Command display standard: all executable commands are shown as RED TEXT ON YELLOW HIGHLIGHT for rapid identification and copying.
JUNIPER SRX - COMMANDS
⌕
114 / 114 distinct commands

Juniper SRX Interactive Commands

Bootloader checks → USB autoinstall status → bootloader update → backup → USB recovery → normal upgrades → verification

114distinct command / prompt entries in this recovery-first version
106Operational-mode command cards
27high-risk command cards highlighted
1-clickcopy button on every executable command card

Mode & Prompt Quick Reference Table

Use this table before running any command. The symbol at the end of the prompt tells you which command environment you are currently using.

Mode Typical Prompt How to Enter What It Is Used For Does commit Apply?
Operational Mode root@SRX> Log in to Junos CLI, or type cli from a shell. Show/status commands, software install requests, reboot, snapshots, file operations. No
Configuration Mode root@SRX# From Operational mode: configure Persistent configuration changes using set, delete, etc. Yes — use show | compare, then commit.
Shell Mode root@SRX% or root@SRX:/var/tmp # From Operational mode: start shell or start shell user root FreeBSD file-system work, df, dmesg, dd, gunzip, bootloader utilities. No
Boot Loader loader> Interrupt the boot process from console. Disaster recovery from TFTP or a non-bootable USB. No
U-Boot Environment Platform-dependent boot prompt Reached during low-level boot/recovery. Network variables and lower-level recovery on supported releases. No
Admin PC / Terminal C:\>, PowerShell, macOS/Linux shell Use your local workstation. Prepare USB media, create autoinstall.conf, unzip/write bootable images. No
Rule: If you make a persistent Junos configuration change in Configuration Mode (#), review it with show | compare and save it with commit before leaving the mode.

Junos Firmware File Types — Select the Correct Package

SRX software download pages can offer several different package types for the same release. They are not interchangeable. Match the file type to the installation method.

Juniper Download Description Typical Filename Pattern Use It From Purpose Important Notes
CLI Install Image junos-install-srxsme-mips-64-<RELEASE>.tgz Operational mode > Normal software installation/upgrade from /var/tmp, mounted USB, or a copied image. For USB autoinstallation, use this standard upgrade file in the USB root with autoinstall.conf. Do not use a file containing media, net, or usb for that autoinstall workflow.
Net / Loader Install Image junos-install-media-net-srxsme-mips-64-<RELEASE>.tgz loader> Loader-based disaster recovery via TFTP or locally attached non-bootable USB for 24.4+. For 24.4+, the Juniper KB specifically states that the loader method uses the file containing net even when the source is a USB drive.
USB Install Image junos-install-media-usb-srxsme-mips-64-<RELEASE>.img.gz Bootable USB media Create a fully bootable USB recovery/install drive. Unzip to .img, then write the image to the whole USB device with Rufus or dd. This overwrites the USB and, when used for installation, can return the SRX to factory-default state.
Checksums Release-specific checksum file/value Admin workstation Verify download integrity. Use the checksum published next to the exact image downloaded from Juniper.
Do not select a package based only on the Junos release number. Check the description on the Juniper download page and make sure the filename matches the installation method. For example, a CLI .tgz, loader install-media-net package, and bootable install-media-usb image can all exist for the same release.

Special Requirements When Crossing into Junos 24.4+

The Juniper SRX3xx KB you provided applies specifically to crossing the 24.2/23.4 generation into 24.4 or later on SRX300, SRX320, SRX340, SRX345 and SRX380. Its stated jump versions are:

23.4R2-S3 or later 24.2R2 or later
Pre-check Command / Method Pass Condition Why It Matters
Current Junos show version Use a supported jump version before crossing to 24.4+. Unsupported direct jumps can fail or leave the platform requiring recovery.
U-Boot / Loader Check console boot output and boot environment. For the newer USB/TFTP install architecture, meet the documented bootloader prerequisites for the target release. Newer installation images may not boot with older loader components.
Partition layout start shell then df -h On SRX300/320/340/345, the newer layout shows /dev/bo0s3f around 5 GB. Old dual-root layout can block the 24.4 upgrade.
Free space show system storage / df -h More than 2 GB free on /dev/bo0s3f. The upgrade needs space to create /var/preserve and preserve configs/certificates/licenses/scripts.
Backup request system snapshot media usb Bootable snapshot completed and labelled. Provides a recovery image of the current SRX state.
Data-loss warning for 24.4+: The KB states that /var/log and /var/tmp are lost during this filesystem transition. Loader-based installs and bootable install-media-usb methods can return the SRX to factory default, so back up the configuration, licenses, certificates, scripts and any other required data first.

Verified SRX3xx 24.4+ Upgrade, Backup & Recovery Commands

These commands are taken from the SRX3xx 24.4+ upgrade KB supplied with this runbook and are organised here as workflows.

Check the Current Partition Layout

Operational Mode (>)
start shell
Shell Mode (%)
df -h

SRX380 Dual-Root Snapshot Check

Operational Mode (>)
show system snapshot media internal

Repartition on the Supported Jump Release Before 24.4+

Use only when the pre-24.4 jump release has the old partition layout. This is not a generic 24.4/25.x partition command.
Operational Mode (>)
request system software add no-copy no-validate partition /var/tmp/junos-srxsme-23.4R2-S3.9.tgz

Create a Full Bootable USB Snapshot Before Upgrade

Do not mount the USB first. On SRX300/320/340/345 the KB recommends a trusted 8 GB or larger drive. The command partitions the USB and creates a full bootable snapshot.
Operational Mode (>)
request system snapshot media usb
Operational Mode (>)
show system snapshot media usb

Track Snapshot Progress from Another Session

Operational Mode (>)
show system storage | match snap-tmp
Operational Mode (>)
show system storage | match snap-tmp | refresh 180

Check USB Capacity / Device Information from Shell

Operational Mode (>)
start shell user root
Shell Mode (%)
dmesg | grep da0:

Standalone Upgrade to 24.4 from a Valid Jump Release

Operational Mode (>)
request system software add no-validate /var/tmp/junos-install-srxsme-mips-64-24.4R1.9.tgz
Operational Mode (>)
request system reboot

Loader Recovery — TFTP (24.4+)

Factory-default/data-loss method. For 24.4+, the loader image must use the install-media-net filename family.
Boot Loader (loader>)
install tftp://10.0.113.2/junos-install-media-net-srxsme-mips-64-24.4R1.9.tgz

Loader Recovery — Non-Bootable USB (24.4+)

Boot Loader (loader>)
install file:///junos-install-media-net-srxsme-mips-64-24.4R1.9.tgz

Create a Bootable USB Image from SRX / Unix

Danger: dd overwrites the target device. Verify the USB device name before running it, and do not run dd against a mounted USB on an SRX.
Shell / Unix
gunzip junos-install-media-usb-srxsme-mips-64-24.4R1.9.img.gz
Shell / Unix
dd if=/var/tmp/junos-install-media-usb-srxsme-mips-64-24.4R1.9.img of=/dev/da1 bs=1m

Boot the SRX Directly from a Bootable USB

Operational Mode (>) — pre-24.4 syntax shown in KB
request system reboot media usb
Operational Mode (>) — 24.4+ rollback/USB boot syntax
request system reboot usb

USB Autoinstallation Status / Logs

Operational Mode (>)
show log messages | match usb_autoinstall
Critical completion step: after the console says USB image auto-installation complete, waiting for the USB removal, do not issue a manual reboot. Remove the USB and allow the SRX to reboot itself.

Restore Internal Media from a Pre-Upgrade Bootable USB Snapshot

Operational Mode (>) — while running from recovery USB
request system snapshot media internal
Operational Mode (>)
request system power-off
After the internal snapshot completes, power the SRX off before removing the recovery USB. The KB warns that removing it while the SRX is still running can corrupt the USB recovery drive.

Downgrade Back to the Jump Release

Operational Mode (>)
request system software add /var/tmp/junos-srxsme-23.4R2-S3.9.tgz reboot
The supplied KB states that request system software rollback is not supported for rolling back from 24.4 to an earlier release.

Runbook Order — Follow from Top to Bottom

All navigation is now at the top. Start with bootloader prerequisites before USB/TFTP work, then follow the recovery or upgrade path that matches the device condition.

Filter commands: Risk:
1Check Bootloader
2Check USB Auto
3Update Bootloader
4Back Up
5Choose Recovery/Upgrade
6Verify

1. Connect, Login & Identify the Prompt

Connect by console or SSH and identify which prompt you are at.

7 command entries in this section
ACCESS / PROMPT COMMAND Word Guide
Follow the access instructions shown for this item.
Press Enter

Purpose: Wake the console session and display the SRX login prompt if it is not already visible.

ACCESS / PROMPT COMMAND Word Guide
Follow the access instructions shown for this item.
root

Purpose: Example administrator username from the supplied notes. If the SRX uses another administrator account, enter that username instead.

ADMIN PC / TERMINAL COMMAND Word Guide
Run this on the administrator computer, not at an SRX Junos prompt.
ssh <username>@<management-IP>

Purpose: Open an SSH session to the SRX using the actual administrator username and management IP address.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
root@SRX>

Purpose: Command retained from the supplied source material.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
root@SRX#

Purpose: Command retained from the supplied source material.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
root@SRX%

Purpose: Command retained from the supplied source material.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
loader>

Purpose: Command retained from the supplied source material.

2. Understand Modes & Saving Changes

Know exactly how to move between Operational, Configuration, Shell and Loader environments.

10 command entries in this section
OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
configure

Purpose: Enter Junos configuration mode.

CONFIGURATION # COMMAND Juniper Verified
You must already be at a # prompt. Example: edit system services.
edit <hierarchy>

Purpose: Navigate to a configuration hierarchy after you are already in Configuration mode. Use configure—not edit—to enter Configuration mode from Operational mode.

CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
exit

Purpose: Leave configuration mode. If configuration changes were made, commit them first unless you intentionally intend to discard them.

OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
start shell

Purpose: Enter the underlying shell environment.

OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
start shell user root

Purpose: Enter the shell as root, as shown in the supplied upgrade example.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
cli

Purpose: Start or return to the Junos CLI from the shell.

CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set <configuration-statement>

Purpose: Enter the required configuration statement from the relevant section.

CONFIGURATION # CONFIG CHANGE Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show | compare

Purpose: Review candidate configuration changes against the active configuration before commit.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
commit

Purpose: Validate and apply the candidate Junos configuration so the changes become active.

CONFIGURATION # CONFIG CHANGE Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
commit and-quit

Purpose: Commit the candidate configuration, apply it, and leave configuration mode.

3. Check Bootloader, Loader, BIOS & Junos Version First

Do this before any firmware recovery or 24.4R1+ USB/TFTP installation. Do not proceed until you know the current boot environment.

24.4R1+ prerequisite for SRX300/SRX320/SRX340/SRX345/SRX380 USB or TFTP install: Juniper requires U-Boot 3.15 or later and a loader build from 2023 or later. For the documented 24.4R1 path, upgrade first to 23.4R2-S3 or 24.2R2 so the current /boot/uboot and /boot/veloader binaries are available.
What to checkWherePass condition for 24.4R1+ USB/TFTP
U-BootConsole boot output / shell environment3.15 or later
LoaderConsole boot output; note its build dateBuild year 2023 or later
BIOS/Firmwareshow system firmware and show chassis routing-engine biosNo unexpected firmware alarm/status
5 command entries in this section
OPERATIONAL >READ ONLYJuniper Verified
Required prompt ends with > (for example root@SRX>).
show version

Purpose: Confirm the currently running Junos OS release before selecting an upgrade path.

OPERATIONAL >READ ONLYJuniper Verified
Required prompt ends with > (for example root@SRX>).
show system firmware

Purpose: Display firmware status and available/current firmware information. Use this as a general firmware health check before and after bootloader work.

OPERATIONAL >READ ONLYJuniper Verified
Required prompt ends with > (for example root@SRX>).
show chassis routing-engine bios

Purpose: Display the Routing Engine BIOS version on supported SRX platforms.

OPERATIONAL >COMMANDJuniper Verified
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
start shell

Purpose: Enter the Junos shell so the U-Boot/loader environment values can be inspected.

SHELL %READ ONLYJuniper Verified
Required prompt ends with %. Enter from Operational mode with start shell.
kenv

Purpose: Display kernel/boot environment values. Check boot.ver, loader.name and loader.version; the loader build date is also visible during console boot.

4. Check USB Autoinstallation Status

Confirm USB autoinstallation is not disabled before preparing an automatic USB image installation.

Default state: USB autoinstallation is enabled unless it has been explicitly disabled. For automatic USB firmware installation, make sure set system autoinstallation usb disable is not present.
USB removal safety: when autoinstallation is enabled, Junos can scan an inserted USB for up to about 50 seconds. Juniper recommends waiting at least 60 seconds before removal. If autoinstallation is intentionally disabled before insertion, the stated waiting interval can be reduced to 20 seconds.
7 command entries in this section
OPERATIONAL >READ ONLYJuniper Verified
Required prompt ends with > (for example root@SRX>).
show configuration system | display set | match autoinstallation

Purpose: Check the configured autoinstallation statements. If you see "set system autoinstallation usb disable", USB image autoinstallation is disabled.

OPERATIONAL >COMMANDJuniper Verified
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
configure

Purpose: Enter Configuration mode before changing the USB autoinstallation setting.

CONFIGURATION #CONFIG CHANGEJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
delete system autoinstallation usb disable

Purpose: Remove the explicit USB-autoinstall disable statement so the USB image autoinstallation feature can operate.

CONFIGURATION #READ ONLYJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
show | compare

Purpose: Review the candidate change before saving it.

CONFIGURATION #CONFIG CHANGEJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
commit

Purpose: Save and activate the configuration change.

CONFIGURATION #COMMANDJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
exit

Purpose: Leave Configuration mode and return to Operational mode.

CONFIGURATION #CONFIG CHANGEJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
set system autoinstallation usb disable

Purpose: Optional reverse action: deliberately disable USB autoinstallation when you do not want insertion of a prepared USB to trigger the feature.

5. Update U-Boot / Veloader If Required

Only perform bootloader work after checking versions. For SRX300-line 24.4R1+ USB/TFTP, Juniper requires U-Boot 3.15+ and a loader build from 2023 or later.

Enter shell: use start shell from Operational mode.
Upgrade U-Boot: bootupgrade -u /boot/uboot.
Upgrade Veloader: bootupgrade -l /boot/veloader -x.
Reboot: the new bootloader version takes effect after reboot.
Verify again: inspect console boot output and rerun firmware/BIOS checks.
⚠ High-risk section: verify backups, device model, image type and recovery procedure before executing these commands.
8 command entries in this section
SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -u /boot/uboot

Purpose: Upgrade primary U-Boot.

SHELL % HIGH RISK Juniper Verified
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -s -u

Purpose: Upgrade the secondary boot loader using Juniper-documented bootupgrade syntax. Use only when the platform/release procedure calls for it.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -l /boot/veloader -x

Purpose: Upgrade Veloader.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -c u-boot

Purpose: Verify/check primary U-Boot CRC.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -s -c u-boot

Purpose: Verify/check secondary U-Boot CRC.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -c loader

Purpose: Verify/check loader CRC.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
reboot

Purpose: Reboot after boot firmware work.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system snapshot slice alternate

Purpose: Copy the active root file system to the alternate root slice on supported SRX platforms.

6. Backup, Rescue & Pre-Upgrade Checks

Back up first, save rescue/recovery state where applicable, check storage and alarms.

16 command entries in this section
CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
request system configuration rescue save

Purpose: Save the current configuration as the rescue configuration.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system autorecovery state save

Purpose: Save autorecovery state on releases where autorecovery is supported. On FreeBSD 12 / newer SRX software, Juniper directs you to snapshots instead.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system storage cleanup

Purpose: Clean up extra files from local storage before an upgrade.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show version

Purpose: Display the current Junos release.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system firmware

Purpose: See firmware / boot version information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system storage

Purpose: Check internal storage usage.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show system storage detail

Purpose: Display more detailed storage information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis hardware

Purpose: Display chassis hardware.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system uptime

Purpose: Check uptime.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system alarms

Purpose: Check system alarms.

OPERATIONAL > READ ONLY Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
show system alarms

Purpose: Display active Junos system alarms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis alarms

Purpose: Check chassis alarms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show interfaces terse

Purpose: Review interface state.

CONFIGURATION # READ ONLY Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show configuration | display set | match root-authentication

Purpose: Check the root-authentication configuration line(s).

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
file list /var/tmp

Purpose: List files in /var/tmp.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show log messages | last 20

Purpose: Review the last 20 log lines.

7. USB Safety Before Inserting or Removing Media

Understand the autoinstall scan and removal timing before working with any USB device.

Do not remove a newly inserted USB immediately. With USB autoinstallation enabled, wait at least 60 seconds before removal. Removing it during the scan can cause an SRX reboot, USB-port failure, or USB data loss.
3 command entries in this section
CONFIGURATION #CONFIG CHANGEJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
set system autoinstallation usb disable

Purpose: Optional safety setting if you need to use USB only as storage and want to prevent automatic image installation. Commit the change before inserting the USB.

CONFIGURATION #CONFIG CHANGEJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
delete system autoinstallation usb disable

Purpose: Re-enable the default USB autoinstall behavior when you want to perform automatic USB image installation.

CONFIGURATION #CONFIG CHANGEJuniper Verified
Required prompt ends with #. Commit configuration changes before leaving.
commit

Purpose: Save the USB autoinstallation configuration change.

8. Prepare the USB for Automatic Junos Installation

Create the supported USB layout and autoinstall marker before inserting it into the SRX.

Use a suitable USB flash drive: USB 2.0 or later and FAT/FAT32/MS-DOS format.
Copy exactly one Junos image to the root of the USB. For 24.4R1+ use the package type appropriate to the USB installation method; do not substitute a CLI or TFTP package merely by renaming it.
Create autoinstall.conf as an empty file in the USB root.
Optional: add junos-config.conf if you want an automatic configuration update/backup during the process.
Before insertion: verify the SRX does not have set system autoinstallation usb disable configured.
24.4R1+ package families: CLI = junos-install-srxsme-mips-64*; TFTP loader = junos-install-media-net-srxsme-mips-64*; USB installation = junos-install-media-usb-srxsme-mips-64*; firmware package = jfirmware-srxsme-mips-64*.
1 command entries in this section
ADMIN PC / TERMINALCOMMANDJuniper Verified
Run on the administrator computer, not at an SRX Junos prompt.
echo " " > F:\autoinstall.conf

Purpose: On a Windows administrator PC, create the empty autoinstall.conf marker file in the root of the USB. Replace F: with the actual USB drive letter.

9. Automatic USB Firmware Installation — autoinstall.conf + RESET CONFIG

Use this when the SRX can still detect the USB autoinstall mechanism. This is different from boot-loader disaster recovery.

Insert the prepared USB into the SRX USB port and watch the LEDs.
Observe amber indication. The LEDs initially blink amber and then become steady amber when the Junos image is recognised.
Press the physical RESET CONFIG button once to start the image installation. When a valid USB install image is present, the button acts as the image-upgrade trigger.
Do not interrupt power. Steady amber indicates installation is in progress.
Green LEDs indicate successful installation. Red indicates an installation error and requires console troubleshooting.
Remove USB only when safe. The SRX automatically restarts and loads the new Junos version.
Important: this mechanism will not start if set system autoinstallation usb disable is configured.

10. Complete Failure — Boot Loader + USB Clean Recovery

Primary disaster-recovery path when Junos does not boot but the boot loader is still usable.

⚠ High-risk recovery section: this procedure can format or overwrite internal boot media. Use console access and verify the exact package and SRX model first.
COMPLETE FAILURE / CORRUPTED INTERNAL MEDIA: use this path when Junos will not boot but U-Boot/loader still work. It is a destructive recovery procedure and can overwrite the internal installation.
Connect console before powering on so you can see the boot sequence.
Prepare MS-DOS/FAT USB with the correct Junos USB installation image.
Insert USB before power-cycle/reboot.
Interrupt boot and stop at loader>.
Run the loader install file:///... command. Internal media is formatted and Junos is installed.
If USB is not recognised: leave it inserted, power-cycle the SRX and retry from loader>.
After successful installation: remove USB safely and verify the system after boot.
For 24.4R1 or later: U-Boot must already be 3.15+ and the loader build must be from 2023 or later. If the device has failed before those prerequisites were established, recovery may require an intermediate supported recovery path or JTAC guidance.
2 command entries in this section
ACCESS / PROMPTREAD ONLYJuniper Verified
Follow the access instruction shown.
loader>

Purpose: Target prompt for disaster recovery. Reach it via console by interrupting normal boot when prompted.

BOOT LOADER loader>HIGH RISKJuniper Verified
You must be at the boot loader prompt: loader>.
install file:///<image-path-on-usb>

Purpose: From loader>, install the Junos image from USB. Juniper documents that this procedure formats internal media and installs Junos with dual-root partitioning.

11. Manual USB Mounting, Backup & File Handling

Use the USB as ordinary storage when manually copying firmware or configuration files.

13 command entries in this section
SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mkdir /var/tmp/usb

Purpose: Create the temporary USB mount point.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mount_msdosfs /dev/da1s1 /var/tmp/usb

Purpose: Mount a FAT/FAT32 USB drive. Replace da1s1 if the SRX detects a different device such as da2s1.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mount -t msdosfs /dev/da1s1 /var/tmp/usb

Purpose: Mount a FAT/FAT32 USB partition.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mount -t msdosfs /dev/da1 /mnt

Purpose: Alternative FAT/FAT32 mount using /dev/da1 and /mnt.

SHELL % READ ONLY Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
ls /var/tmp/usb

Purpose: Confirm the firmware file is present.

SHELL % READ ONLY Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
file list /var/tmp/usb

Purpose: Verify that msqsrx-usb.conf is present.

OPERATIONAL > READ ONLY Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
file list /var/tmp/usb

Purpose: List files on the USB mounted at /var/tmp/usb.

CONFIGURATION # READ ONLY Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show configuration | save /var/tmp/usb/msqsrx-usb.conf

Purpose: Save the active configuration to the mounted USB using the supplied filename.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
show configuration | save /var/tmp/srx_backup.conf

Purpose: Save the active committed configuration from Operational mode to /var/tmp/srx_backup.conf.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
file copy /var/tmp/srx_backup.conf /var/tmp/usb/

Purpose: Copy the configuration backup from internal storage to the USB mount point.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
file copy /var/tmp/usb/srx_backup.conf /var/tmp/

Purpose: Copy the configuration backup from the mounted USB to internal /var/tmp.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
umount /var/tmp/usb

Purpose: Unmount the USB before removing it.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
umount /cf/var/tmp/usb

Purpose: Unmount the USB path used in this source example.

12. Manual Junos Installation Directly from a Mounted USB

Normal CLI-based installation from a mounted USB when Junos is still running.

6 command entries in this section
SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /mnt/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot

Purpose: Used when the USB was mounted on /mnt using /dev/da1.

OPERATIONAL > REBOOT / IMPACT Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/usb/junos.tgz no-validate reboot

Purpose: Install a valid Junos CLI installation package from the USB mount point and reboot. Replace junos.tgz with the exact compatible package name.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos.tgz no-validate reboot

Purpose: Generic junos.tgz example.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot

Purpose: 24.4R2.21 direct USB example.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos23.tgz no-validate reboot

Purpose: Source example named junos23.tgz.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos21.tgz no-validate reboot

Purpose: Source example named junos21.tgz.

13. Network / Management Configuration for Online Download

Configure management IP, SSH, gateway and related settings when needed.

8 command entries in this section
CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system root-authentication plain-text-password

Purpose: Set the root password.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system host-name srx

Purpose: Set hostname to srx.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system services ssh

Purpose: Enable SSH.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system services ssh root-login allow

Purpose: Allow root SSH login.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set interfaces fxp0 unit 0 family inet address 192.168.0.178/24

Purpose: Assign the example management IP to fxp0.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set security zones security-zone trust host-inbound-traffic system-services ssh

Purpose: Allow SSH host-inbound traffic on the trust zone.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set chassis alarm management-ethernet link-down ignore

Purpose: Ignore the management Ethernet link-down alarm if fxp0 is intentionally unused.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
commit

Purpose: Validate and apply the candidate Junos configuration so the changes become active.

14. Connect the SRX to the Internet & Download Directly from Juniper

Stage an authenticated Juniper download directly into /var/tmp.

Official Juniper method: On the Juniper Download Software page, choose the correct SRX platform and Junos release, sign in with your Juniper account, accept the applicable licence terms, then use the page's Copy function to copy the generated device-download URL. Juniper states that this generated URL is active for approximately 15 minutes. On the SRX, run file copy "URL" /var/tmp. A Juniper account and appropriate software entitlement/support access may be required.
Do not guess the package: Select the package that Juniper lists for the exact SRX model and target release. Image names and upgrade requirements change between Junos releases. Keep console access available for firmware upgrades because management connectivity can be interrupted during reboot.
1Configure SRX IP / route / DNS
2Verify internet connectivity
3Sign in to Juniper Downloads
4Copy generated URL to /var/tmp
5Verify and install the package

Browser steps on the administrator PC

  1. Open Juniper Support — Downloads.
  2. Select the SRX platform and the required Junos release/package for the exact device.
  3. Sign in with your Juniper Networks account. Juniper documentation notes that download access can require a valid support contract/software entitlement.
  4. Review and accept the licence terms where presented.
  5. Use the Juniper page's device-download option and click Copy to copy the generated temporary URL.
  6. Return immediately to the SRX Operational prompt and use the file copy command below. The URL is time-limited.
13 command entries in this section
OPERATIONAL >CONFIG CHANGEJuniper Official / Added
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
configure

Purpose: Enter Configuration mode before adding or changing management connectivity settings.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
set interfaces fxp0 unit 0 family inet address <MANAGEMENT-IP>/<PREFIX-LENGTH>

Purpose: Assign an IPv5 management address to fxp0. Replace the placeholders with the address and prefix for your network. If you manage the SRX through another interface, use that interface instead.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
set routing-options static route 0.0.0.0/0 next-hop <DEFAULT-GATEWAY-IP>

Purpose: Add a default route so the SRX itself can reach addresses outside the local management subnet.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
set system name-server <DNS-SERVER-IP>

Purpose: Configure a DNS resolver so the SRX can resolve hostnames used by external services.

CONFIGURATION #READ ONLYJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
show | compare

Purpose: Review the candidate management, route and DNS changes before saving them.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
commit

Purpose: Save and activate the configuration changes.

OPERATIONAL >COMMANDJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
exit

Purpose: Leave Configuration mode and return to Operational mode.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
show route 0.0.0.0/0

Purpose: Verify that a default route is present in the routing table.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
ping 8.8.8.8 count 5

Purpose: Test basic IP connectivity to the internet without relying on DNS.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
ping www.juniper.net count 5

Purpose: Test DNS resolution and external reachability. ICMP may be filtered on some paths, so a failed ping does not by itself prove HTTPS is unavailable.

OPERATIONAL >COMMANDJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
file copy "<JUNIPER-GENERATED-DOWNLOAD-URL>" /var/tmp/

Purpose: Download the selected Junos package directly from the temporary URL generated by the Juniper Download Software page. Juniper documents this as the direct device-download method; paste the generated URL inside quotation marks.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
file list /var/tmp/

Purpose: Confirm that the Junos package is present in /var/tmp after the download.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
request system software validate /var/tmp/<JUNOS-INSTALL-PACKAGE>.tgz

Purpose: Optionally validate the downloaded Junos package before installation when supported for the release and upgrade path.

After the file is in /var/tmp: use the dedicated Internal Storage Installation section below. Your exact 25.2R1.9 jfirmware, junos-install and junos-install-media-net examples are retained there; the loader-specific example remains in the recovery section.

Juniper sources: Preparing for Software Installation and Upgrade; request system software add; and SRX software-download guidance. The direct Juniper device-download workflow uses a temporary URL copied from the authenticated Juniper download page rather than embedding your Juniper username/password in the SRX command.

15. Install Firmware Already Staged in Internal /var/tmp

Install the appropriate CLI package after it has been copied or downloaded to internal storage.

Exact method retained: The jfirmware-srxsme-mips-64-25.2R1.9.tgz, junos-install-srxsme-mips-64-25.2R1.9.tgz, and junos-install-media-net-srxsme-mips-64-25.2R1.9.tgz Operational-mode examples are all included below. The source-retained loader> install file:///var/tmp/junos-install-srxsme-mips-64-25.2R1.9.tgz example is kept in the Clean Install, Repartition & Recovery section because it belongs to the boot-loader environment.
5 command entries in this section
SHELL % READ ONLY Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
ls -lh /var/tmp/junos.tgz

Purpose: Verify a copied .tgz file and its size, if that is the filename used.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos.tgz no-validate reboot

Purpose: Install junos.tgz from internal storage and reboot.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/jfirmware-srxsme-mips-64-25.2R1.9.tgz no-validate reboot

Purpose: jfirmware 25.2R1.9 example from internal storage.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos-install-srxsme-mips-64-25.2R1.9.tgz no-validate reboot

Purpose: junos-install 25.2R1.9 example from internal storage.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
rm /var/tmp/junos.tgz

Purpose: Delete the copied junos.tgz after it is no longer needed.

16. Clean / Repartition / Legacy Recovery Methods

Version-dependent clean-install and repartition procedures. Read warnings carefully.

⚠ High-risk section: verify backups, device model, image type and recovery procedure before executing these commands.
4 command entries in this section
OPERATIONAL > HIGH RISK Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/usb/junos.tgz partition no-validate reboot

Purpose: Repartition and install the Junos package from USB, then reboot. This is destructive.

OPERATIONAL > HIGH RISK Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos-srxsme-23.4R2.13.tgz no-copy no-validate partition reboot

Purpose: Pre-24.4 SRX300-line repartition example. Back up first. The partition workflow does not apply the same way to Junos 24.4 and later.

BOOT LOADER loader> COMMAND Word Guide
Required prompt is loader>. Reach it through the boot/recovery process, not from normal CLI navigation.
boot -s

Purpose: Boot to single-user mode as recorded in the source.

BOOT LOADER loader> COMMAND Juniper Verified
Run at loader>. The loader installation formats internal media; back up configuration first.
install file:///junos-install-media-usb-srxsme-mips-64-<RELEASE>.img.gz

Purpose: Install Junos from a USB installation-media image at the loader prompt. Use the exact media-usb filename supplied by Juniper for your release.

17. TFTP / SCP Installation & Loader Recovery

Network-based staging and loader recovery when USB is unavailable.

12 command entries in this section
U-BOOT => COMMAND Juniper Verified
Run at the U-Boot => prompt before entering the FreeBSD loader.
setenv ipaddr 192.168.1.20

Purpose: Set the temporary SRX IP address in U-Boot for TFTP recovery.

U-BOOT => COMMAND Juniper Verified
Run at the U-Boot => prompt.
setenv netmask 255.255.255.0

Purpose: Set the temporary network mask in U-Boot.

U-BOOT => COMMAND Juniper Verified
Run at the U-Boot => prompt.
setenv serverip 192.168.1.10

Purpose: Set the TFTP server IP address in U-Boot.

U-BOOT =>COMMANDJuniper Verified
Run at the U-Boot => prompt.
setenv gatewayip 192.168.1.1

Purpose: Set the default gateway in U-Boot when the TFTP server is not on the same subnet.

U-BOOT =>COMMANDJuniper Verified
Run at the U-Boot => prompt.
saveenv

Purpose: Save U-Boot environment variables before rebooting to the loader stage.

U-BOOT =>HIGH RISKJuniper Verified
Run at the U-Boot => prompt.
reset

Purpose: Reboot from U-Boot after saving the network environment so you can stop at loader>.

BOOT LOADER loader> COMMAND Juniper Verified
Run only after U-Boot network variables are set and you have reached loader>.
install tftp://192.168.1.10/junos-install-media-net-srxsme-mips-64-25.2R1.9.tgz

Purpose: From loader>, download and install the network-install media package from the TFTP server. This operation formats internal media.

BOOT LOADER loader> COMMAND Uploaded HTML
Required prompt is loader>. Reach it through the boot/recovery process, not from normal CLI navigation.
install tftp://192.168.1.10/junos.tgz

Purpose: Install a Junos image from the example TFTP server using the shorter example filename.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
scp carlos@192.168.0.102:/var/lib/tftpboot/junos-srxsme-21.2R1.10.tgz /var/tmp/

Purpose: Copy the Junos image from the source server to /var/tmp.

SHELL % COMMAND Uploaded HTML
Required prompt ends with %. From Operational mode, use start shell when needed.
scp user@host:/path/to/junos.tgz /var/tmp/

Purpose: Generic SCP example for copying a Junos package from a remote host to /var/tmp.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos-srxsme-21.2R1.10.tgz no-copy

Purpose: Add the new software without copying the package again.

OPERATIONAL > REBOOT / IMPACT Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system reboot

Purpose: Reboot the SRX.

18. Configuration Restore Workflow

Restore a saved configuration, compare it, commit it, and save a new recovery point.

7 command entries in this section
OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
file copy /var/tmp/usb/srx_backup.conf /var/tmp/

Purpose: Copy the configuration backup from the mounted USB to internal /var/tmp.

OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
configure

Purpose: Enter Junos configuration mode.

CONFIGURATION # HIGH RISK Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
load override /var/tmp/backup.conf

Purpose: Replace the candidate configuration with the specified backup file; review and commit before use.

CONFIGURATION # HIGH RISK Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
load override /var/tmp/srx_backup.conf

Purpose: Replace the candidate configuration with the SRX backup file; review and commit before use.

CONFIGURATION # CONFIG CHANGE Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show | compare

Purpose: Review candidate configuration changes against the active configuration before commit.

CONFIGURATION # CONFIG CHANGE Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
commit and-quit

Purpose: Commit the candidate configuration, apply it, and leave configuration mode.

CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
request system configuration rescue save

Purpose: Save the current configuration as the rescue configuration.

19. Post-Upgrade Verification, Logs, Storage & Routing

Confirm Junos, firmware, partitions, alarms, interfaces, routing and logs after work.

24 command entries in this section
OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system information

Purpose: Check system information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis hardware detail

Purpose: Display detailed hardware information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis fpc pic-status

Purpose: Check FPC/PIC status.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis routing-engine

Purpose: Check Routing Engine status.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis environment

Purpose: Check chassis environmental state.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system license

Purpose: Check licenses.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show system processes

Purpose: Display active system processes.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show log messages | match ERROR

Purpose: Filter system log messages for entries containing ERROR.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show route summary

Purpose: Display a summary of the routing table.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show version

Purpose: Display the current Junos release.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis hardware

Purpose: Display chassis hardware.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis alarms

Purpose: Check chassis alarms.

OPERATIONAL > READ ONLY Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
show system alarms

Purpose: Display active Junos system alarms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system alarms

Purpose: Check system alarms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system storage

Purpose: Check internal storage usage.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show system storage detail

Purpose: Display more detailed storage information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system uptime

Purpose: Check uptime.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show log messages | last 20

Purpose: Review the last 20 log lines.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
file list /var/tmp

Purpose: List files in /var/tmp.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show interfaces terse

Purpose: Review interface state.

CONFIGURATION # READ ONLY Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show configuration | display set | match root-authentication

Purpose: Check the root-authentication configuration line(s).

OPERATIONAL >COMMANDJuniper Verified
Run from Junos Operational mode (>).
show system storage partitions

Purpose: Verify active/backup partition details and boot media on supported SRX devices.

OPERATIONAL >COMMANDJuniper Verified
Run from Junos Operational mode (>).
show chassis routing-engine bios

Purpose: Display the Routing Engine BIOS version on supported SRX platforms.

OPERATIONAL >COMMANDJuniper Verified
Run from Junos Operational mode (>).
show system autorecovery state

Purpose: Display saved autorecovery status on releases where autorecovery is supported.

20. Official Juniper References Used for Verification

Primary Juniper sources used to verify the recovery and upgrade procedures.

21. Complete Command Inventory

Master searchable command inventory retained for completeness.

Some commands intentionally appear earlier in workflow sections as well. Duplicate contextual appearances are retained because they help users follow a procedure.

108 command entries in this section
ACCESS / PROMPT COMMAND Word Guide
Follow the access instructions shown for this item.
Press Enter

Purpose: Wake the console session and display the SRX login prompt if it is not already visible.

ACCESS / PROMPT COMMAND Word Guide
Follow the access instructions shown for this item.
root

Purpose: Example administrator username from the supplied notes. If the SRX uses another administrator account, enter that username instead.

ADMIN PC / TERMINAL COMMAND Word Guide
Run this on the administrator computer, not at an SRX Junos prompt.
ssh <username>@<management-IP>

Purpose: Open an SSH session to the SRX using the actual administrator username and management IP address.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
root@SRX>

Purpose: Command retained from the supplied source material.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
root@SRX#

Purpose: Command retained from the supplied source material.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
root@SRX%

Purpose: Command retained from the supplied source material.

ACCESS / PROMPT READ ONLY Word Guide
Follow the access instructions shown for this item.
loader>

Purpose: Command retained from the supplied source material.

OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
configure

Purpose: Enter Junos configuration mode.

CONFIGURATION # COMMAND Juniper Verified
You must already be at a # prompt. Example: edit system services.
edit <hierarchy>

Purpose: Navigate to a configuration hierarchy after you are already in Configuration mode. Use configure—not edit—to enter Configuration mode from Operational mode.

CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
exit

Purpose: Leave configuration mode. If configuration changes were made, commit them first unless you intentionally intend to discard them.

OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
start shell

Purpose: Enter the underlying shell environment.

OPERATIONAL > COMMAND Word Guide
Enter this command from Junos Operational mode (>). The prompt will change to the target mode.
start shell user root

Purpose: Enter the shell as root, as shown in the supplied upgrade example.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
cli

Purpose: Start or return to the Junos CLI from the shell.

CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set <configuration-statement>

Purpose: Enter the required configuration statement from the relevant section.

CONFIGURATION # CONFIG CHANGE Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show | compare

Purpose: Review candidate configuration changes against the active configuration before commit.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
commit

Purpose: Validate and apply the candidate Junos configuration so the changes become active.

CONFIGURATION # CONFIG CHANGE Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
commit and-quit

Purpose: Commit the candidate configuration, apply it, and leave configuration mode.

CONFIGURATION # COMMAND Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
request system configuration rescue save

Purpose: Save the current configuration as the rescue configuration.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system autorecovery state save

Purpose: Save autorecovery state on releases where autorecovery is supported. On FreeBSD 12 / newer SRX software, Juniper directs you to snapshots instead.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system storage cleanup

Purpose: Clean up extra files from local storage before an upgrade.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show version

Purpose: Display the current Junos release.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system firmware

Purpose: See firmware / boot version information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system storage

Purpose: Check internal storage usage.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show system storage detail

Purpose: Display more detailed storage information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis hardware

Purpose: Display chassis hardware.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system uptime

Purpose: Check uptime.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system alarms

Purpose: Check system alarms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis alarms

Purpose: Check chassis alarms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show interfaces terse

Purpose: Review interface state.

CONFIGURATION # READ ONLY Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show configuration | display set | match root-authentication

Purpose: Check the root-authentication configuration line(s).

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
file list /var/tmp

Purpose: List files in /var/tmp.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show log messages | last 20

Purpose: Review the last 20 log lines.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mkdir /var/tmp/usb

Purpose: Create the temporary USB mount point.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mount_msdosfs /dev/da1s1 /var/tmp/usb

Purpose: Mount a FAT/FAT32 USB drive. Replace da1s1 if the SRX detects a different device such as da2s1.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mount -t msdosfs /dev/da1s1 /var/tmp/usb

Purpose: Mount a FAT/FAT32 USB partition.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
mount -t msdosfs /dev/da1 /mnt

Purpose: Alternative FAT/FAT32 mount using /dev/da1 and /mnt.

SHELL % READ ONLY Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
ls /var/tmp/usb

Purpose: Confirm the firmware file is present.

SHELL % READ ONLY Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
file list /var/tmp/usb

Purpose: Verify that msqsrx-usb.conf is present.

CONFIGURATION # READ ONLY Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
show configuration | save /var/tmp/usb/msqsrx-usb.conf

Purpose: Save the active configuration to the mounted USB using the supplied filename.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
show configuration | save /var/tmp/srx_backup.conf

Purpose: Save the active committed configuration from Operational mode to /var/tmp/srx_backup.conf.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
file copy /var/tmp/srx_backup.conf /var/tmp/usb/

Purpose: Copy the configuration backup from internal storage to the USB mount point.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
file copy /var/tmp/usb/srx_backup.conf /var/tmp/

Purpose: Copy the configuration backup from the mounted USB to internal /var/tmp.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
umount /var/tmp/usb

Purpose: Unmount the USB before removing it.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
umount /cf/var/tmp/usb

Purpose: Unmount the USB path used in this source example.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /mnt/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot

Purpose: Used when the USB was mounted on /mnt using /dev/da1.

OPERATIONAL > REBOOT / IMPACT Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/usb/junos.tgz no-validate reboot

Purpose: Install a valid Junos CLI installation package from the USB mount point and reboot. Replace junos.tgz with the exact compatible package name.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot

Purpose: 24.4R2.21 direct USB example.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos23.tgz no-validate reboot

Purpose: Source example named junos23.tgz.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
request system software add /var/tmp/usb/junos21.tgz no-validate reboot

Purpose: Source example named junos21.tgz.

SHELL % READ ONLY Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
ls -lh /var/tmp/junos.tgz

Purpose: Verify a copied .tgz file and its size, if that is the filename used.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos.tgz no-validate reboot

Purpose: Install junos.tgz from internal storage and reboot.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/jfirmware-srxsme-mips-64-25.2R1.9.tgz no-validate reboot

Purpose: jfirmware 25.2R1.9 example from internal storage.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos-install-srxsme-mips-64-25.2R1.9.tgz no-validate reboot

Purpose: junos-install 25.2R1.9 example from internal storage.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
rm /var/tmp/junos.tgz

Purpose: Delete the copied junos.tgz after it is no longer needed.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
set interfaces fxp0 unit 0 family inet address <MANAGEMENT-IP>/<PREFIX-LENGTH>

Purpose: Assign an IPv5 management address to fxp0. Replace the placeholders with the address and prefix for your network. If you manage the SRX through another interface, use that interface instead.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
set routing-options static route 0.0.0.0/0 next-hop <DEFAULT-GATEWAY-IP>

Purpose: Add a default route so the SRX itself can reach addresses outside the local management subnet.

CONFIGURATION #CONFIG CHANGEJuniper Official / Added
Required prompt ends with #. Use configure first; review with show | compare and commit changes before leaving.
set system name-server <DNS-SERVER-IP>

Purpose: Configure a DNS resolver so the SRX can resolve hostnames used by external services.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
show route 0.0.0.0/0

Purpose: Verify that a default route is present in the routing table.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
ping 8.8.8.8 count 5

Purpose: Test basic IP connectivity to the internet without relying on DNS.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
ping www.juniper.net count 5

Purpose: Test DNS resolution and external reachability. ICMP may be filtered on some paths, so a failed ping does not by itself prove HTTPS is unavailable.

OPERATIONAL >COMMANDJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
file copy "<JUNIPER-GENERATED-DOWNLOAD-URL>" /var/tmp/

Purpose: Download the selected Junos package directly from the temporary URL generated by the Juniper Download Software page. Juniper documents this as the direct device-download method; paste the generated URL inside quotation marks.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
file list /var/tmp/

Purpose: Confirm that the Junos package is present in /var/tmp after the download.

OPERATIONAL >READ ONLYJuniper Official / Added
Required prompt typically ends with > (for example root@SRX>).
request system software validate /var/tmp/<JUNOS-INSTALL-PACKAGE>.tgz

Purpose: Optionally validate the downloaded Junos package before installation when supported for the release and upgrade path.

OPERATIONAL > HIGH RISK Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/usb/junos.tgz partition no-validate reboot

Purpose: Repartition and install the Junos package from USB, then reboot. This is destructive.

OPERATIONAL > HIGH RISK Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos-srxsme-23.4R2.13.tgz no-copy no-validate partition reboot

Purpose: Pre-24.4 SRX300-line repartition example. Back up first. The partition workflow does not apply the same way to Junos 24.4 and later.

BOOT LOADER loader> COMMAND Word Guide
Required prompt is loader>. Reach it through the boot/recovery process, not from normal CLI navigation.
boot -s

Purpose: Boot to single-user mode as recorded in the source.

BOOT LOADER loader> COMMAND Juniper Verified
Run at loader>. The loader installation formats internal media; back up configuration first.
install file:///junos-install-media-usb-srxsme-mips-64-<RELEASE>.img.gz

Purpose: Install Junos from a USB installation-media image at the loader prompt. Use the exact media-usb filename supplied by Juniper for your release.

U-BOOT => COMMAND Juniper Verified
Run at the U-Boot => prompt before entering the FreeBSD loader.
setenv ipaddr 192.168.1.20

Purpose: Set the temporary SRX IP address in U-Boot for TFTP recovery.

U-BOOT => COMMAND Juniper Verified
Run at the U-Boot => prompt.
setenv netmask 255.255.255.0

Purpose: Set the temporary network mask in U-Boot.

U-BOOT => COMMAND Juniper Verified
Run at the U-Boot => prompt.
setenv serverip 192.168.1.10

Purpose: Set the TFTP server IP address in U-Boot.

U-BOOT =>COMMANDJuniper Verified
Run at the U-Boot => prompt.
setenv gatewayip 192.168.1.1

Purpose: Set the default gateway in U-Boot when the TFTP server is not on the same subnet.

U-BOOT =>COMMANDJuniper Verified
Run at the U-Boot => prompt.
saveenv

Purpose: Save U-Boot environment variables before rebooting to the loader stage.

U-BOOT =>HIGH RISKJuniper Verified
Run at the U-Boot => prompt.
reset

Purpose: Reboot from U-Boot after saving the network environment so you can stop at loader>.

BOOT LOADER loader> COMMAND Juniper Verified
Run only after U-Boot network variables are set and you have reached loader>.
install tftp://192.168.1.10/junos-install-media-net-srxsme-mips-64-25.2R1.9.tgz

Purpose: From loader>, download and install the network-install media package from the TFTP server. This operation formats internal media.

BOOT LOADER loader> COMMAND Uploaded HTML
Required prompt is loader>. Reach it through the boot/recovery process, not from normal CLI navigation.
install tftp://192.168.1.10/junos.tgz

Purpose: Install a Junos image from the example TFTP server using the shorter example filename.

SHELL % COMMAND Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
scp carlos@192.168.0.102:/var/lib/tftpboot/junos-srxsme-21.2R1.10.tgz /var/tmp/

Purpose: Copy the Junos image from the source server to /var/tmp.

SHELL % COMMAND Uploaded HTML
Required prompt ends with %. From Operational mode, use start shell when needed.
scp user@host:/path/to/junos.tgz /var/tmp/

Purpose: Generic SCP example for copying a Junos package from a remote host to /var/tmp.

OPERATIONAL > COMMAND Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system software add /var/tmp/junos-srxsme-21.2R1.10.tgz no-copy

Purpose: Add the new software without copying the package again.

OPERATIONAL > REBOOT / IMPACT Word Guide
Required prompt typically ends with > (for example root@SRX>).
request system reboot

Purpose: Reboot the SRX.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system root-authentication plain-text-password

Purpose: Set the root password.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system host-name srx

Purpose: Set hostname to srx.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system services ssh

Purpose: Enable SSH.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set system services ssh root-login allow

Purpose: Allow root SSH login.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set interfaces fxp0 unit 0 family inet address 192.168.0.178/24

Purpose: Assign the example management IP to fxp0.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set security zones security-zone trust host-inbound-traffic system-services ssh

Purpose: Allow SSH host-inbound traffic on the trust zone.

CONFIGURATION # CONFIG CHANGE Word Guide
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
set chassis alarm management-ethernet link-down ignore

Purpose: Ignore the management Ethernet link-down alarm if fxp0 is intentionally unused.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -u /boot/uboot

Purpose: Upgrade primary U-Boot.

SHELL % HIGH RISK Juniper Verified
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -s -u

Purpose: Upgrade the secondary boot loader using Juniper-documented bootupgrade syntax. Use only when the platform/release procedure calls for it.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -l /boot/veloader -x

Purpose: Upgrade Veloader.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -c u-boot

Purpose: Verify/check primary U-Boot CRC.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -s -c u-boot

Purpose: Verify/check secondary U-Boot CRC.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
bootupgrade -c loader

Purpose: Verify/check loader CRC.

SHELL % HIGH RISK Word Guide
Required prompt ends with %. From Operational mode, use start shell when needed.
reboot

Purpose: Reboot after boot firmware work.

OPERATIONAL > COMMAND Juniper Verified
Required prompt typically ends with > (for example root@SRX>).
request system snapshot slice alternate

Purpose: Copy the active root file system to the alternate root slice on supported SRX platforms.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system information

Purpose: Check system information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis hardware detail

Purpose: Display detailed hardware information.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis fpc pic-status

Purpose: Check FPC/PIC status.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis routing-engine

Purpose: Check Routing Engine status.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show chassis environment

Purpose: Check chassis environmental state.

OPERATIONAL > READ ONLY Word Guide
Required prompt typically ends with > (for example root@SRX>).
show system license

Purpose: Check licenses.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show system processes

Purpose: Display active system processes.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show log messages | match ERROR

Purpose: Filter system log messages for entries containing ERROR.

OPERATIONAL > READ ONLY Uploaded HTML
Required prompt typically ends with > (for example root@SRX>).
show route summary

Purpose: Display a summary of the routing table.

OPERATIONAL >COMMANDJuniper Verified
Run from Junos Operational mode (>).
show system storage partitions

Purpose: Verify active/backup partition details and boot media on supported SRX devices.

OPERATIONAL >COMMANDJuniper Verified
Run from Junos Operational mode (>).
show chassis routing-engine bios

Purpose: Display the Routing Engine BIOS version on supported SRX platforms.

OPERATIONAL >COMMANDJuniper Verified
Run from Junos Operational mode (>).
show system autorecovery state

Purpose: Display saved autorecovery status on releases where autorecovery is supported.

CONFIGURATION # HIGH RISK Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
load override /var/tmp/backup.conf

Purpose: Replace the candidate configuration with the specified backup file; review and commit before use.

CONFIGURATION # HIGH RISK Uploaded HTML
Required prompt ends with #. Use configure/edit first; commit configuration changes before leaving.
load override /var/tmp/srx_backup.conf

Purpose: Replace the candidate configuration with the SRX backup file; review and commit before use.

No matching commands found. Clear the search or change the filters.
Recovery-first interactive SRX command runbook. Commands and recovery prerequisites should always be confirmed against the exact SRX model, installed Junos release, target release and current Juniper documentation.
Juniper-verified recovery order: This version places SRX300-line bootloader prerequisites, USB-autoinstall status and complete-failure USB recovery before routine upgrade methods. For 24.4R1+ USB/TFTP installation, U-Boot 3.15+ and a loader build from 2023 or later are mandatory prerequisites.
Safety: Commands involving partition, rm, loader install, TFTP recovery, or low-level bootupgrade operations can alter boot media or make the device unavailable. Back up first and confirm the exact SRX model, upgrade path, bootloader prerequisite and package type before production use.
Commit rule: Use commit only for Junos Configuration-mode changes. Operational >, Shell %, Boot Loader loader>, and administrator-PC commands do not use Junos configuration commits.
Operationalroot@SRX>show, request, file
Configurationroot@SRX#set / delete / commit
Shellroot@SRX%mount, cp, ls, rm, scp
Boot Loaderloader>low-level recovery

Further Juniper Information & Upgrade-Path References