JPR-961 JNCIE-SP Practice Questions
Prepare for JPR-961 with more than an answer.
- 1
You are creating an event script in Junos to automatically disable an interface if the input error rate exceeds a certain threshold. Which hierarchy level do you use to register this script so that the event policy can invoke it?
Show answer details
Correct answer: A
Event scripts are registered under
edit event-options event-script file. Once registered, they can be called by an event-policy using thethen event-scriptstatement. - 2
In a Segment Routing (SR-MPLS) deployment, you need to map an IPv4 prefix to a specific Segment ID (SID) that is consistent across the entire domain. Which configuration parameter defines this unique identifier for the loopback interface?
Show answer details
Correct answer: B
In Junos, the Node-SID (index) is typically configured under
protocols isis source-packet-routing node-segment ipv4-indexfor the router's loopback. This index is added to the SRGB start label to derive the actual MPLS label used by other routers to reach this node. - 3
A Service Provider is offering a 'Carrier-of-Carriers' (CoC) VPN service. The customer (Carrier A) wants to exchange labeled routes for their own internal VPNs across your backbone. Which protocol and family must be negotiated on the MP-BGP session between the Provider Edge (PE) router and the Customer Edge (CE) router?
Show answer details
Correct answer: B
In a Carrier-of-Carriers scenario, the customer CE needs to send MPLS-labeled traffic to the PE. The PE and CE exchange routes using BGP
family inet labeled-unicast(RFC 3107). This allows the CE to advertise its loopbacks with labels, so the SP core can build an LSP to the CE's loopbacks, enabling the customer to run their own VPN services inside the SP's VPN. - 4
You are the Senior Network Architect for a Service Provider designing a new Segment Routing over MPLS (SR-MPLS) core network. The network uses IS-IS as the IGP. You require a mechanism to steer traffic through a specific sequence of nodes that does not follow the shortest path calculated by the IGP, but you want to avoid maintaining per-flow state on transit routers. Which architectural component and corresponding configuration strategy best satisfies these requirements?
Show answer details
Correct answer: D
Segment Routing Traffic Engineering (SR-TE) allows source routing by pushing a stack of labels at the ingress. Using Adjacency-SIDs allows strict path control by specifying the exact links (adjacencies) to traverse. Unlike RSVP-TE, SR-TE does not require signaling or per-flow state on transit routers (mid-point state), satisfying the requirement.
- 5
A customer reports that their Layer 3 VPN traffic is being dropped periodically. During troubleshooting, you notice that the control plane of the PE router is experiencing high CPU utilization due to a DDoS attack targeting the routing engine. You need to implement a stateless protection mechanism that strictly limits specific protocol traffic while allowing legitimate management access. Which configuration applied to the loopback interface is most appropriate?
Show answer details
Correct answer: D
Stateless control plane protection is best implemented using a firewall filter applied to the loopback interface (lo0) in the input direction. This filter operates in hardware (ASIC) before traffic reaches the Routing Engine CPU, effectively dropping unwanted traffic and rate-limiting valid traffic if policers are attached.
- 6
You are configuring an Inter-Provider Layer 3 VPN (Option B) between AS 65100 and AS 65200. The Autonomous System Border Routers (ASBRs) are directly connected. You have established an MP-EBGP session between the ASBRs. However, the VPN routes are hidden on the receiving ASBR. What is the most likely cause of this issue?
Show answer details
Correct answer: A
In Inter-AS Option B, the ASBRs exchange labeled VPN-IPv4 routes. For the ASBR to accept and process MPLS packets on the interface connecting to the peer ASBR, the interface must be configured with the appropriate MPLS family (usually
family mpls). If the BGP session negotiatesinet-vpnbut the interface doesn't support MPLS, or if thefamily inet-vpnsignaling is present but the route is hidden, it is often due to the lack of an MPLS data path or next-hop resolution failure. However, a common specific Junos requirement for Option B is that the BGP session must be MP-BGP, and the routes are kept inbgp.l3vpn.0. If the ASBR doesn't havefamily mplson the physical link, it can't install the forwarding entry.
