Juniper · Junos OS

Junos Compare, Commit Confirmed and Rollback Reference

Quick answer #

show | compare reviews candidate changes. commit check validates the candidate without initially activating it. commit confirmed 5 activates it with a five-minute confirmation window. These are different actions, and a successful syntax check does not establish that the network will remain reachable.

Scope: Junos OS configuration workflow on MX/EX/SRX, subject to permissions, commit policies and platform behavior. Dual-RE and chassis-cluster procedures need their own runbook.

Review before activation #

Operational mode:

Review before activation
Junos OS · Operational CLI

Read-only
show system commit
Read-only
show configuration | compare rollback 1
Output may contain sensitive operational data.

Inside an authorized configuration session, at [edit]:

Review before activation
Junos OS · Configuration mode [edit]

Diagnostic state
top
Read-only
show | compare
Changes configuration
commit check

Preserve the confirmed-commit window until validation; a subsequent commit or commit check can confirm it. See recovery notes below.

The operational comparison examines the active configuration against an earlier stored version. The configuration-mode comparison examines the candidate against the active configuration. Keep those two comparisons distinct when explaining a change ticket.

Activate only after the change is approved #

Configuration-changing example, not a read-only diagnostic:

Activate only after the change is approved
Junos OS · Configuration mode [edit]

Changes configuration

Replace these example values: 123, CHG-1234.

commit confirmed 5 comment "CHG-1234: apply reviewed change"

Preserve the confirmed-commit window until validation; a subsequent commit or commit check can confirm it. See recovery notes below.

Perform the planned reachability, routing and service tests. Only after those tests pass, confirm the change:

Activate only after the change is approved
Junos OS · Configuration mode [edit]

Changes configuration

Replace these example values: 123, CHG-1234.

commit comment "CHG-1234: validation complete"

Preserve the confirmed-commit window until validation; a subsequent commit or commit check can confirm it. See recovery notes below.

Do not place activation and confirmation in one copy-all block. Immediately confirming would remove the recovery window before the tests happen. Include comments even where optional, so the history explains why the change occurred.

Understand rollback #

In configuration mode, rollback 0 reloads the active configuration into the candidate and discards uncommitted edits in that candidate. rollback 1 loads a previously committed configuration into the candidate; it does not itself activate it. Always inspect the resulting diff before a separate commit.

Coordinate with other administrators. A shared candidate may contain another person's edits, and rollback numbering changes as commits occur. Identify the intended version by commit history rather than assuming that version 1 always corresponds to the change you remember.

The confirmation trap #

Junos documents that a subsequent commit or commit check can confirm a pending confirmed commit. Therefore, do not run commit check casually during the validation window if you intend automatic rollback to remain available. Check the pending state with show system commit from operational mode.

A practical change workflow #

Record the baseline and recovery access, review the complete candidate diff, and define the service test before activation. Keep commands that alter configuration visually separate from observation commands. If validation fails, follow the approved recovery procedure instead of layering more unreviewed edits onto the problem.

Pitfalls and follow-up #

Automatic rollback is not a guarantee of zero packet loss, and it does not undo actions on other devices. Platform commit policies can require comments or additional handling. Junos Route Lookup and VRF Routing Table Commands and Junos BGP Troubleshooting: Neighbors and Advertised Routes provide routing checks; Junos Logs, NTP and System Health Commands provides timestamped system evidence. The IPv4 Subnet Calculator helps validate an addressing change before it enters the candidate configuration.

Sources

Documentation reviewed: 8 October 2026