IPv4 subnetting & address planning
Calculate boundaries, size a subnet and identify address-plan mistakes before touching a device.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance

Wolex network reference library · Free · No signup
12 detailed topic guides and six platform field sheets for network engineers. Protocol tables, visual explanations, command comparisons, worked examples and troubleshooting sequences—online and in Wolex-branded PDFs.
12 topic guides · Tables + diagrams + examples
Start with the protocol or search the full guide content for a symptom, command or concept. Each topic includes an individual PDF.
12 topic guides
Calculate boundaries, size a subnet and identify address-plan mistakes before touching a device.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Read IPv6 prefixes and troubleshoot link-local neighbors, router advertisements and dual-stack failures.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Follow one endpoint VLAN across access ports, trunks and the gateway without confusing link state with forwarding.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Interpret root election and port roles, distinguish expected blocking from a fault and check MST boundaries.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Check whether links are actually participating in a bundle and explain why a single flow does not use its total capacity.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Use neighbor state to narrow the fault, then verify the intended prefix reaches the routing and forwarding tables.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Separate peer health, received paths, policy acceptance, best-path selection, installation and advertisement.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Track the original and translated tuples and avoid the common destination-NAT address-versus-zone mistake.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Separate IKE negotiation, IPsec selectors and real encrypted application traffic.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Find the conversation, inspect handshake failures and use TCP analysis flags as leads rather than verdicts.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Capture a bounded, targeted conversation and read a saved trace without unnecessary name lookups.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
Define what working means before the cutover, preserve a recovery path and close with evidence rather than a reachable CLI.
Quick table · Visual explanation · Commands · Worked example · Troubleshooting · Acceptance
No matching guides. Try a broader term or reset the library search.
Original Wolex content and diagrams, supported by linked vendor documentation and protocol specifications. Independently produced; no vendor affiliation is implied.
Quick checks for Cisco, Juniper and Palo Alto, plus cross-vendor cutover workflows. Download the six platform sheets.
25 reference cards
Inspection commands are read-only unless labeled otherwise. Replace example interfaces, documentation IP addresses and <PLACEHOLDERS>. Confirm syntax and features for your model, software release and routing context.
Read-only inspection
show interfaces status
show interfaces GigabitEthernet1/0/1Inspect: Compare link state, speed/duplex and rising error counters. A single cumulative CRC count does not prove an active fault.
Next: Take two timestamped samples; inspect both ends and the physical path before changing speed or bouncing the port.
Interface is an example; replace it. Cable diagnostics can affect service and are not part of this read-only block.
Read-only inspection
show interfaces GigabitEthernet1/0/1 switchport
show interfaces trunkInspect: Compare access/native VLAN and allowed/active VLANs along the uplink path.
Next: Check the same VLAN at the far end, then its gateway and the endpoint IP settings.
Do not assume trunk means every VLAN is forwarded.
Read-only inspection
show spanning-tree vlan 30
show etherchannel summaryInspect: Identify the root, forwarding/blocking roles and bundled versus individual members.
Next: Check VLAN and LACP settings on the peer; determine whether STP blocking is expected.
VLAN 30 is illustrative. Do not disable STP or force channel mode to hide a mismatch.
Read-only inspection
show interfaces status
show interfaces trunk
show etherchannel summaryInspect: Compare uplink state, VLAN carriage and bundle members with the saved baseline.
Next: Test management from a separate path and one real application per affected VLAN before saving the accepted running configuration.
Pre-stage interface mapping, console access and a tested backup/recovery method. A syntax-valid configuration is not proof of working service.
Read-only inspection
show ip route 192.0.2.10
show ip cef 192.0.2.10Inspect: Compare the selected route with the forwarding entry, resolved next hop and outgoing interface.
Next: Verify next-hop reachability and the destination-side return route in the same routing context.
192.0.2.10 is a documentation address; replace it. CEF output alone does not prove hardware forwarding or firewall permission.
Read-only inspection
show ip bgp summary
show ip bgp 192.0.2.0Inspect: Distinguish neighbor state from received prefixes and selected paths. A numeric prefix count indicates an established session.
Next: Check address family and import/export policy; confirm that the selected prefix is actually installed in the IP routing table.
A healthy TCP/BGP session does not guarantee the needed prefix is accepted or advertised.
Read-only inspection
show ip cef exact-route 198.51.100.10 192.0.2.10Inspect: Identify the forwarding choice for this source/destination pair.
Next: Compare source networks, routing context, ACL/NAT policy and return path; reproduce the failing application tuple.
Documentation addresses; replace both. Policy-based routing can alter the path. This is not a complete PBR or security-policy evaluation.
Read-only inspection
show ip route 192.0.2.10
show ip cef 192.0.2.10
show ip bgp summaryInspect: Compare next hop, forwarding choice and expected peers with the pre-change baseline.
Next: Verify application traffic from affected source networks; use the reviewed recovery plan if acceptance fails. Save only the accepted configuration.
IOS XE changes normally affect running state immediately. Configuration replacement needs a compatible full backup and platform-specific preparation; do not paste a generic rollback command.
Read-only inspection
show interfaces terse
show interfaces ge-0/0/1 extensiveInspect: Separate physical Admin/Link state from logical-unit protocol state; compare error-counter deltas.
Next: Inspect the peer and cabling, then verify whether the required logical unit exists and is configured for the intended service.
Replace ge-0/0/1 with the actual member/port. A physical up state does not prove VLAN or L3 reachability.
Read-only inspection
show ethernet-switching table
show vlansInspect: Check VLAN membership and where the client MAC is learned.
Next: Generate controlled client traffic; follow the MAC along each hop and then check the gateway ARP/route.
Use EX/QFX switching syntax. MX bridge-domain tables and ELS/non-ELS configuration stanzas differ.
Read-only inspection
show lacp interfaces
show virtual-chassis status
show virtual-chassis vc-port all-membersInspect: Check LACP participation, expected member roles and VCP links.
Next: Compare serial/member mapping and peer state with the design; inspect links before attempting a membership change.
Run VC commands only on a supported Virtual Chassis. Stack changes can affect management and transit traffic.
Read-only inspection
show interfaces terse
show ethernet-switching table
show lacp interfacesInspect: Compare ports, VLAN learning and expected aggregate participation against the baseline.
Next: Use the Junos change sequence below; test management and affected applications before confirming the timed commit.
Pre-check EX model, release, ELS syntax, member IDs and optics. Do not assume EX3300 configuration stanzas can be copied unchanged to every EX3400 release.
Read-only inspection
show route 192.0.2.0/24 detail
show route forwarding-table destination 192.0.2.10Inspect: Separate route selection from the forwarding-table entry and next-hop resolution.
Next: Check the correct routing instance, preference/policy and next-hop reachability; verify a route for the return source.
Examples target inet.0. A route in another table does not automatically provide reachability here.
Read-only inspection
show bgp summary
show route advertising-protocol bgp 198.51.100.1
show route receive-protocol bgp 198.51.100.1Inspect: Compare session state with advertisements and received paths for the actual neighbor.
Next: Inspect policy and active-route eligibility, then test the destination from the actual source network.
Replace the neighbor. Received-route display is not proof that the route is active or forwarded.
Read-only inspection
show interfaces terse
show interfaces xe-0/0/0 extensiveInspect: Compare interface state, MTU and counter changes on the suspected path.
Next: Test return routing and application-size behavior; for MPLS/VPN environments verify labels and service tables using the release-specific guide.
A small ping can work while larger packets fail. This sheet does not prescribe a universal MTU.
Read-only inspection
show route 192.0.2.0/24 detail
show bgp summary
show route forwarding-table destination 192.0.2.10Inspect: Compare route activity, peers and next hops against the pre-change baseline.
Next: Use the Junos change sequence below, then verify source-specific application traffic and the reverse path before confirming.
On dual Routing Engines, use the platform-reviewed synchronization method. Do not commit independently on a backup RE as a generic recovery step.
Read-only inspection
show session all filter source 198.51.100.10 destination 192.0.2.10
show session id <SESSION_ID>Inspect: Inspect both flow directions, rule, zones, application, translations and byte counters.
Next: Compare the original and translated tuple with traffic logs and the return route during a fresh, controlled attempt.
Replace the addresses and session ID. No matching session is not by itself proof of a firewall deny.
Read-only inspection
test security-policy-match from <SOURCE_ZONE> to <DEST_ZONE> source 198.51.100.10 destination 192.0.2.10 destination-port 443 protocol 6Inspect: Compare the matched rule with the intended zones, addresses, protocol and port.
Next: Add the actual application/user context where needed; validate the real session and traffic log after a controlled attempt.
Policy simulation is not end-to-end traffic proof. NAT, PBF, App-ID, User-ID, decryption and existing sessions can change what you observe.
Read-only inspection
show vpn ike-sa
show vpn ipsec-sa
show vpn flowInspect: Separate IKE state, IPsec state and traffic/counter movement.
Next: Verify selectors/proxy IDs, tunnel routing, policy/NAT and return routes; test the actual application from both sides.
An established tunnel does not prove that a subnet or application is permitted through it.
Read-only inspection
test routing fib-lookup ip 192.0.2.10 virtual-router <VR_NAME>Inspect: Identify the route/egress selected by the specified legacy virtual router.
Next: Check PBF and session egress, then the reverse path. For Advanced Routing Engine deployments use its logical-router command reference.
Use the correct vsys/VR. The legacy and advanced routing command sets differ.
Read-only inspection
show config diff
show jobs all
show high-availability stateInspect: Review candidate/running differences, commit job outcome and HA state.
Next: Validate and review scope before commit; after commit, check logs and new sessions for intended allows and intended denies. For Panorama, verify the push job and target device.
Export a protected configuration backup and document the recovery procedure first. A successful commit does not prove that the application works. These commands do not perform a commit or HA failover.
Read-only inspection
Inspect: Write source, destination, TCP/UDP port, time, source VLAN/VRF and expected path. Separate DNS resolution from reachability.
Next: Check link -> VLAN/MAC -> gateway/ARP -> route -> policy/NAT -> session -> reverse path. Keep the failing tuple unchanged between tests.
Engineer-authored method. Do not substitute a device management ping for the affected client application test.
Workflow / scoped active test
Inspect: Compare packet sizes, path MTU, tunnel overhead and whether required ICMP feedback is permitted.
Next: Use a scoped, rate-limited size test in both directions with platform-appropriate DF options; correlate counters or an approved filtered capture.
Active probes generate traffic. Do not guess a universal MTU or enable an unrestricted production capture.
Read-only inspection
Inspect: Collect model/release, timestamp/timezone, topology, affected tuple, counter deltas and relevant sanitized outputs.
Next: State what works, what fails, the last change and which hop is supported by evidence. Record the owner and next validation step.
Remove secrets and unnecessary customer identifiers. Full support bundles can be large and sensitive; gather deliberately.
Change planning
Inspect: Before: record ports, optics, VLANs, peers, routes, management path, version compatibility and an approved backup. Define acceptance and rollback triggers.
Next: During: make one reviewed change, track timing and preserve console access. After: test management plus real services, intended denies, redundancy and monitoring; compare with baseline.
Close only after acceptance, saved/confirmed configuration and updated documentation. A reachable CLI is not full deployment acceptance.
No matching cards. Try a broader term or reset the filters.
A reference helps you collect evidence. Wolex can help turn it into a reviewed migration, infrastructure fix or security improvement.