JN0-106 Junos Configuration Basics Practice Question
A junior engineer is tasked with configuring a firewall filter to only allow SSH access to the management interface. The management interface is fxp0. Which configuration is correct?
⚠ Common exam trap
Watch out — candidates often confuse the management interface (fxp0) with the loopback interface (lo0) or a data-plane interface (ge-0/0/0), leading candidates to apply the filter to the wrong interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
set interfaces fxp0 unit 0 family inet filter input allow-ssh
The management interface on Juniper devices is fxp0, and applying a firewall filter to its inet family input direction restricts inbound traffic. The filter 'allow-ssh' must permit only TCP port 22, blocking all other management access. This configuration ensures SSH-only access to the management interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
set interfaces lo0 unit 0 family inet filter input allow-ssh
Why it's wrong here
The loopback interface lo0 is a virtual interface that represents the router itself and is used for protocols like OSPF and for router identification, not for out-of-band management. Applying an input filter to lo0 would affect all traffic destined to any of the router's local addresses, which is a much broader and riskier control-plane filtering action. In contrast, fxp0 is the dedicated management Ethernet interface on many Junos platforms, and filtering there specifically protects out-of-band management access without impacting protocol traffic.
- ✗
set groups management-filter interfaces fxp0 unit 0 family inet filter input allow-ssh
Why it's wrong here
The 'groups' hierarchy is for defining configuration groups that can be reused with the 'apply-groups' statement; it is not a direct way to apply a firewall filter. Simply defining a group does not activate anything—the group data is only active where it is explicitly applied. The command 'set groups management-filter interfaces fxp0 ...' creates a configuration group but never references it, so the filter would not be applied to any interface. To use groups, you would also need an 'apply-groups' statement at a higher hierarchy level, which is missing here.
- ✗
set interfaces ge-0/0/0 unit 0 family inet filter input allow-ssh
Why it's wrong here
Interface ge-0/0/0 is a typical data-plane network port used for transit traffic, not the out-of-band management interface. On Junos devices, the management port is specifically named fxp0 (or em0/vme on newer platforms) and is physically separate from the forwarding plane ports. Applying a filter to ge-0/0/0 would only filter traffic that enters or leaves that data port, leaving the actual management interface unguarded and still allowing unrestricted SSH.
- ✓
set interfaces fxp0 unit 0 family inet filter input allow-ssh
Why this is correct
This command correctly applies the firewall filter 'allow-ssh' to the management interface fxp0 under the inet family. fxp0 is the dedicated out-of-band management port on many Junos platforms, and because 'unit 0' is the logical unit for that interface, the input filter will inspect all IPv4 traffic arriving on it. With this configuration, SSH traffic is filtered according to the 'allow-ssh' term, providing a targeted control-plane protection mechanism separate from data-plane interfaces.
Visual reference
Go deeper
Related to this question
About these practice questions
This JN0-106 question is part of Courseiva's 326-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This JN0-106 practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JN0-106 exam.