor ICMP traffic from a specific source—Useful to verify if ICMP echo requests from a management host are reaching the RE, and whether replies are being generated.
regress@rct3-mx10004-a> monitor traffic interface fxp0 matching "src host 192.168.1.100 and icmp"
-
Monitor SSH management traffic on OOB interface—Captures only SSH sessions (TCP port 22) initiated toward the router's management interface.
regress@rct3-mx10004-a> monitor traffic interface fxp0 matching "tcp port 22" no-promiscuous
-
Monitor NTP sync traffic—Captures UDP port 123 to verify NTP request/response exchanges with configured NTP servers.
regress@rct3-mx10004-a> monitor traffic interface fxp0 matching "udp port 123"
-
Capture and save to a file for offline analysis—The
write-fileoption saves the capture in pcap format, which can then be opened in Wireshark or analyzed withtcpdump -r. Combine withcountto limit capture size.regress@rct3-mx10004-a> monitor traffic interface et-1/1/1 matching "tcp port 179" count 500 write-file /var/tmp/bgp-capture.pcap
To read back the capture:
regress@rct3-mx10004-a> monitor traffic read-file /var/tmp/bgp-capture.pcap matching "host 10.0.0.1."
Verbosity Options
The output verbosity can be combined with matching to control the level of
protocol decode:
|
Option |
Output Level |
|---|---|
|
(default) |
Single-line summary per packet: timestamp, protocol, src/dst, length |
|
brief |
Abbreviated one-line format |
|
detail |
Layer 3/4 header decode with flags and options |
|
extensive |
Full header decode + hexadecimal payload dump |
|
print-hex |
Full hexadecimal dump alongside decoded output |
Example—full decode of OSPF packets:
regress@rct3-mx10004-a> monitor traffic interface et-1/1/1 matching "proto 89" extensive
For more information on control plane monitoring on MX devices, see the Monitoring, Sampling, and Collection Services Interfaces User Guide.