Skip to content

Juniper Junos

EX, MX and SRX: candidate config, commit confirmed, BGP and policies.

Juniper Requires SmartCom Revisited 1.0.0 or newer

by Nathan Kirk · 82 downloads · MIT licence · revision 1 · published 14 Aug 2026

This bundle can change or destroy device state

  • Factory resets the device (1 step) — Returns the device to factory settings, including management addressing. Expect to need console access afterwards.
  • Reboots or reloads the device (1 step) — Restarts the device. Any session on it drops, and anything not saved is lost.
  • Writes configuration to persistent storage (9 steps) — Makes the current configuration survive a reboot. Intended, usually — but it is not a read-only button.
Show exactly which steps matched
  • Set Interface Address — Writes configuration to persistent storage (steps[3], sent text)

    commit confirmed {{MINUTES}}
  • Add Access VLAN to Port — Writes configuration to persistent storage (steps[4], sent text)

    commit confirmed {{MINUTES}}
  • Add Trunk VLAN to Port — Writes configuration to persistent storage (steps[3], sent text)

    commit confirmed {{MINUTES}}
  • Add Static Route — Writes configuration to persistent storage (steps[3], sent text)

    commit confirmed {{MINUTES}}
  • Disable Interface — Writes configuration to persistent storage (steps[4], sent text)

    commit confirmed {{MINUTES}}
  • Delete Interface Config — Writes configuration to persistent storage (steps[4], sent text)

    commit confirmed {{MINUTES}}
  • Load Factory Default Config — Factory resets the device (steps[2], sent text)

    load factory-default
  • Create Allow Policy — Writes configuration to persistent storage (steps[6], sent text)

    commit confirmed {{MINUTES}}
  • Create Deny Policy — Writes configuration to persistent storage (steps[7], sent text)

    commit confirmed {{MINUTES}}
  • Delete Security Policy — Writes configuration to persistent storage (steps[4], sent text)

    commit confirmed {{MINUTES}}
  • Reboot Device — Reboots or reloads the device (steps[1], sent text)

    request system reboot

Flagged automatically by matching command text. It is a prompt to read the script, not a verdict — plenty of legitimate buttons reboot things on purpose.

Download

4 sets, 131 buttons, 245 steps · 175.5 KB

File format version 1 · exported by Smartcom Revisited

Download .buttons.json
SHA-256 db3867e17c9a625927ae81e4dfd206665ae98944fb116eb637fe6e0ad9006c01

You get the exact file the uploader submitted, byte for byte — that checksum is what sha256sum will print. Import it from the button panel in SmartCom Revisited.

About this set

Junos the way it is actually driven: operational show commands, edits staged in the candidate config, and commit confirmed as the standard safety net so a bad change rolls itself back.

Every button, in full

Exactly what gets sent

This is the complete script of the file below — nothing is summarised or hidden. Read it before you download it, the same way you would read a script someone emailed you.

Junos - Operational Status

30 buttons

Interfaces, chassis health, ARP, LLDP and the routing table.

Interface Terse

Run: show interfaces terse

1 step

  1. Send
    show interfaces terse

    Sends Enter afterwards.

Interface Descriptions

Run: show interfaces descriptions

1 step

  1. Send
    show interfaces descriptions

    Sends Enter afterwards.

Interface Detail

Run: show interfaces {{IFACE}} detail

1 step · 1 input

  1. Send
    show interfaces {{IFACE}} detail

    Sends Enter afterwards.

Interface Extensive

Run: show interfaces {{IFACE}} extensive

1 step · 1 input

  1. Send
    show interfaces {{IFACE}} extensive

    Sends Enter afterwards.

Interface Statistics

Run: show interfaces {{IFACE}} statistics

1 step · 1 input

  1. Send
    show interfaces {{IFACE}} statistics

    Sends Enter afterwards.

Interface Media

Run: show interfaces {{IFACE}} media

1 step · 1 input

  1. Send
    show interfaces {{IFACE}} media

    Sends Enter afterwards.

Optics Diagnostics

Run: show interfaces diagnostics optics {{IFACE}}

1 step · 1 input

  1. Send
    show interfaces diagnostics optics {{IFACE}}

    Sends Enter afterwards.

Ethernet Switching Table

Run: show ethernet-switching table

1 step

  1. Send
    show ethernet-switching table

    Sends Enter afterwards.

Find MAC Address

Run: show ethernet-switching table | match {{MAC}}

1 step · 1 input

  1. Send
    show ethernet-switching table | match {{MAC}}

    Sends Enter afterwards.

VLAN Summary

Run: show vlans

1 step

  1. Send
    show vlans

    Sends Enter afterwards.

VLAN Detail

Run: show vlans {{VLAN_NAME}} detail

1 step · 1 input

  1. Send
    show vlans {{VLAN_NAME}} detail

    Sends Enter afterwards.

Spanning-Tree Bridge

Run: show spanning-tree bridge

1 step

  1. Send
    show spanning-tree bridge

    Sends Enter afterwards.

Spanning-Tree Interface

Run: show spanning-tree interface

1 step

  1. Send
    show spanning-tree interface

    Sends Enter afterwards.

LACP Interfaces

Run: show lacp interfaces

1 step

  1. Send
    show lacp interfaces

    Sends Enter afterwards.

LLDP Neighbours

Run: show lldp neighbors

1 step

  1. Send
    show lldp neighbors

    Sends Enter afterwards.

ARP Table

Run: show arp

1 step

  1. Send
    show arp

    Sends Enter afterwards.

ARP for Host

Run: show arp | match {{IP}}

1 step · 1 input

  1. Send
    show arp | match {{IP}}

    Sends Enter afterwards.

IPv6 Neighbours

Run: show ipv6 neighbors

1 step

  1. Send
    show ipv6 neighbors

    Sends Enter afterwards.

Chassis Hardware

Run: show chassis hardware

1 step

  1. Send
    show chassis hardware

    Sends Enter afterwards.

Chassis Alarms

Run: show chassis alarms

1 step

  1. Send
    show chassis alarms

    Sends Enter afterwards.

Chassis Environment

Run: show chassis environment

1 step

  1. Send
    show chassis environment

    Sends Enter afterwards.

Chassis Routing Engine

Run: show chassis routing-engine

1 step

  1. Send
    show chassis routing-engine

    Sends Enter afterwards.

System Uptime

Run: show system uptime

1 step

  1. Send
    show system uptime

    Sends Enter afterwards.

System Storage

Run: show system storage

1 step

  1. Send
    show system storage

    Sends Enter afterwards.

System Processes

Run: show system processes extensive | match cpu

1 step

  1. Send
    show system processes extensive | match cpu

    Sends Enter afterwards.

Virtual Chassis Status

Run: show virtual-chassis status

1 step

  1. Send
    show virtual-chassis status

    Sends Enter afterwards.

PoE Status

Run: show poe interface

1 step

  1. Send
    show poe interface

    Sends Enter afterwards.

Software Version

Run: show version

1 step

  1. Send
    show version

    Sends Enter afterwards.

Licence Status

Run: show system license

1 step

  1. Send
    show system license

    Sends Enter afterwards.

Alarm History

Run: show system alarms

1 step

  1. Send
    show system alarms

    Sends Enter afterwards.

Junos - Routing & Reachability

34 buttons

Route table, BGP, OSPF, static routes and path testing.

Route Summary

Run: show route summary

1 step

  1. Send
    show route summary

    Sends Enter afterwards.

Routing Table

Run: show route

1 step

  1. Send
    show route

    Sends Enter afterwards.

Route for Prefix

Run: show route {{PREFIX}}

1 step · 1 input

  1. Send
    show route {{PREFIX}}

    Sends Enter afterwards.

Route Detail

Run: show route {{PREFIX}} detail

1 step · 1 input

  1. Send
    show route {{PREFIX}} detail

    Sends Enter afterwards.

Best Path to Host

Run: show route {{IP}} exact

1 step · 1 input

  1. Send
    show route {{IP}} exact

    Sends Enter afterwards.

Static Routes

Run: show route protocol static

1 step

  1. Send
    show route protocol static

    Sends Enter afterwards.

Direct Routes

Run: show route protocol direct

1 step

  1. Send
    show route protocol direct

    Sends Enter afterwards.

Routes in Instance

Run: show route table {{VRF}}.inet.0

1 step · 1 input

  1. Send
    show route table {{VRF}}.inet.0

    Sends Enter afterwards.

Forwarding Table

Run: show route forwarding-table destination {{IP}}

1 step · 1 input

  1. Send
    show route forwarding-table destination {{IP}}

    Sends Enter afterwards.

BGP Summary

Run: show bgp summary

1 step

  1. Send
    show bgp summary

    Sends Enter afterwards.

BGP Neighbour Detail

Run: show bgp neighbor {{PEER}}

1 step · 1 input

  1. Send
    show bgp neighbor {{PEER}}

    Sends Enter afterwards.

BGP Routes Received

Run: show route receive-protocol bgp {{PEER}}

1 step · 1 input

  1. Send
    show route receive-protocol bgp {{PEER}}

    Sends Enter afterwards.

BGP Routes Advertised

Run: show route advertising-protocol bgp {{PEER}}

1 step · 1 input

  1. Send
    show route advertising-protocol bgp {{PEER}}

    Sends Enter afterwards.

BGP Group Status

Run: show bgp group

1 step

  1. Send
    show bgp group

    Sends Enter afterwards.

OSPF Neighbours

Run: show ospf neighbor

1 step

  1. Send
    show ospf neighbor

    Sends Enter afterwards.

OSPF Interfaces

Run: show ospf interface

1 step

  1. Send
    show ospf interface

    Sends Enter afterwards.

OSPF Database

Run: show ospf database

1 step

  1. Send
    show ospf database

    Sends Enter afterwards.

OSPF Route Table

Run: show ospf route

1 step

  1. Send
    show ospf route

    Sends Enter afterwards.

ISIS Adjacencies

Run: show isis adjacency

1 step

  1. Send
    show isis adjacency

    Sends Enter afterwards.

MPLS Interfaces

Run: show mpls interface

1 step

  1. Send
    show mpls interface

    Sends Enter afterwards.

LDP Neighbours

Run: show ldp neighbor

1 step

  1. Send
    show ldp neighbor

    Sends Enter afterwards.

RSVP Sessions

Run: show rsvp session

1 step

  1. Send
    show rsvp session

    Sends Enter afterwards.

VRRP Status

Run: show vrrp summary

1 step

  1. Send
    show vrrp summary

    Sends Enter afterwards.

Routing Instances

Run: show route instance summary

1 step

  1. Send
    show route instance summary

    Sends Enter afterwards.

Ping Host

Run: ping {{HOST}} count {{COUNT}}

1 step · 2 inputs

  1. Send
    ping {{HOST}} count {{COUNT}}

    Sends Enter afterwards.

Ping in Routing Instance

Run: ping {{HOST}} routing-instance {{VRF}} count {{COUNT}}

1 step · 3 inputs

  1. Send
    ping {{HOST}} routing-instance {{VRF}} count {{COUNT}}

    Sends Enter afterwards.

Ping from Source

Run: ping {{HOST}} source {{IP}} count {{COUNT}}

1 step · 3 inputs

  1. Send
    ping {{HOST}} source {{IP}} count {{COUNT}}

    Sends Enter afterwards.

Traceroute

Run: traceroute {{HOST}}

1 step · 1 input

  1. Send
    traceroute {{HOST}}

    Sends Enter afterwards.

Traceroute in Instance

Run: traceroute {{HOST}} routing-instance {{VRF}}

1 step · 2 inputs

  1. Send
    traceroute {{HOST}} routing-instance {{VRF}}

    Sends Enter afterwards.

Resolve Hostname

Run: show host {{FQDN}}

1 step · 1 input

  1. Send
    show host {{FQDN}}

    Sends Enter afterwards.

Clear BGP Neighbour

Run: clear bgp neighbor {{PEER}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Reset the BGP session with {{PEER}}. Every prefix from that peer is withdrawn until the session rebuilds. Continue?”

    Answering no stops the script here.

  2. Send
    clear bgp neighbor {{PEER}}

    Sends Enter afterwards.

Soft-Clear BGP Neighbour

Run: clear bgp neighbor soft {{PEER}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Re-exchange routes with {{PEER}} without dropping the session. Prefixes may churn while it settles. Continue?”

    Answering no stops the script here.

  2. Send
    clear bgp neighbor soft {{PEER}}

    Sends Enter afterwards.

Clear ARP Entry

Run: clear arp hostname {{IP}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Remove the ARP entry for {{IP}}. Traffic to that host pauses until it is re-resolved. Continue?”

    Answering no stops the script here.

  2. Send
    clear arp hostname {{IP}}

    Sends Enter afterwards.

Clear OSPF Neighbours

Run: clear ospf neighbor

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Reset every OSPF adjacency. Routes are withdrawn and reconverge — expect a brief loss of transit. Continue?”

    Answering no stops the script here.

  2. Send
    clear ospf neighbor

    Sends Enter afterwards.

Junos - Configuration & Commit

28 buttons

Candidate edits, compare, commit confirmed and rollback.

Show Configuration

Run: show configuration

1 step

  1. Send
    show configuration

    Sends Enter afterwards.

Show Config as Set Commands

Run: show configuration | display set

1 step

  1. Send
    show configuration | display set

    Sends Enter afterwards.

Show Config Section

Run: show configuration {{PATTERN}}

1 step · 1 input

  1. Send
    show configuration {{PATTERN}}

    Sends Enter afterwards.

Show Interface Config

Run: show configuration interfaces {{IFACE}}

1 step · 1 input

  1. Send
    show configuration interfaces {{IFACE}}

    Sends Enter afterwards.

Show Config Differences

Run: configure ; show | compare ; exit

3 steps

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    show | compare

    Sends Enter afterwards.

  3. Send
    exit

    Sends Enter afterwards.

Commit History

Run: show system commit

1 step

  1. Send
    show system commit

    Sends Enter afterwards.

Config Rollback List

Run: configure ; rollback ? ; exit

3 steps

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    rollback ?

    Sends Enter afterwards.

  3. Send
    exit

    Sends Enter afterwards.

Compare with Rollback 1

Run: configure ; show | compare rollback 1 ; exit

3 steps

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    show | compare rollback 1

    Sends Enter afterwards.

  3. Send
    exit

    Sends Enter afterwards.

Who Is Editing

Run: show system users

1 step

  1. Send
    show system users

    Sends Enter afterwards.

Configuration Users

Run: configure ; status ; exit

3 steps

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    status

    Sends Enter afterwards.

  3. Send
    exit

    Sends Enter afterwards.

Set Interface Description

Run: configure ; set interfaces {{IFACE}} description "{{DESCRIPTION}}" ; show | compare ; commit comment "{{COMMENT}}" ; exit

5 steps · asks for confirmation before it runs · 3 inputs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set interfaces {{IFACE}} description "{{DESCRIPTION}}"

    Sends Enter afterwards.

  3. Send
    show | compare

    Sends Enter afterwards.

  4. Send
    commit comment "{{COMMENT}}"

    Sends Enter afterwards.

  5. Send
    exit

    Sends Enter afterwards.

Set Interface Address

Commits with a rollback timer — run Confirm Commit within the window or it reverts itself.

5 steps · asks for confirmation before it runs · 4 inputs

  • Writes configuration to persistent storage
  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set interfaces {{IFACE}} unit 0 family inet address {{IP}}/{{PREFIX_LEN}}

    Sends Enter afterwards.

  3. Send
    show | compare

    Sends Enter afterwards.

  4. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  5. Send
    exit

    Sends Enter afterwards.

Add Access VLAN to Port

Run: configure ; set interfaces {{IFACE}} unit 0 family ethernet-switching interface-mode access ; set interfaces {{IFACE}} unit 0 family ethernet-switching vlan members {{VLAN_NAME}} ; show | compare ; commit confirmed {{MINUTES}} ; exit

6 steps · asks for confirmation before it runs · 3 inputs

  • Writes configuration to persistent storage
  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set interfaces {{IFACE}} unit 0 family ethernet-switching interface-mode access

    Sends Enter afterwards.

  3. Send
    set interfaces {{IFACE}} unit 0 family ethernet-switching vlan members {{VLAN_NAME}}

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Add Trunk VLAN to Port

Run: configure ; set interfaces {{IFACE}} unit 0 family ethernet-switching vlan members {{VLAN_NAME}} ; show | compare ; commit confirmed {{MINUTES}} ; exit

5 steps · asks for confirmation before it runs · 3 inputs

  • Writes configuration to persistent storage
  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set interfaces {{IFACE}} unit 0 family ethernet-switching vlan members {{VLAN_NAME}}

    Sends Enter afterwards.

  3. Send
    show | compare

    Sends Enter afterwards.

  4. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  5. Send
    exit

    Sends Enter afterwards.

Create VLAN

Run: configure ; set vlans {{VLAN_NAME}} vlan-id {{VLAN}} ; show | compare ; commit comment "{{COMMENT}}" ; exit

5 steps · asks for confirmation before it runs · 3 inputs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set vlans {{VLAN_NAME}} vlan-id {{VLAN}}

    Sends Enter afterwards.

  3. Send
    show | compare

    Sends Enter afterwards.

  4. Send
    commit comment "{{COMMENT}}"

    Sends Enter afterwards.

  5. Send
    exit

    Sends Enter afterwards.

Add Static Route

Run: configure ; set routing-options static route {{PREFIX}} next-hop {{NEXT_HOP}} ; show | compare ; commit confirmed {{MINUTES}} ; exit

5 steps · asks for confirmation before it runs · 3 inputs

  • Writes configuration to persistent storage
  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set routing-options static route {{PREFIX}} next-hop {{NEXT_HOP}}

    Sends Enter afterwards.

  3. Send
    show | compare

    Sends Enter afterwards.

  4. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  5. Send
    exit

    Sends Enter afterwards.

Set Hostname

Run: configure ; set system host-name {{HOSTNAME}} ; commit comment "{{COMMENT}}" ; exit

4 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set system host-name {{HOSTNAME}}

    Sends Enter afterwards.

  3. Send
    commit comment "{{COMMENT}}"

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Add NTP Server

Run: configure ; set system ntp server {{NTP}} ; commit ; exit

4 steps · asks for confirmation before it runs · 1 input

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set system ntp server {{NTP}}

    Sends Enter afterwards.

  3. Send
    commit

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Add Syslog Host

Run: configure ; set system syslog host {{SERVER}} any notice ; commit ; exit

4 steps · asks for confirmation before it runs · 1 input

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set system syslog host {{SERVER}} any notice

    Sends Enter afterwards.

  3. Send
    commit

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Confirm Commit

Makes the last commit confirmed permanent. Run this before the rollback timer expires.

4 steps · asks for confirmation before it runs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    commit check

    Sends Enter afterwards.

  3. Send
    commit

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Validate Candidate Config

Run: configure ; commit check ; exit

3 steps · asks for confirmation before it runs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    commit check

    Sends Enter afterwards.

  3. Send
    exit

    Sends Enter afterwards.

Save Config to File

Run: save {{FILE}}

1 step · asks for confirmation before it runs · 1 input

  1. Send
    save {{FILE}}

    Sends Enter afterwards.

Discard Candidate Changes

Run: configure ; rollback 0 ; exit

4 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Throw away every uncommitted change in the candidate config, including anything a colleague is part-way through. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    rollback 0

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Roll Back One Commit

Run: configure ; rollback 1 ; show | compare ; commit ; exit

6 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Revert to the configuration before the last commit and apply it. Any change made since is undone. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    rollback 1

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    commit

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Roll Back to Numbered Config

Run: configure ; rollback {{ROLLBACK}} ; show | compare ; commit ; exit

6 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Revert to rollback {{ROLLBACK}} and commit it. Everything configured since that point is undone, including current management access. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    rollback {{ROLLBACK}}

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    commit

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Disable Interface

Run: configure ; set interfaces {{IFACE}} disable ; show | compare ; commit confirmed {{MINUTES}} ; exit

6 steps · asks for confirmation before it runs · 2 inputs

  • Writes configuration to persistent storage
  1. Confirm

    Asks yes or no: “Disable {{IFACE}}. The link drops as soon as this commits. It is a commit confirmed, so it reverts on its own if you lose access — do not confirm it until you are sure. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    set interfaces {{IFACE}} disable

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Delete Interface Config

Run: configure ; delete interfaces {{IFACE}} ; show | compare ; commit confirmed {{MINUTES}} ; exit

6 steps · asks for confirmation before it runs · 2 inputs

  • Writes configuration to persistent storage
  1. Confirm

    Asks yes or no: “Remove the whole configuration for {{IFACE}}, addressing and VLANs included. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    delete interfaces {{IFACE}}

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Load Factory Default Config

Run: configure ; load factory-default ; show | compare ; exit

5 steps · asks for confirmation before it runs

  • Factory resets the device
  1. Confirm

    Asks yes or no: “Load the factory default into the candidate config. It is not committed by this button, but committing it afterwards wipes the device. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    load factory-default

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    exit

    Sends Enter afterwards.

Junos - SRX Security

39 buttons

Security policies, zones, NAT, sessions and IPsec on SRX.

Security Policies

Run: show security policies

1 step

  1. Send
    show security policies

    Sends Enter afterwards.

Policy Detail

Run: show security policies policy-name {{POLICY}} detail

1 step · 1 input

  1. Send
    show security policies policy-name {{POLICY}} detail

    Sends Enter afterwards.

Policy Hit Count

Run: show security policies hit-count

1 step

  1. Send
    show security policies hit-count

    Sends Enter afterwards.

Zones Summary

Run: show security zones

1 step

  1. Send
    show security zones

    Sends Enter afterwards.

Zone Detail

Run: show security zones {{ZONE}}

1 step · 1 input

  1. Send
    show security zones {{ZONE}}

    Sends Enter afterwards.

Address Book

Run: show security address-book

1 step

  1. Send
    show security address-book

    Sends Enter afterwards.

Applications

Run: show configuration applications

1 step

  1. Send
    show configuration applications

    Sends Enter afterwards.

Session Summary

Run: show security flow session summary

1 step

  1. Send
    show security flow session summary

    Sends Enter afterwards.

All Sessions

Run: show security flow session

1 step

  1. Send
    show security flow session

    Sends Enter afterwards.

Sessions for Host

Run: show security flow session source-prefix {{IP}}

1 step · 1 input

  1. Send
    show security flow session source-prefix {{IP}}

    Sends Enter afterwards.

Sessions on Port

Run: show security flow session destination-port {{PORT}}

1 step · 1 input

  1. Send
    show security flow session destination-port {{PORT}}

    Sends Enter afterwards.

Session Count by Policy

Run: show security flow session policy {{POLICY}}

1 step · 1 input

  1. Send
    show security flow session policy {{POLICY}}

    Sends Enter afterwards.

Source NAT Rules

Run: show security nat source rule all

1 step

  1. Send
    show security nat source rule all

    Sends Enter afterwards.

Source NAT Pools

Run: show security nat source pool all

1 step

  1. Send
    show security nat source pool all

    Sends Enter afterwards.

Destination NAT Rules

Run: show security nat destination rule all

1 step

  1. Send
    show security nat destination rule all

    Sends Enter afterwards.

Static NAT Rules

Run: show security nat static rule all

1 step

  1. Send
    show security nat static rule all

    Sends Enter afterwards.

NAT Translation Table

Run: show security flow session nat

1 step

  1. Send
    show security flow session nat

    Sends Enter afterwards.

IPsec Security Associations

Run: show security ipsec security-associations

1 step

  1. Send
    show security ipsec security-associations

    Sends Enter afterwards.

IPsec SA Detail

Run: show security ipsec security-associations detail

1 step

  1. Send
    show security ipsec security-associations detail

    Sends Enter afterwards.

IKE Security Associations

Run: show security ike security-associations

1 step

  1. Send
    show security ike security-associations

    Sends Enter afterwards.

IKE SA Detail

Run: show security ike security-associations detail

1 step

  1. Send
    show security ike security-associations detail

    Sends Enter afterwards.

Screen Statistics

Run: show security screen statistics zone {{ZONE}}

1 step · 1 input

  1. Send
    show security screen statistics zone {{ZONE}}

    Sends Enter afterwards.

IDP Status

Run: show security idp status

1 step

  1. Send
    show security idp status

    Sends Enter afterwards.

UTM Status

Run: show security utm status

1 step

  1. Send
    show security utm status

    Sends Enter afterwards.

Chassis Cluster Status

Run: show chassis cluster status

1 step

  1. Send
    show chassis cluster status

    Sends Enter afterwards.

Cluster Interfaces

Run: show chassis cluster interfaces

1 step

  1. Send
    show chassis cluster interfaces

    Sends Enter afterwards.

Cluster Statistics

Run: show chassis cluster statistics

1 step

  1. Send
    show chassis cluster statistics

    Sends Enter afterwards.

Create Allow Policy

Run: configure ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match source-address {{SRC}} ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match destination-address {{DST}} ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match application {{SERVICE}} ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} then permit ; show | compare ; commit confirmed {{MINUTES}} ; exit

8 steps · asks for confirmation before it runs · 7 inputs

  • Writes configuration to persistent storage
  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match source-address {{SRC}}

    Sends Enter afterwards.

  3. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match destination-address {{DST}}

    Sends Enter afterwards.

  4. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match application {{SERVICE}}

    Sends Enter afterwards.

  5. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} then permit

    Sends Enter afterwards.

  6. Send
    show | compare

    Sends Enter afterwards.

  7. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  8. Send
    exit

    Sends Enter afterwards.

Add Address to Book

Run: configure ; set security address-book global address {{OBJECT}} {{SUBNET}} ; commit ; exit

4 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set security address-book global address {{OBJECT}} {{SUBNET}}

    Sends Enter afterwards.

  3. Send
    commit

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Start Flow Trace for Host

Writes matching packet decisions to the flow-trace file. Turn it off again with Stop Flow Trace.

6 steps · asks for confirmation before it runs · 1 input

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    set security flow traceoptions file flow-trace

    Sends Enter afterwards.

  3. Send
    set security flow traceoptions flag basic-datapath

    Sends Enter afterwards.

  4. Send
    set security flow traceoptions packet-filter pf1 source-prefix {{IP}}

    Sends Enter afterwards.

  5. Send
    commit

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Stop Flow Trace

Run: configure ; delete security flow traceoptions ; commit ; exit

4 steps · asks for confirmation before it runs

  1. Send
    configure

    Sends Enter afterwards.

  2. Send
    delete security flow traceoptions

    Sends Enter afterwards.

  3. Send
    commit

    Sends Enter afterwards.

  4. Send
    exit

    Sends Enter afterwards.

Read Flow Trace

Run: show log flow-trace | last {{LINES}}

1 step · 1 input

  1. Send
    show log flow-trace | last {{LINES}}

    Sends Enter afterwards.

Create Deny Policy

Run: configure ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match source-address {{SRC}} ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match destination-address {{DST}} ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match application any ; set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} then deny ; show | compare ; commit confirmed {{MINUTES}} ; exit

9 steps · asks for confirmation before it runs · 6 inputs

  • Writes configuration to persistent storage
  1. Confirm

    Asks yes or no: “Add a deny policy between {{SRC_ZONE}} and {{DST_ZONE}}. Check the ordering and make sure it cannot match your own management path. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match source-address {{SRC}}

    Sends Enter afterwards.

  4. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match destination-address {{DST}}

    Sends Enter afterwards.

  5. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} match application any

    Sends Enter afterwards.

  6. Send
    set security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} then deny

    Sends Enter afterwards.

  7. Send
    show | compare

    Sends Enter afterwards.

  8. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  9. Send
    exit

    Sends Enter afterwards.

Delete Security Policy

Run: configure ; delete security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}} ; show | compare ; commit confirmed {{MINUTES}} ; exit

6 steps · asks for confirmation before it runs · 4 inputs

  • Writes configuration to persistent storage
  1. Confirm

    Asks yes or no: “Delete policy {{POLICY}}. Traffic it permitted stops at the default deny. Continue?”

    Answering no stops the script here.

  2. Send
    configure

    Sends Enter afterwards.

  3. Send
    delete security policies from-zone {{SRC_ZONE}} to-zone {{DST_ZONE}} policy {{POLICY}}

    Sends Enter afterwards.

  4. Send
    show | compare

    Sends Enter afterwards.

  5. Send
    commit confirmed {{MINUTES}}

    Sends Enter afterwards.

  6. Send
    exit

    Sends Enter afterwards.

Clear Sessions for Host

Run: clear security flow session source-prefix {{IP}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Drop every session from {{IP}}. Their connections through this firewall break immediately. Continue?”

    Answering no stops the script here.

  2. Send
    clear security flow session source-prefix {{IP}}

    Sends Enter afterwards.

Clear All Sessions

Run: clear security flow session all

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Drop every session on this SRX. Every connection through the firewall breaks at once and users will notice. Continue?”

    Answering no stops the script here.

  2. Send
    clear security flow session all

    Sends Enter afterwards.

Clear IPsec SA

Run: clear security ipsec security-associations

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Tear down every IPsec SA. Tunnels renegotiate and traffic across them stops until they do. Continue?”

    Answering no stops the script here.

  2. Send
    clear security ipsec security-associations

    Sends Enter afterwards.

Fail Over Chassis Cluster

Run: request chassis cluster failover redundancy-group {{GROUP_ID}} node {{NODE_ID}}

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Force redundancy group {{GROUP_ID}} to node {{NODE_ID}}. Unsynchronised sessions drop during the switch, and the manual failover has to be reset afterwards. Continue?”

    Answering no stops the script here.

  2. Send
    request chassis cluster failover redundancy-group {{GROUP_ID}} node {{NODE_ID}}

    Sends Enter afterwards.

Reboot Device

Run: request system reboot

2 steps · asks for confirmation before it runs

  • Reboots or reloads the device
  1. Confirm

    Asks yes or no: “Reboot this Junos device now. Everything through it stops for the length of the boot, and any uncommitted candidate config is lost. Continue?”

    Answering no stops the script here.

  2. Send
    request system reboot

    Sends Enter afterwards.

Version history

  • Revision 1 current

    First published version.

    14 Aug 2026 · 175.5 KB · needs 1.0.0+ · db3867e17c9a6259…

Something wrong with this set?

Sign in to report it, or email abuse@smartcomrevisited.com.