Blogs

Modern data center IP fabrics are built on VXLAN and EVPN. The technology is genuinely powerful: a decoupled underlay and overlay with multi-protocol BGP, Type-2 and Type-5 routes, distributed anycast gateways, etc. Getting it right rewards you with a fabric that is resilient, programmable, and scales cleanly from dozens to thousands of endpoints. Get any piece wrong, and you'll document an unfortunate discovery during an outage window. Adding a firewall into that fabric raises the stakes further — now the firewall itself has to participate in a control plane it wasn't originally designed for. Layer in a requirement for fast, stateful failover, and the complexity ...
Introduction Artificial Intelligence (AI) and Machine Learning (ML) training clusters can easily outgrow a single data hall. Power and cooling limits decide how many AI accelerators (XPUs) can be hosted in one building, and once that limit is reached, then the clusters need to be deployed across data halls. The network that provides connectivity among AI accelerator (XPU) backend fabrics is now commonly called Scale-Across [1,10,11]. Scale-Across is not a Wide Area Network (WAN) problem in the traditional sense, because traditional WANs are generally designed to tolerate packet loss, including tail drops, as Transmission Control Protocol (TCP) retransmits ...

HPE SRX-SSE Link

This TechPost provides an example of how to connect unmanaged users and systems behind an HPE SRX Firewall to HPE Security Services Edge (SSE) for security policy enforcement in the cloud. This facilitates a common cloud based policy for these systems as well as system with the SSE agent installed. In addition to connectivity itself, a deployed production setup is explored to provide a resilient connection to local and backup SSE POPs. Introduction In certain use cases, although the SRX is a fully capable NGFW, it may be desirable to enforce advanced security in the HPE SSE service using ZTNA principles beyond a single site context. This could be to unify ...
Dear Community Members, We’re bringing the Juniper Elevate Community and HPE Airheads Community together as one unified HPE Networking Community—a stronger, more connected hub where members can find product information, share best practices, and learn from peers across the HPE Networking portfolio. What this means for members: One destination for content and conversations: Access discussions, documentation, blogs, and product information in one place. Broader visibility and peer knowledge sharing: Engage with the full community, discover answers faster, and share best practices across a larger network. Simpler access and more ways ...

Introducing the QFX5140

The HPE Juniper Networking QFX5140 is a 1RU fixed-configuration data center switch built on the Broadcom Trident 5 ASIC, delivering 16 Tbps of switching capacity in a single rack unit. It combines 24× 400GbE QSFP112 ports with native 112G PAM4 SerDes and 8× 800GbE OSFP800 ports, breaking out to up to 160× 100GbE interfaces. Purpose-built for AI inference and storage fabrics, it pairs low-microsecond latency and right-sized on-chip buffering with RoCEv2, PFC, DCQCN, and dynamic load balancing. QFX5140 Top View Introduction The QFX5140-24CD8O is a 1RU fixed-form-factor switch that delivers 16 Tbps of switching capacity and is built on the Broadcom ...
Junos is moving colored transport resolution away from service-family-specific inetcolor/inet6color mechanisms and toward classful transports (CT), where transport intent is modeled as transport classes, per-class transport RIBs, and configurable resolution schemes for service-to-transport mapping. Future feature work in Junos is focused on CT rather than inetcolor. In this article we will dive into details of the history, differences between the resolution models, ways to migrate and validate the control and forwarding planes. Why colored transport resolution exists The basic problem is deceptively simple: two services may have the same remote PE next ...
HPE–Juniper Networks QFX Series switch platforms support ORv3-compliant data center deployments, aligning with Open Compute Project (OCP) Open Rack Version 3 (ORv3) specifications. Compliance is achieved through mechanical and electrical adaptations to the QFX platform, enabling integration into ORv3 rack infrastructure. Introduction The Open Compute Project (OCP) is an industry-wide collaborative initiative focused on optimizing the design, efficiency, and scalability of hyperscale data center and IT infrastructure. Its scope spans server hardware, rack and power architecture, storage systems, energy efficiency, and open networking platforms. This ...
Introduction — The Scale Problem Network service providers don't build their networks one router at a time — they scale them. The customer we worked with during this Professional Services engagement had hundreds of PE routers and, on top of them, thousands of VPN service instances . Every single one of those services had been hand-crafted directly on the Junos CLI. They worked. Traffic flowed. Customers were happy. But there was a catch: all of it lived entirely outside any controller. No single source of truth. No lifecycle automation. No closed-loop assurance. Every change was a keyboard operation, every audit was a diff exercise, and every new service ...
Read Part 2: Elevate Community Registration Closing Soon We’re pleased to share an exciting update: the Juniper Elevate Community and the HPE Airheads Community are coming together as one unified HPE Networking Community. This is more than a platform transition. It is an opportunity to bring two trusted technical communities together in a way that strengthens the experience for everyone. Elevate has long been a destination for Juniper customers, partners, and experts to exchange product knowledge, solve challenges, and share real-world guidance. Airheads has built a similarly strong tradition ...
Packet capture on QFX switches enables visibility into control-plane and data-plane traffic for efficient troubleshooting, traffic analysis, and network diagnostics. Flexible capture methods allow packets to be mirrored and analyzed, providing deeper insight into switch behavior and forwarding operations. Introduction Network troubleshooting frequently presents the challenge of sorting out discrepancies between control-plane and data-plane reported status and error conditions. For example, the control plane may report a fully healthy state across all interfaces, while the data plane silently drops traffic, causing application failures. In such scenarios, ...
Introduction Modern data center networks are increasingly built around overlay technologies that enable scalability, workload mobility, and efficient network segmentation. VXLAN has become a widely adopted solution for extending Layer 2 connectivity across Layer 3 infrastructures, serving as a foundational technology in many EVPN-based data center deployments. As organizations continue to expand cloud and distributed networking environments, ensuring secure communication across these overlay networks has become an important design consideration. To address this need, the QFX5130-48CM introduces VXLANsec support within the QFX switching portfolio, ...
Introduction With the rapid transition from traditional workloads to AI applications, data centers are undergoing a fundamental architectural change. Traditional compute-centric systems are unable to match the requirements of modern AI applications that need huge data mobility, parallel processing, and ultra-low latency. This has led to the growth of high-speed, interconnect fabrics that focus on bandwidth and efficiency, enabling smooth communication across thousands of compute nodes like GPUs, TPUs and other accelerators. GPUs are the brain of any current AI Clusters, but it is the precision timing that is the heartbeat synchronizing every ...
This Tech-Post validates WAN-MACSec over WAN on MX Trio 6 platforms, focusing on session scale and forwarding throughput under EAPOL/MKA operation. It provides configuration, verification commands, and practical observations from a 200-session testbed. Introduction MACSec is increasingly being deployed to secure Layer 2 communications between hosts and access switches, as well as between switches. Its value becomes even more significant when network links traverse public or untrusted infrastructure, such as inter-building connections. MACSec sessions are established using the MACSec Key Agreement (MKA) protocol. MKA relies on Extensible Authentication ...
Why we need this NGPE Solution We’re in the middle of a bandwidth step-change. AI workloads — training clusters, inference pipelines, and the east-west traffic they generate — are driving bandwidth utilization to levels the industry hasn’t seen before. To keep up, network platforms are moving to ever-higher-capacity interfaces: 100G and 400G today, 800G now shipping, and the industry already moving toward 1.6T Ethernet. Those interfaces are built on a new generation of high-throughput forwarding silicon. A modern aggregation router is designed, end to end, to drive high-speed ports at terabits per second — exactly what you want facing the core and the high-bandwidth ...
Introduction In L3VPN‑over‑SRv6 design, the metros and the core speak the same transport — IPv6 with Segment Routing. Production networks are rarely that tidy. Most operators run large, mature SR‑MPLS metros and want to slide a modern SRv6 core underneath them — without a flag day and without rebuilding the metros. This post shows how to carry a customer IPv4 L3VPN end‑to‑end across two SR‑MPLS metros that are glued together by an IPv6‑only SRv6 uSID core, using MPLS‑over‑SRv6 (Mo6) transport interworking and Inter‑AS Option C. The two border routers do all the heavy lifting: they encapsulate MPLS into SRv6 on the way in (H.Encaps) and decapsulate SRv6 ...
Introduction When people think about Artificial Intelligence (AI), they usually think about models, GPUs, and applications. They picture chatbots answering questions, copilots generating content, recommendation engines personalizing experiences, or image generators creating artwork. What often goes unnoticed is the network... Every AI interaction begins and ends with a network transaction. Before a model can generate an answer, a request must travel through access networks, service provider infrastructure, transport networks, data centers, storage systems, and compute platforms. Once the response is generated, it must make the journey back to ...
When a Broadband Network Gateway goes down, thousands of subscribers lose connectivity. Traditional BNG redundancy solutions often result in subscriber session loss, requiring DHCP reinitialization and leading to service disruption. Active Lease Query (ALQ) solves this challenge by synchronizing DHCP lease states between BNG peers in real time. When the active BNG fails, the standby BNG already has all subscribers provisioned and takes over seamlessly, with no DHCP re-establishment required. In this article, we validate ALQ-based chassis redundancy on MX480 BNGs with MPC10E TRIO-based line cards using EVPN-VPWS multihoming to demonstrate scalable and ...
BGP runs on trust, and route leaks and hijacks are what happen when that trust is misplaced. This article shows how three complementary mechanisms close the gap — BGP Roles with Only-To-Customer attribute prevent and detect leaks several hops from the source, and - if the leak already happened - RPKI Route Origin Authorization (ROA) helps validate the origin AS, and Autonomous System Provider Authorization (ASPA) confirms the full AS PATH is valley-free. Introduction Any BGP speaker can advertise a syntactically valid route for almost any prefix. Commercial relationships between autonomous systems, such as customer, provider, and peer, are supposed ...