ON THIS PAGE
ZTP Onboarding Process for NGPE Satellite Devices
Zero Touch Provisioning (ZTP) allows you to onboard NextGen Port Extender (NGPE) satellite devices from the aggregation device, requiring minimal user input. ZTP is supported in Junos OS Release 25.4R1-S2 and later.
Prerequisites
You will need to ensure the following requirements are met prior to implementing ZTP.
ZTP Onboarding Process
Configure Elements for ZTP Onboarding
Verification
Verify Satellite Onboarding
Once the ZTP process has started, you can monitor progress via live console access or
using the tail command on /var/log/jnu/ztp.log.
Sample Output DHCP server set for ZTP provisioning for satellite sd1. Please ensure the device is connected to the network and powered on for successful ZTP provisioning. Default password is hostname for satellite sd1. Please change the password after first login. 2026-03-23 22:27:10 IST ngpe_event_logging : DHCP local network 10.0.1.0/31 is mapped to interface et-0/0/0.0. 2026-03-23 22:27:10 IST ngpe_event_logging : dhcp binding is not yet active 2026-03-23 22:27:10 IST ngpe_event_logging : ZTP ongoing for satellite sd1. Triggered 720 seconds ago 2026-03-23 22:27:10 IST ngpe_event_logging : No satellite key files found. Exiting. Will retry in few minutes. ... 2026-03-23 22:48:42 IST ngpe_event_logging : DHCP local network 10.0.1.0/31 is mapped to interface et-0/0/0.0. 2026-03-23 22:48:42 IST ngpe_event_logging : dhcp binding is not yet active 2026-03-23 22:48:42 IST ngpe_event_logging : ZTP ongoing for satellite sd1. Triggered 1440 seconds ago 2026-03-23 22:48:42 IST ngpe_event_logging : ZTP configuration removed successfully on controller. 2026-03-23 22:48:42 IST ngpe_event_logging : Updated the satellite's ssh key. 2026-03-23 22:48:42 IST ngpe_event_logging : Activated JNU configuration for satellite. Please refer jnud logs for more details. Exiting.
The following commands can be used to further confirm satellite onboarding.
-
show chassis jnu role: displays whether a device is a controller or satellite.
If run from the AD: show chassis jnu role controller If run from a satellite: show chassis jnu role satellite
-
show chassis jnu satellites: displays the status of a single satellite or all satellites.
user@ad> show chassis jnu satellites Satellite Alive Model Version ------------------------------------------------------------------- sd1 up qfx5120-48y-8c 25.4R1-S2.3
-
show chassis port-extender: displays each virtual SD slot number, along with its IP address, MAC address, and cascade port number.
user@ad> show chassis port-extender Target MAC-address MAC Slot Description IP-address mode Base count Cascade-ports 100 sd1 10.100.100.1 N 80:63:7c:0e:af:39 1280 ae4001 -
show interfaces terse: displays the up/down status of interfaces; useful for confirming the NGPE fabric is up.
user@ad> show interfaces terse Interface Admin Link Proto Local Remote et-0/0/0 up up et-0/0/0.0 up up aenet --> ae4001.0 et-0/0/0.16384 up up aenet --> ae4001.16384 et-0/0/0.32767 up up aenet --> ae4001.32767 ... ae4001 up up ae4001.0 up up inet 10.0.1.0/31 multiservice ae4001.16384 up up inet 10.1.1.0/31 multiservice ae4001.32767 up up multiservice ... ge-100/0/0 up up ge-100/0/0.16386 up up ge-100/0/1 up up ge-100/0/1.16386 up up ge-100/0/2 up up ge-100/0/2.16386 up up ge-100/0/3 up up ge-100/0/3.16386 up up ge-100/0/4 up up ge-100/0/4.16386 up up ge-100/0/5 up up ge-100/0/5.16386 up up ge-100/0/6 up up ge-100/0/6.16386 up up ge-100/0/7 up up ge-100/0/7.16386 up up ge-100/0/8 up up ge-100/0/8.16386 up up ge-100/0/9 up up ge-100/0/9.16386 up up -
show lacp interfaces: check the status of aex participating in LACP
user@ad> show lacp interfaces Aggregated interface: ae4001 LACP state: Role Exp Def Dist Col Syn Aggr Timeout Activity et-0/0/0 Actor No No Yes Yes Yes Yes Fast Active et-0/0/0 Partner No No Yes Yes Yes Yes Fast Active et-0/0/1 Actor No No Yes Yes Yes Yes Fast Active et-0/0/1 Partner No No Yes Yes Yes Yes Fast Active LACP protocol: Receive State Transmit State Mux State et-0/0/0 Current Fast periodic Collecting distributing et-0/0/1 Current Fast periodic Collecting distributing Aggregated interface: ae4002 LACP state: Role Exp Def Dist Col Syn Aggr Timeout Activity et-0/0/2 Actor No No Yes Yes Yes Yes Fast Active et-0/0/2 Partner No No Yes Yes Yes Yes Fast Active et-0/0/3 Actor No No Yes Yes Yes Yes Fast Active et-0/0/3 Partner No No Yes Yes Yes Yes Fast Active LACP protocol: Receive State Transmit State Mux State et-0/0/2 Current Fast periodic Collecting distributing et-0/0/3 Current Fast periodic Collecting distributing -
show interfaces vtep: check the status of VTEP interfaces.
user@ad> show interfaces vtep Physical interface: vtep, Enabled, Physical link is Up Interface index: 136, SNMP ifIndex: 521 Type: Software-Pseudo, Link-level type: VxLAN-Tunnel-Endpoint, MTU: Unlimited, Speed: Unlimited Device flags : Present Running Interface Specific flags: Internal: 0x200 Link type : Full-Duplex Link flags : None Last flapped : Never Input packets : 0 Output packets: 0 Logical interface vtep.32768 (Index 387) (SNMP ifIndex 546) Flags: Up SNMP-Traps 0x4000 Encapsulation: ENET2 Ethernet segment value: 00:00:00:00:00:00:00:00:00:00, Mode: single-homed, Multi-homed status: Forwarding VXLAN Endpoint Type: Source, VXLAN Endpoint Address: 10.101.100.0, L2 Routing Instance: ngpe/ngpe-ad, L3 Routing Instance: ngpe/default Input packets : 0 Output packets: 0 Logical interface vtep.32769 (Index 432) (SNMP ifIndex 726) Flags: Up SNMP-Traps Encapsulation: ENET2 VXLAN Endpoint Type: Remote, VXLAN Endpoint Address: 10.101.100.1, L2 Routing Instance: ngpe/ngpe-ad, L3 Routing Instance: ngpe/default Input packets : 0 Output packets: 0 Protocol bridge, MTU: Unlimited Flags: Is-Primary, Trunk-Mode, 0xc000000 -
show l2-learning vxlan-tunnel-endpoint remote: check the status of remote VTEP interfaces
user@ad> show l2-learning vxlan-tunnel-endpoint remote Logical System Name Id SVTEP-IP IFL L3-Idx SVTEP-Mode ELP-SVTEP-IP ngpe 1 10.101.100.0 lo0.16000 9
-
show bfd session device-list [satellite-name(s)]: check the status of BFD sessions
user@ad> show bfd session device-list [sd1 sd2] sd1 -------------------------------------------------------------------- Detect Transmit Address State Interface Time Interval Multiplier 10.1.1.0 Up ae0.1 3.000 1.000 3 10.101.100.0 Up 5.000 1.000 5 2 sessions, 2 clients Cumulative transmit rate 2.0 pps, cumulative receive rate 2.0 pps sd2 -------------------------------------------------------------------- Detect Transmit Address State Interface Time Interval Multiplier 10.1.2.0 Up ae0.1 3.000 1.000 3 10.101.100.0 Up 5.000 1.000 5 2 sessions, 2 clients Cumulative transmit rate 2.0 pps, cumulative receive rate 2.0 pps -
request jnu satellite sync: needed if the SD failed to initially sync, meaning the SD is configured and working, yet it isn't associated with the AD.
user@sd1> request jnu satellite sync Junos node unifier process started, pid 99442
-
show configuration | display set: displays the active configuration on the device, where you can view all of the auto-generated NGPE configuration
-
show configuration services port-extender satellite satellite-name| display set: here you can confirm that the
ztpconfiguration knob is no longer present on this statement -
show log jnud: use this command to either monitor the progress of a satellite onboarding, or use after onboarding to check for any errors.
user@ad> show log jnud Nov 25 05:18:39 jnud_open_netconf_session : Host name : 10.100.100.0 - User name : jnuadmin Nov 25 05:18:39 jnud_send_request_to_node - Node : 10.100.100.0 RPC : <mgd-jnu-get-lock/> Nov 25 05:18:39 jnud_send_request_to_node - Node : 10.100.100.0 RPC : <mgd-jnu-get-lock/> successfull Nov 25 05:18:39 jnud_receive_response_from_node : 10.100.100.0 Nov 25 05:18:40 jnud_get_release_lock: rpc <mgd-jnu-get-lock/> passed Nov 25 05:18:40 jnud_get_release_lock: rpc <mgd-jnu-get-lock/> passed Nov 25 05:18:40 jnud_send_file_remote_scp: Copying the files with scp -O -o StrictHostKeychecking=no -i /var/db/jnu/.ssh/id_rsa /var/tmp/jnu_initial_sync jnuuser@10.100.100.0:/var/tmp/jnu_initial_sync Nov 25 05:18:41 jnud_send_request_to_node - Node : 10.100.100.0 RPC : <mgd-jnu-schema-add> <model>qfx5120-48y-8c</model> <version>25.4R1-S2.3</version> <filename>/var/tmp/sd1-schema-258.tar.gz</filename> <model-id>169</model-id> </mgd-jnu-schema-add> Nov 25 05:18:41 jnud_send_request_to_node - Node : 10.100.100.0 RPC : <mgd-jnu-schema-add> <model>qfx5120-48y-8c</model> <version>25.4R1-S2.3</version> <filename>/var/tmp/sd1-schema-258.tar.gz</filename> <model-id>169</model-id> </mgd-jnu-schema-add> successfull Nov 25 05:18:41 jnud_receive_response_from_node : 10.100.100.0 Nov 25 05:18:42 jnud_sync_dual_controller: schema create rpc passed