Press Enter
Purpose: Wake the console session and display the SRX login prompt if it is not already visible.
RED TEXT ON YELLOW HIGHLIGHT
for rapid identification and copying.
Bootloader checks → USB autoinstall status → bootloader update → backup → USB recovery → normal upgrades → verification
Use this table before running any command. The symbol at the end of the prompt tells you which command environment you are currently using.
| Mode | Typical Prompt | How to Enter | What It Is Used For | Does commit Apply? |
|---|---|---|---|---|
| Operational Mode | root@SRX> |
Log in to Junos CLI, or type cli from a shell. |
Show/status commands, software install requests, reboot, snapshots, file operations. | No |
| Configuration Mode | root@SRX# |
From Operational mode: configure |
Persistent configuration changes using set, delete, etc. |
Yes — use show | compare, then commit. |
| Shell Mode | root@SRX% or root@SRX:/var/tmp # |
From Operational mode: start shell or start shell user root |
FreeBSD file-system work, df, dmesg, dd, gunzip, bootloader utilities. |
No |
| Boot Loader | loader> |
Interrupt the boot process from console. | Disaster recovery from TFTP or a non-bootable USB. | No |
| U-Boot Environment | Platform-dependent boot prompt | Reached during low-level boot/recovery. | Network variables and lower-level recovery on supported releases. | No |
| Admin PC / Terminal | C:\>, PowerShell, macOS/Linux shell |
Use your local workstation. | Prepare USB media, create autoinstall.conf, unzip/write bootable images. |
No |
show | compare and save it with commit before leaving the mode.SRX software download pages can offer several different package types for the same release. They are not interchangeable. Match the file type to the installation method.
| Juniper Download Description | Typical Filename Pattern | Use It From | Purpose | Important Notes |
|---|---|---|---|---|
| CLI Install Image | junos-install-srxsme-mips-64-<RELEASE>.tgz |
Operational mode > |
Normal software installation/upgrade from /var/tmp, mounted USB, or a copied image. |
For USB autoinstallation, use this standard upgrade file in the USB root with autoinstall.conf. Do not use a file containing media, net, or usb for that autoinstall workflow. |
| Net / Loader Install Image | junos-install-media-net-srxsme-mips-64-<RELEASE>.tgz |
loader> |
Loader-based disaster recovery via TFTP or locally attached non-bootable USB for 24.4+. | For 24.4+, the Juniper KB specifically states that the loader method uses the file containing net even when the source is a USB drive. |
| USB Install Image | junos-install-media-usb-srxsme-mips-64-<RELEASE>.img.gz |
Bootable USB media | Create a fully bootable USB recovery/install drive. | Unzip to .img, then write the image to the whole USB device with Rufus or dd. This overwrites the USB and, when used for installation, can return the SRX to factory-default state. |
| Checksums | Release-specific checksum file/value | Admin workstation | Verify download integrity. | Use the checksum published next to the exact image downloaded from Juniper. |
.tgz, loader install-media-net package, and bootable install-media-usb image can all exist for the same release.
The Juniper SRX3xx KB you provided applies specifically to crossing the 24.2/23.4 generation into 24.4 or later on SRX300, SRX320, SRX340, SRX345 and SRX380. Its stated jump versions are:
| Pre-check | Command / Method | Pass Condition | Why It Matters |
|---|---|---|---|
| Current Junos | show version |
Use a supported jump version before crossing to 24.4+. | Unsupported direct jumps can fail or leave the platform requiring recovery. |
| U-Boot / Loader | Check console boot output and boot environment. | For the newer USB/TFTP install architecture, meet the documented bootloader prerequisites for the target release. | Newer installation images may not boot with older loader components. |
| Partition layout | start shell then df -h |
On SRX300/320/340/345, the newer layout shows /dev/bo0s3f around 5 GB. |
Old dual-root layout can block the 24.4 upgrade. |
| Free space | show system storage / df -h |
More than 2 GB free on /dev/bo0s3f. |
The upgrade needs space to create /var/preserve and preserve configs/certificates/licenses/scripts. |
| Backup | request system snapshot media usb |
Bootable snapshot completed and labelled. | Provides a recovery image of the current SRX state. |
/var/log and /var/tmp are lost during this filesystem transition. Loader-based installs and bootable install-media-usb methods can return the SRX to factory default, so back up the configuration, licenses, certificates, scripts and any other required data first.
These commands are taken from the SRX3xx 24.4+ upgrade KB supplied with this runbook and are organised here as workflows.
start shelldf -hshow system snapshot media internalpartition command.request system software add no-copy no-validate partition /var/tmp/junos-srxsme-23.4R2-S3.9.tgzrequest system snapshot media usbshow system snapshot media usbshow system storage | match snap-tmpshow system storage | match snap-tmp | refresh 180start shell user rootdmesg | grep da0:request system software add no-validate /var/tmp/junos-install-srxsme-mips-64-24.4R1.9.tgzrequest system rebootinstall-media-net filename family.install tftp://10.0.113.2/junos-install-media-net-srxsme-mips-64-24.4R1.9.tgzinstall file:///junos-install-media-net-srxsme-mips-64-24.4R1.9.tgzdd overwrites the target device. Verify the USB device name before running it, and do not run dd against a mounted USB on an SRX.gunzip junos-install-media-usb-srxsme-mips-64-24.4R1.9.img.gzdd if=/var/tmp/junos-install-media-usb-srxsme-mips-64-24.4R1.9.img of=/dev/da1 bs=1mrequest system reboot media usbrequest system reboot usbshow log messages | match usb_autoinstallrequest system snapshot media internalrequest system power-offrequest system software add /var/tmp/junos-srxsme-23.4R2-S3.9.tgz rebootrequest system software rollback is not supported for rolling back from 24.4 to an earlier release.All navigation is now at the top. Start with bootloader prerequisites before USB/TFTP work, then follow the recovery or upgrade path that matches the device condition.
Connect by console or SSH and identify which prompt you are at.
Press Enter
Purpose: Wake the console session and display the SRX login prompt if it is not already visible.
root
Purpose: Example administrator username from the supplied notes. If the SRX uses another administrator account, enter that username instead.
ssh <username>@<management-IP>
Purpose: Open an SSH session to the SRX using the actual administrator username and management IP address.
root@SRX>
Purpose: Command retained from the supplied source material.
root@SRX#
Purpose: Command retained from the supplied source material.
root@SRX%
Purpose: Command retained from the supplied source material.
loader>
Purpose: Command retained from the supplied source material.
Know exactly how to move between Operational, Configuration, Shell and Loader environments.
configure
Purpose: Enter Junos configuration mode.
edit <hierarchy>
Purpose: Navigate to a configuration hierarchy after you are already in Configuration mode. Use configure—not edit—to enter Configuration mode from Operational mode.
exit
Purpose: Leave configuration mode. If configuration changes were made, commit them first unless you intentionally intend to discard them.
start shell
Purpose: Enter the underlying shell environment.
start shell user root
Purpose: Enter the shell as root, as shown in the supplied upgrade example.
cli
Purpose: Start or return to the Junos CLI from the shell.
set <configuration-statement>
Purpose: Enter the required configuration statement from the relevant section.
show | compare
Purpose: Review candidate configuration changes against the active configuration before commit.
commit
Purpose: Validate and apply the candidate Junos configuration so the changes become active.
commit and-quit
Purpose: Commit the candidate configuration, apply it, and leave configuration mode.
Do this before any firmware recovery or 24.4R1+ USB/TFTP installation. Do not proceed until you know the current boot environment.
/boot/uboot and /boot/veloader binaries are available.| What to check | Where | Pass condition for 24.4R1+ USB/TFTP |
|---|---|---|
| U-Boot | Console boot output / shell environment | 3.15 or later |
| Loader | Console boot output; note its build date | Build year 2023 or later |
| BIOS/Firmware | show system firmware and show chassis routing-engine bios | No unexpected firmware alarm/status |
show versionPurpose: Confirm the currently running Junos OS release before selecting an upgrade path.
show system firmwarePurpose: Display firmware status and available/current firmware information. Use this as a general firmware health check before and after bootloader work.
show chassis routing-engine biosPurpose: Display the Routing Engine BIOS version on supported SRX platforms.
start shellPurpose: Enter the Junos shell so the U-Boot/loader environment values can be inspected.
kenvPurpose: Display kernel/boot environment values. Check boot.ver, loader.name and loader.version; the loader build date is also visible during console boot.
Confirm USB autoinstallation is not disabled before preparing an automatic USB image installation.
set system autoinstallation usb disable is not present.show configuration system | display set | match autoinstallationPurpose: Check the configured autoinstallation statements. If you see "set system autoinstallation usb disable", USB image autoinstallation is disabled.
configurePurpose: Enter Configuration mode before changing the USB autoinstallation setting.
delete system autoinstallation usb disablePurpose: Remove the explicit USB-autoinstall disable statement so the USB image autoinstallation feature can operate.
show | comparePurpose: Review the candidate change before saving it.
commitPurpose: Save and activate the configuration change.
exitPurpose: Leave Configuration mode and return to Operational mode.
set system autoinstallation usb disablePurpose: Optional reverse action: deliberately disable USB autoinstallation when you do not want insertion of a prepared USB to trigger the feature.
Only perform bootloader work after checking versions. For SRX300-line 24.4R1+ USB/TFTP, Juniper requires U-Boot 3.15+ and a loader build from 2023 or later.
start shell from Operational mode.bootupgrade -u /boot/uboot.bootupgrade -l /boot/veloader -x.bootupgrade -u /boot/uboot
Purpose: Upgrade primary U-Boot.
bootupgrade -s -u
Purpose: Upgrade the secondary boot loader using Juniper-documented bootupgrade syntax. Use only when the platform/release procedure calls for it.
bootupgrade -l /boot/veloader -x
Purpose: Upgrade Veloader.
bootupgrade -c u-boot
Purpose: Verify/check primary U-Boot CRC.
bootupgrade -s -c u-boot
Purpose: Verify/check secondary U-Boot CRC.
bootupgrade -c loader
Purpose: Verify/check loader CRC.
reboot
Purpose: Reboot after boot firmware work.
request system snapshot slice alternate
Purpose: Copy the active root file system to the alternate root slice on supported SRX platforms.
Back up first, save rescue/recovery state where applicable, check storage and alarms.
request system configuration rescue save
Purpose: Save the current configuration as the rescue configuration.
request system autorecovery state save
Purpose: Save autorecovery state on releases where autorecovery is supported. On FreeBSD 12 / newer SRX software, Juniper directs you to snapshots instead.
request system storage cleanup
Purpose: Clean up extra files from local storage before an upgrade.
show version
Purpose: Display the current Junos release.
show system firmware
Purpose: See firmware / boot version information.
show system storage
Purpose: Check internal storage usage.
show system storage detail
Purpose: Display more detailed storage information.
show chassis hardware
Purpose: Display chassis hardware.
show system uptime
Purpose: Check uptime.
show system alarms
Purpose: Check system alarms.
show system alarms
Purpose: Display active Junos system alarms.
show chassis alarms
Purpose: Check chassis alarms.
show interfaces terse
Purpose: Review interface state.
show configuration | display set | match root-authentication
Purpose: Check the root-authentication configuration line(s).
file list /var/tmp
Purpose: List files in /var/tmp.
show log messages | last 20
Purpose: Review the last 20 log lines.
Understand the autoinstall scan and removal timing before working with any USB device.
set system autoinstallation usb disablePurpose: Optional safety setting if you need to use USB only as storage and want to prevent automatic image installation. Commit the change before inserting the USB.
delete system autoinstallation usb disablePurpose: Re-enable the default USB autoinstall behavior when you want to perform automatic USB image installation.
commitPurpose: Save the USB autoinstallation configuration change.
Create the supported USB layout and autoinstall marker before inserting it into the SRX.
autoinstall.conf as an empty file in the USB root.junos-config.conf if you want an automatic configuration update/backup during the process.set system autoinstallation usb disable configured.junos-install-srxsme-mips-64*; TFTP loader = junos-install-media-net-srxsme-mips-64*; USB installation = junos-install-media-usb-srxsme-mips-64*; firmware package = jfirmware-srxsme-mips-64*.echo " " > F:\autoinstall.confPurpose: On a Windows administrator PC, create the empty autoinstall.conf marker file in the root of the USB. Replace F: with the actual USB drive letter.
Use this when the SRX can still detect the USB autoinstall mechanism. This is different from boot-loader disaster recovery.
set system autoinstallation usb disable is configured.Primary disaster-recovery path when Junos does not boot but the boot loader is still usable.
loader>.install file:///... command. Internal media is formatted and Junos is installed.loader>.loader>Purpose: Target prompt for disaster recovery. Reach it via console by interrupting normal boot when prompted.
install file:///<image-path-on-usb>Purpose: From loader>, install the Junos image from USB. Juniper documents that this procedure formats internal media and installs Junos with dual-root partitioning.
Use the USB as ordinary storage when manually copying firmware or configuration files.
mkdir /var/tmp/usb
Purpose: Create the temporary USB mount point.
mount_msdosfs /dev/da1s1 /var/tmp/usb
Purpose: Mount a FAT/FAT32 USB drive. Replace da1s1 if the SRX detects a different device such as da2s1.
mount -t msdosfs /dev/da1s1 /var/tmp/usb
Purpose: Mount a FAT/FAT32 USB partition.
mount -t msdosfs /dev/da1 /mnt
Purpose: Alternative FAT/FAT32 mount using /dev/da1 and /mnt.
ls /var/tmp/usb
Purpose: Confirm the firmware file is present.
file list /var/tmp/usb
Purpose: Verify that msqsrx-usb.conf is present.
file list /var/tmp/usb
Purpose: List files on the USB mounted at /var/tmp/usb.
show configuration | save /var/tmp/usb/msqsrx-usb.conf
Purpose: Save the active configuration to the mounted USB using the supplied filename.
show configuration | save /var/tmp/srx_backup.conf
Purpose: Save the active committed configuration from Operational mode to /var/tmp/srx_backup.conf.
file copy /var/tmp/srx_backup.conf /var/tmp/usb/
Purpose: Copy the configuration backup from internal storage to the USB mount point.
file copy /var/tmp/usb/srx_backup.conf /var/tmp/
Purpose: Copy the configuration backup from the mounted USB to internal /var/tmp.
umount /var/tmp/usb
Purpose: Unmount the USB before removing it.
umount /cf/var/tmp/usb
Purpose: Unmount the USB path used in this source example.
Normal CLI-based installation from a mounted USB when Junos is still running.
request system software add /mnt/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot
Purpose: Used when the USB was mounted on /mnt using /dev/da1.
request system software add /var/tmp/usb/junos.tgz no-validate reboot
Purpose: Install a valid Junos CLI installation package from the USB mount point and reboot. Replace junos.tgz with the exact compatible package name.
request system software add /var/tmp/usb/junos.tgz no-validate reboot
Purpose: Generic junos.tgz example.
request system software add /var/tmp/usb/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot
Purpose: 24.4R2.21 direct USB example.
request system software add /var/tmp/usb/junos23.tgz no-validate reboot
Purpose: Source example named junos23.tgz.
request system software add /var/tmp/usb/junos21.tgz no-validate reboot
Purpose: Source example named junos21.tgz.
Configure management IP, SSH, gateway and related settings when needed.
set system root-authentication plain-text-password
Purpose: Set the root password.
set system host-name srx
Purpose: Set hostname to srx.
set system services ssh
Purpose: Enable SSH.
set system services ssh root-login allow
Purpose: Allow root SSH login.
set interfaces fxp0 unit 0 family inet address 192.168.0.178/24
Purpose: Assign the example management IP to fxp0.
set security zones security-zone trust host-inbound-traffic system-services ssh
Purpose: Allow SSH host-inbound traffic on the trust zone.
set chassis alarm management-ethernet link-down ignore
Purpose: Ignore the management Ethernet link-down alarm if fxp0 is intentionally unused.
commit
Purpose: Validate and apply the candidate Junos configuration so the changes become active.
Stage an authenticated Juniper download directly into /var/tmp.
file copy "URL" /var/tmp. A Juniper account and appropriate software entitlement/support access may be required.file copy command below. The URL is time-limited.configure
Purpose: Enter Configuration mode before adding or changing management connectivity settings.
set interfaces fxp0 unit 0 family inet address <MANAGEMENT-IP>/<PREFIX-LENGTH>
Purpose: Assign an IPv5 management address to fxp0. Replace the placeholders with the address and prefix for your network. If you manage the SRX through another interface, use that interface instead.
set routing-options static route 0.0.0.0/0 next-hop <DEFAULT-GATEWAY-IP>
Purpose: Add a default route so the SRX itself can reach addresses outside the local management subnet.
set system name-server <DNS-SERVER-IP>
Purpose: Configure a DNS resolver so the SRX can resolve hostnames used by external services.
show | compare
Purpose: Review the candidate management, route and DNS changes before saving them.
commit
Purpose: Save and activate the configuration changes.
exit
Purpose: Leave Configuration mode and return to Operational mode.
show route 0.0.0.0/0
Purpose: Verify that a default route is present in the routing table.
ping 8.8.8.8 count 5
Purpose: Test basic IP connectivity to the internet without relying on DNS.
ping www.juniper.net count 5
Purpose: Test DNS resolution and external reachability. ICMP may be filtered on some paths, so a failed ping does not by itself prove HTTPS is unavailable.
file copy "<JUNIPER-GENERATED-DOWNLOAD-URL>" /var/tmp/
Purpose: Download the selected Junos package directly from the temporary URL generated by the Juniper Download Software page. Juniper documents this as the direct device-download method; paste the generated URL inside quotation marks.
file list /var/tmp/
Purpose: Confirm that the Junos package is present in /var/tmp after the download.
request system software validate /var/tmp/<JUNOS-INSTALL-PACKAGE>.tgz
Purpose: Optionally validate the downloaded Junos package before installation when supported for the release and upgrade path.
jfirmware, junos-install and junos-install-media-net examples are retained there; the loader-specific example remains in the recovery section.Juniper sources: Preparing for Software Installation and Upgrade; request system software add; and SRX software-download guidance. The direct Juniper device-download workflow uses a temporary URL copied from the authenticated Juniper download page rather than embedding your Juniper username/password in the SRX command.
Install the appropriate CLI package after it has been copied or downloaded to internal storage.
jfirmware-srxsme-mips-64-25.2R1.9.tgz, junos-install-srxsme-mips-64-25.2R1.9.tgz, and junos-install-media-net-srxsme-mips-64-25.2R1.9.tgz Operational-mode examples are all included below. The source-retained loader> install file:///var/tmp/junos-install-srxsme-mips-64-25.2R1.9.tgz example is kept in the Clean Install, Repartition & Recovery section because it belongs to the boot-loader environment.ls -lh /var/tmp/junos.tgz
Purpose: Verify a copied .tgz file and its size, if that is the filename used.
request system software add /var/tmp/junos.tgz no-validate reboot
Purpose: Install junos.tgz from internal storage and reboot.
request system software add /var/tmp/jfirmware-srxsme-mips-64-25.2R1.9.tgz no-validate reboot
Purpose: jfirmware 25.2R1.9 example from internal storage.
request system software add /var/tmp/junos-install-srxsme-mips-64-25.2R1.9.tgz no-validate reboot
Purpose: junos-install 25.2R1.9 example from internal storage.
rm /var/tmp/junos.tgz
Purpose: Delete the copied junos.tgz after it is no longer needed.
Version-dependent clean-install and repartition procedures. Read warnings carefully.
request system software add /var/tmp/usb/junos.tgz partition no-validate reboot
Purpose: Repartition and install the Junos package from USB, then reboot. This is destructive.
request system software add /var/tmp/junos-srxsme-23.4R2.13.tgz no-copy no-validate partition reboot
Purpose: Pre-24.4 SRX300-line repartition example. Back up first. The partition workflow does not apply the same way to Junos 24.4 and later.
boot -s
Purpose: Boot to single-user mode as recorded in the source.
install file:///junos-install-media-usb-srxsme-mips-64-<RELEASE>.img.gz
Purpose: Install Junos from a USB installation-media image at the loader prompt. Use the exact media-usb filename supplied by Juniper for your release.
Network-based staging and loader recovery when USB is unavailable.
setenv ipaddr 192.168.1.20
Purpose: Set the temporary SRX IP address in U-Boot for TFTP recovery.
setenv netmask 255.255.255.0
Purpose: Set the temporary network mask in U-Boot.
setenv serverip 192.168.1.10
Purpose: Set the TFTP server IP address in U-Boot.
setenv gatewayip 192.168.1.1Purpose: Set the default gateway in U-Boot when the TFTP server is not on the same subnet.
saveenvPurpose: Save U-Boot environment variables before rebooting to the loader stage.
resetPurpose: Reboot from U-Boot after saving the network environment so you can stop at loader>.
install tftp://192.168.1.10/junos-install-media-net-srxsme-mips-64-25.2R1.9.tgz
Purpose: From loader>, download and install the network-install media package from the TFTP server. This operation formats internal media.
install tftp://192.168.1.10/junos.tgz
Purpose: Install a Junos image from the example TFTP server using the shorter example filename.
scp carlos@192.168.0.102:/var/lib/tftpboot/junos-srxsme-21.2R1.10.tgz /var/tmp/
Purpose: Copy the Junos image from the source server to /var/tmp.
scp user@host:/path/to/junos.tgz /var/tmp/
Purpose: Generic SCP example for copying a Junos package from a remote host to /var/tmp.
request system software add /var/tmp/junos-srxsme-21.2R1.10.tgz no-copy
Purpose: Add the new software without copying the package again.
request system reboot
Purpose: Reboot the SRX.
Restore a saved configuration, compare it, commit it, and save a new recovery point.
file copy /var/tmp/usb/srx_backup.conf /var/tmp/
Purpose: Copy the configuration backup from the mounted USB to internal /var/tmp.
configure
Purpose: Enter Junos configuration mode.
load override /var/tmp/backup.conf
Purpose: Replace the candidate configuration with the specified backup file; review and commit before use.
load override /var/tmp/srx_backup.conf
Purpose: Replace the candidate configuration with the SRX backup file; review and commit before use.
show | compare
Purpose: Review candidate configuration changes against the active configuration before commit.
commit and-quit
Purpose: Commit the candidate configuration, apply it, and leave configuration mode.
request system configuration rescue save
Purpose: Save the current configuration as the rescue configuration.
Confirm Junos, firmware, partitions, alarms, interfaces, routing and logs after work.
show system information
Purpose: Check system information.
show chassis hardware detail
Purpose: Display detailed hardware information.
show chassis fpc pic-status
Purpose: Check FPC/PIC status.
show chassis routing-engine
Purpose: Check Routing Engine status.
show chassis environment
Purpose: Check chassis environmental state.
show system license
Purpose: Check licenses.
show system processes
Purpose: Display active system processes.
show log messages | match ERROR
Purpose: Filter system log messages for entries containing ERROR.
show route summary
Purpose: Display a summary of the routing table.
show version
Purpose: Display the current Junos release.
show chassis hardware
Purpose: Display chassis hardware.
show chassis alarms
Purpose: Check chassis alarms.
show system alarms
Purpose: Display active Junos system alarms.
show system alarms
Purpose: Check system alarms.
show system storage
Purpose: Check internal storage usage.
show system storage detail
Purpose: Display more detailed storage information.
show system uptime
Purpose: Check uptime.
show log messages | last 20
Purpose: Review the last 20 log lines.
file list /var/tmp
Purpose: List files in /var/tmp.
show interfaces terse
Purpose: Review interface state.
show configuration | display set | match root-authentication
Purpose: Check the root-authentication configuration line(s).
show system storage partitionsPurpose: Verify active/backup partition details and boot media on supported SRX devices.
show chassis routing-engine biosPurpose: Display the Routing Engine BIOS version on supported SRX platforms.
show system autorecovery statePurpose: Display saved autorecovery status on releases where autorecovery is supported.
Primary Juniper sources used to verify the recovery and upgrade procedures.
Master searchable command inventory retained for completeness.
Some commands intentionally appear earlier in workflow sections as well. Duplicate contextual appearances are retained because they help users follow a procedure.
Press Enter
Purpose: Wake the console session and display the SRX login prompt if it is not already visible.
root
Purpose: Example administrator username from the supplied notes. If the SRX uses another administrator account, enter that username instead.
ssh <username>@<management-IP>
Purpose: Open an SSH session to the SRX using the actual administrator username and management IP address.
root@SRX>
Purpose: Command retained from the supplied source material.
root@SRX#
Purpose: Command retained from the supplied source material.
root@SRX%
Purpose: Command retained from the supplied source material.
loader>
Purpose: Command retained from the supplied source material.
configure
Purpose: Enter Junos configuration mode.
edit <hierarchy>
Purpose: Navigate to a configuration hierarchy after you are already in Configuration mode. Use configure—not edit—to enter Configuration mode from Operational mode.
exit
Purpose: Leave configuration mode. If configuration changes were made, commit them first unless you intentionally intend to discard them.
start shell
Purpose: Enter the underlying shell environment.
start shell user root
Purpose: Enter the shell as root, as shown in the supplied upgrade example.
cli
Purpose: Start or return to the Junos CLI from the shell.
set <configuration-statement>
Purpose: Enter the required configuration statement from the relevant section.
show | compare
Purpose: Review candidate configuration changes against the active configuration before commit.
commit
Purpose: Validate and apply the candidate Junos configuration so the changes become active.
commit and-quit
Purpose: Commit the candidate configuration, apply it, and leave configuration mode.
request system configuration rescue save
Purpose: Save the current configuration as the rescue configuration.
request system autorecovery state save
Purpose: Save autorecovery state on releases where autorecovery is supported. On FreeBSD 12 / newer SRX software, Juniper directs you to snapshots instead.
request system storage cleanup
Purpose: Clean up extra files from local storage before an upgrade.
show version
Purpose: Display the current Junos release.
show system firmware
Purpose: See firmware / boot version information.
show system storage
Purpose: Check internal storage usage.
show system storage detail
Purpose: Display more detailed storage information.
show chassis hardware
Purpose: Display chassis hardware.
show system uptime
Purpose: Check uptime.
show system alarms
Purpose: Check system alarms.
show chassis alarms
Purpose: Check chassis alarms.
show interfaces terse
Purpose: Review interface state.
show configuration | display set | match root-authentication
Purpose: Check the root-authentication configuration line(s).
file list /var/tmp
Purpose: List files in /var/tmp.
show log messages | last 20
Purpose: Review the last 20 log lines.
mkdir /var/tmp/usb
Purpose: Create the temporary USB mount point.
mount_msdosfs /dev/da1s1 /var/tmp/usb
Purpose: Mount a FAT/FAT32 USB drive. Replace da1s1 if the SRX detects a different device such as da2s1.
mount -t msdosfs /dev/da1s1 /var/tmp/usb
Purpose: Mount a FAT/FAT32 USB partition.
mount -t msdosfs /dev/da1 /mnt
Purpose: Alternative FAT/FAT32 mount using /dev/da1 and /mnt.
ls /var/tmp/usb
Purpose: Confirm the firmware file is present.
file list /var/tmp/usb
Purpose: Verify that msqsrx-usb.conf is present.
show configuration | save /var/tmp/usb/msqsrx-usb.conf
Purpose: Save the active configuration to the mounted USB using the supplied filename.
show configuration | save /var/tmp/srx_backup.conf
Purpose: Save the active committed configuration from Operational mode to /var/tmp/srx_backup.conf.
file copy /var/tmp/srx_backup.conf /var/tmp/usb/
Purpose: Copy the configuration backup from internal storage to the USB mount point.
file copy /var/tmp/usb/srx_backup.conf /var/tmp/
Purpose: Copy the configuration backup from the mounted USB to internal /var/tmp.
umount /var/tmp/usb
Purpose: Unmount the USB before removing it.
umount /cf/var/tmp/usb
Purpose: Unmount the USB path used in this source example.
request system software add /mnt/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot
Purpose: Used when the USB was mounted on /mnt using /dev/da1.
request system software add /var/tmp/usb/junos.tgz no-validate reboot
Purpose: Install a valid Junos CLI installation package from the USB mount point and reboot. Replace junos.tgz with the exact compatible package name.
request system software add /var/tmp/usb/junos-install-srxsme-mips-64-24.4R2.21.tgz no-validate reboot
Purpose: 24.4R2.21 direct USB example.
request system software add /var/tmp/usb/junos23.tgz no-validate reboot
Purpose: Source example named junos23.tgz.
request system software add /var/tmp/usb/junos21.tgz no-validate reboot
Purpose: Source example named junos21.tgz.
ls -lh /var/tmp/junos.tgz
Purpose: Verify a copied .tgz file and its size, if that is the filename used.
request system software add /var/tmp/junos.tgz no-validate reboot
Purpose: Install junos.tgz from internal storage and reboot.
request system software add /var/tmp/jfirmware-srxsme-mips-64-25.2R1.9.tgz no-validate reboot
Purpose: jfirmware 25.2R1.9 example from internal storage.
request system software add /var/tmp/junos-install-srxsme-mips-64-25.2R1.9.tgz no-validate reboot
Purpose: junos-install 25.2R1.9 example from internal storage.
rm /var/tmp/junos.tgz
Purpose: Delete the copied junos.tgz after it is no longer needed.
set interfaces fxp0 unit 0 family inet address <MANAGEMENT-IP>/<PREFIX-LENGTH>
Purpose: Assign an IPv5 management address to fxp0. Replace the placeholders with the address and prefix for your network. If you manage the SRX through another interface, use that interface instead.
set routing-options static route 0.0.0.0/0 next-hop <DEFAULT-GATEWAY-IP>
Purpose: Add a default route so the SRX itself can reach addresses outside the local management subnet.
set system name-server <DNS-SERVER-IP>
Purpose: Configure a DNS resolver so the SRX can resolve hostnames used by external services.
show route 0.0.0.0/0
Purpose: Verify that a default route is present in the routing table.
ping 8.8.8.8 count 5
Purpose: Test basic IP connectivity to the internet without relying on DNS.
ping www.juniper.net count 5
Purpose: Test DNS resolution and external reachability. ICMP may be filtered on some paths, so a failed ping does not by itself prove HTTPS is unavailable.
file copy "<JUNIPER-GENERATED-DOWNLOAD-URL>" /var/tmp/
Purpose: Download the selected Junos package directly from the temporary URL generated by the Juniper Download Software page. Juniper documents this as the direct device-download method; paste the generated URL inside quotation marks.
file list /var/tmp/
Purpose: Confirm that the Junos package is present in /var/tmp after the download.
request system software validate /var/tmp/<JUNOS-INSTALL-PACKAGE>.tgz
Purpose: Optionally validate the downloaded Junos package before installation when supported for the release and upgrade path.
request system software add /var/tmp/usb/junos.tgz partition no-validate reboot
Purpose: Repartition and install the Junos package from USB, then reboot. This is destructive.
request system software add /var/tmp/junos-srxsme-23.4R2.13.tgz no-copy no-validate partition reboot
Purpose: Pre-24.4 SRX300-line repartition example. Back up first. The partition workflow does not apply the same way to Junos 24.4 and later.
boot -s
Purpose: Boot to single-user mode as recorded in the source.
install file:///junos-install-media-usb-srxsme-mips-64-<RELEASE>.img.gz
Purpose: Install Junos from a USB installation-media image at the loader prompt. Use the exact media-usb filename supplied by Juniper for your release.
setenv ipaddr 192.168.1.20
Purpose: Set the temporary SRX IP address in U-Boot for TFTP recovery.
setenv netmask 255.255.255.0
Purpose: Set the temporary network mask in U-Boot.
setenv serverip 192.168.1.10
Purpose: Set the TFTP server IP address in U-Boot.
setenv gatewayip 192.168.1.1Purpose: Set the default gateway in U-Boot when the TFTP server is not on the same subnet.
saveenvPurpose: Save U-Boot environment variables before rebooting to the loader stage.
resetPurpose: Reboot from U-Boot after saving the network environment so you can stop at loader>.
install tftp://192.168.1.10/junos-install-media-net-srxsme-mips-64-25.2R1.9.tgz
Purpose: From loader>, download and install the network-install media package from the TFTP server. This operation formats internal media.
install tftp://192.168.1.10/junos.tgz
Purpose: Install a Junos image from the example TFTP server using the shorter example filename.
scp carlos@192.168.0.102:/var/lib/tftpboot/junos-srxsme-21.2R1.10.tgz /var/tmp/
Purpose: Copy the Junos image from the source server to /var/tmp.
scp user@host:/path/to/junos.tgz /var/tmp/
Purpose: Generic SCP example for copying a Junos package from a remote host to /var/tmp.
request system software add /var/tmp/junos-srxsme-21.2R1.10.tgz no-copy
Purpose: Add the new software without copying the package again.
request system reboot
Purpose: Reboot the SRX.
set system root-authentication plain-text-password
Purpose: Set the root password.
set system host-name srx
Purpose: Set hostname to srx.
set system services ssh
Purpose: Enable SSH.
set system services ssh root-login allow
Purpose: Allow root SSH login.
set interfaces fxp0 unit 0 family inet address 192.168.0.178/24
Purpose: Assign the example management IP to fxp0.
set security zones security-zone trust host-inbound-traffic system-services ssh
Purpose: Allow SSH host-inbound traffic on the trust zone.
set chassis alarm management-ethernet link-down ignore
Purpose: Ignore the management Ethernet link-down alarm if fxp0 is intentionally unused.
bootupgrade -u /boot/uboot
Purpose: Upgrade primary U-Boot.
bootupgrade -s -u
Purpose: Upgrade the secondary boot loader using Juniper-documented bootupgrade syntax. Use only when the platform/release procedure calls for it.
bootupgrade -l /boot/veloader -x
Purpose: Upgrade Veloader.
bootupgrade -c u-boot
Purpose: Verify/check primary U-Boot CRC.
bootupgrade -s -c u-boot
Purpose: Verify/check secondary U-Boot CRC.
bootupgrade -c loader
Purpose: Verify/check loader CRC.
reboot
Purpose: Reboot after boot firmware work.
request system snapshot slice alternate
Purpose: Copy the active root file system to the alternate root slice on supported SRX platforms.
show system information
Purpose: Check system information.
show chassis hardware detail
Purpose: Display detailed hardware information.
show chassis fpc pic-status
Purpose: Check FPC/PIC status.
show chassis routing-engine
Purpose: Check Routing Engine status.
show chassis environment
Purpose: Check chassis environmental state.
show system license
Purpose: Check licenses.
show system processes
Purpose: Display active system processes.
show log messages | match ERROR
Purpose: Filter system log messages for entries containing ERROR.
show route summary
Purpose: Display a summary of the routing table.
show system storage partitionsPurpose: Verify active/backup partition details and boot media on supported SRX devices.
show chassis routing-engine biosPurpose: Display the Routing Engine BIOS version on supported SRX platforms.
show system autorecovery statePurpose: Display saved autorecovery status on releases where autorecovery is supported.
load override /var/tmp/backup.conf
Purpose: Replace the candidate configuration with the specified backup file; review and commit before use.
load override /var/tmp/srx_backup.conf
Purpose: Replace the candidate configuration with the SRX backup file; review and commit before use.
partition, rm, loader install, TFTP recovery, or low-level bootupgrade operations can alter boot media or make the device unavailable. Back up first and confirm the exact SRX model, upgrade path, bootloader prerequisite and package type before production use.commit only for Junos Configuration-mode changes. Operational >, Shell %, Boot Loader loader>, and administrator-PC commands do not use Junos configuration commits.root@SRX>show, request, fileroot@SRX#set / delete / commitroot@SRX%mount, cp, ls, rm, scploader>low-level recoveryUse this Juniper Support article before selecting an upgrade target. It is specifically intended to identify supported Junos upgrade paths for SRX platforms and helps determine whether an intermediate/jump release is required.
https://supportportal.juniper.net/s/article/Junos-upgrade-paths-for-SRX-platformsUse this Juniper documentation for broader information about Junos software packages, installation and upgrade preparation, storage, recovery, backup, software integrity and supported installation workflows.
https://www.juniper.net/documentation/us/en/software/junos/junos-install-upgrade/topics/topic-map/junos-os-overview.html