Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation  Back up to About Overview 

Known Behavior

This section contains the known behaviors, system maximums, and limitations in hardware and software in Junos OS Release 15.1X49-D10.

Attack Detection and Prevention (ADP)

  • On all branch SRX Series devices, the fast path bad-inner-header screen is always performed first, followed by the first path signature screen.
  • On all high-end SRX Series devices, the first path signature screen is performed first, followed by the fast path bad-inner-header screen.
  • On all SRX Series devices, when a packet allow or drop session is established, the bad-inner-header screen is performed on every packet, because this screen is a fast path screen.

CLI

  • On SRX5000 line devices, the following CLI statement is deprecated—rather than immediately removed—to provide backward compatibility and a chance to bring your configuration into compliance with the new configuration:

    set chassis fpc <fpc-slot> services offload

    The following new CLI statement replaces the deprecated CLI statement:

    set chassis fpc <fpc-slot> np-cache

Layer 2 Features

  • On all branch SRX Series devices, configuring the Layer 2 Ethernet switching family in transparent mode for an interface is not supported.

Network Address Translation (NAT)

  • On high-end SRX Series devices, the number of IP addresses for NAT with port translation has been increased to 1M addresses since Junos OS Release 12.1X47-D10.

    The SRX5000 line, however, supports a maximum of 384M translation ports and cannot be increased. To use 1M IP addresses, you must confirm that the port number is less than 384. The following CLI commands enable you to configure the twin port range and limit the twin port number:

    • set security nat source pool-default-twin-port-range <low> to <high>
    • set security nat source pool sp1 port range twin-port <low> to <high>

Software Installation and Upgrade

  • In-Service Software Upgrade (ISSU) is not supported for upgrading from earlier Junos OS releases to Junos OS Release 15.1X49. ISSU is supported for upgrading to successive Junos OS Release 15.1X49 releases and to major Junos OS releases.
  • On all high-end SRX Series devices, unified ISSU is supported from Junos OS Release 12.1X45 to Junos OS Release 12.1X46 and from Junos OS Release 12.1X46 to Junos OS Release 15.1X49-D10. Unified ISSU is not supported from Junos OS Release 12.1X45 to Junos OS Release 15.1X49-D10.

VPN

  • On a high-end SRX Series device, VPN monitoring of an externally connected device (such as a PC) is not supported. The destination IP address for VPN monitoring must be a local interface on the high-end SRX Series device.

Related Documentation

Modified: 2016-12-21