
Understand Junos architecture, including the routing engine and packet forwarding engine, and how FPC, PIC, and interfaces are named; configure root authentication, management IP, SSH, and commits with rollback.
Install GNS3 on windows by downloading the software and the GNS3 VM, installing VMware player, importing the VM, and launching the GNS3 client to create and run a test project.
Install the Gns3 VM on macOS with UTM, access it at 192.168.64.9:80, and adjust VM resources on an 8 GB RAM M1 MacBook Pro.
Install and run Gns3 natively on Ubuntu desktop by installing the Gns3 GUI and server, without a Gns3 VM, and manually install dynamips and qemu dependencies.
Learn the OSI model's first four layers and how switches and routers use MAC addresses, frames, and IP packets to enable VLAN switching and routing.
Configure switch and router interfaces in a lab, setting access and trunk ports, native VLANs, and inter-VLAN routing with router on a stick and static routes.
Explore how the spanning tree protocol prevents loops in redundant layer two topologies by electing a root bridge, using BPDUs, and blocking ports.
Explore rapid spanning tree protocol (rstp) and stp by configuring switches in a lab, building a loop-free topology, identifying root bridges, adjusting port costs, and observing blocking and forwarding states.
Learn to configure and troubleshoot LACP (802.3ad) across switches, routers, and firewalls, aggregating up to eight interfaces with matching speeds into a single logical link, using active or passive modes.
Configure and troubleshoot LACP link aggregation between switches and a router, using 802.3ad active and passive modes, VLAN 5, IRB test interfaces, and end-to-end ping checks.
Explore mc-lag concepts, enabling two switches to act as one, with iccp and lcp coordination, mce interfaces, and active/active or active/standby modes, redundancy, loop avoidance, and troubleshooting tips.
Configure and validate mc-lag across two juniper chassis using iccp synchronization and lacp, linking ubuntu servers and interconnected switches. Analyze trunking, vlans, and failover behavior with live testing.
Learn how firewall policies control traffic across Juniper security zones, covering stateless and stateful firewalls, zone configuration, address books, and policy troubleshooting.
Explore configuring firewall policies on a Juniper S6 appliance by setting interfaces, security zones, address books, and application-based rules, then verify traffic with show security flow and policy statistics.
Use destination NAT to translate destination IP from public to private, including subnet and port translations. Process it before route and policy lookups; inbound only and stateful for return traffic.
Configure destination nat in a Juniper SRX lab, covering 1-to-1, subnet translation, and port translation, plus building address books, zones, and policies to verify traffic.
Explore how source NAT translates inside private IPs to public addresses, including single IP, subnet, and automatic port address translation, with route and policy lookups guiding the process.
Configure IP-to-IP NAT between PCs in the source NAT lab, create pools and rules, enable proxy ARP, and verify translations with pings.
Master static nat on Juniper SRX by learning 1-to-1 and not many-to-many translations, configuring outside-to-inside and inside-to-outside traffic, and applying route lookup, policy, and reverse static nat.
The lab guides you to configure static NAT and subnet translation, plus port and IP translation, using security policies and security zones to enable bidirectional connectivity.
Explore IPsec components, protocols, and modes, including IKEv1/IKEv2, tunnel vs transport, and NAT traversal, to secure site-to-site and remote access connections with encrypted traffic.
Configure policy-based ipsec between two juniper devices using sha256, aes 256, group 14, and 3600 second lifetimes; define ike policy and ipsec vpn with traffic selectors, verify with ping.
Configure a route-based IPsec tunnel on a Juniper device and verify the IPsec security associations are up, then remove the traffic selectors and set up st0 and static routes.
Discover how router redundancy protocols enable a master router with backup devices using a common virtual ip and virtual mac, governed by priority and tiebreakers.
Explore a three-router VRRP lab on Junos, set up g00 interfaces, the virtual IP 192.168.1.1, and router priorities; observe mastership failover and tie-breaking by priority and IP address.
Configure GRE tunneling to encapsulate traffic between two routers via tunnel endpoints, enabling IPv6 over IPv4 and MPLS over GRE, while noting GRE's lack of encryption and IPsec for security.
Configure a GRE tunnel across Juniper routers to encapsulate private networks over public IPs and verify with static routes and pings. GRE lacks encryption; use IPsec for sensitive traffic.
Explore how OSPF operates as a link-state protocol in a single-area network, using area zero, hello messages, adjacencies, LSAs, and DR/BDR to build the topology database.
Explore how multi-area OSPF reduces the link-state database size, explains backbone area zero, area border routers, and the role of ABRs and ASBRs, including LSA types and virtual links.
Learn to configure OSPF multi-area with area zero backbone, stub and not so stubby areas, and virtual links to connect areas; observe LSA types, ABR behavior, and route summarization.
Explore the IS-IS link-state dynamic routing protocol, its area and level concepts, TLVs and PDUs, adjacency formation, and practical config and troubleshooting steps.
Practice configuring an is-is lab with a core area using level two links, loopback and iso addresses, and enabling family iso on interfaces; apply export policies to control route sharing.
Master border gateway protocol basics, including BGP messages and attributes like next hop, as path, med, local preference, and community. Apply policies and multipath to influence route selection and troubleshoot.
Configure and verify BGP with external and internal sessions across a multi-site topology, leveraging OSPF learned loopbacks, route import/export policies, next-hop self, and community filtering for traffic engineering.
Engineer BGP traffic engineering using as-path prepend, local preference, MED, and multipath to steer traffic through designated virtual routers and transit links, then validate with acceptance tests.
Discover how BGP route reflectors concentrate routes, use cluster list and originator ID to prevent loops, and configure reflectors with clients in a three-node topology.
Configure BGP route reflectors in a three-node lab, using OSPF to share loopback addresses, establish iBGP with a 65000 autonomous system, and verify route propagation with policy exports.
Explore how BGP confederations scale routes by combining iBGP and BGP with private subbase numbers, including route reflectors, loopback-based peering, and multipath configurations.
Explore configuring BGP confederations to simplify a multi-homed network by using three sub AS groups, iBGP, route reflectors, and route export policies.
Hello,
I am delighted that you chose to attend this course. :)
As a Network Engineer, I started my Networking Career working on Juniper devices which made my transition and learning process so much smoother and faster. Why you may ask? Well let me explain to you:
- JunOS has an intuitive CLI, show commands and protocol configuration is pretty easy to understand.
- Documentation is short and on point most of the time.
- Configuration is easy to see and understand and it makes sense.
While creating this course, my focus was to show you the most used protocols and technologies in the actual working place, using as close to real-life scenarios as possible.
The focus of my lessons is the practice part, but you will find easy-to-understand lectures on how protocols and Juniper devices work, also I made sure to include topics that are liked by the interviewers when targeting a Network engineer role.
This course is targeted for beginner to intermediate level, the curriculum will take you slowly and will gradually increase its complexity, it is created in a way that you will immediately have to use the protocol/technology that we touched by assigning to you "homework" in form of practice labs after each Chapter and more complex multi-technology assignments once we learn more.
In my experience the best way to learn something is by practising it and playing with different scenarios it will for sure make you read more closely networking documentation and in return make you a better engineer.
What this course is proposing:
- Network and JunOS Fundamentals
- Firewall, Switch and Router handling
- LACP and MC-LAG
- Static routing and GRE Tunneling
- STP
- VRRP
- NAT
- OSPF, ISIS and BGP
- IPSec
Hop in and let's go!
Update 07/2024: BGP RouteReflectors, BGP Confederations, IPSec -> all with corresponding labs