Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

New and Changed Features

 

This section describes the new features and enhancements to existing features in the Junos OS main release and the maintenance releases for ACX Series Universal Metro Routers.

Release 16.2R2 New and Changed Features

This section describes the new features or enhancements to existing features for ACX Series Universal Metro Routers in Junos OS Release 16.2R2.

Class of Service

  • Support for CoS (ACX5000)—Junos OS for ACX5000 line of routers supports the following class of service (CoS) features:

    • Ingress classification

    • Fixed classification (interface-based classification)

    • Behavior aggregate (BA) classification

    • Multifield (MF) classification

    CoS features include rewrite, scheduling and buffer management, host outbound traffic, and statistics.

    In addition to these features, you can configure buffer partitions for multicast packets and shared buffer that the multicast packets in the queue can consume. To configure these features, use the buffer-partition multicast percent and multicast statements at the [edit class-of-service schedulers] hierarchy level.

    The following CoS behaviors are specific to the ACX5000 line of routers:

    • Strict priority queuing—Unlike other ACX routers, ACX5000 line of routers support committed information rate (CIR) among strict-priority queues. There is no implicit queue number-based priority among the strict-priority queues.

    • Weighted random early detection (WRED)—Unlike other ACX routers, ACX5000 line of routers support configuring drop profiles (to specify different drop behavior) for loss priorities low, medium-high, and high for both TCP and non-TCP protocols.

  • Support for IPv6 CoS (ACX5000)—Junos OS for ACX5000 line of routers supports IPv6 (dscp-ipv6) classification and rewrite.

Firewall

  • Support for IPv6 firewall filter (ACX5000)—Junos OS for ACX5000 line of routers supports IPv6 firewall filter at the [edit firewall family inet6 filter filter-name] hierarchy level.

  • Support for CoS, filter, and policer with VPLS (ACX5000)—Junos OS for ACX5000 line of routers supports Class of Service (CoS), firewall filters, and policers with the VPLS feature. The ACX5000 line of routers support CoS ingress classification and egress rewrite features with VPLS. VPLS firewall filters and policers can be configured at the logical interface family level.

IPv6

  • Support for IPv6 VPN provider edge router (6VPE) over MPLS (ACX5000)—Junos OS for ACX5000 line of routers provides IPv6 VPN provider edge router (6VPE) support over MPLS. ACX5000 line of routers act as a VPN provider edge router that provides IPV6 forwarding over MPLS. 6VPE adds IPv6 support to the current IPv4 MPLS by transporting IPv6 across MPLS core.

  • Support for DHCPv6 relay agent (ACX5000)—Junos OS for ACX5000 line of routers supports DHCPv6 relay agent. The DHCPv6 relay agent enhances the extended DHCP relay agent by providing DHCP support in an IPv6 network. DHCPv6 relay agents eliminate the necessity of having a DHCPv6 server on each physical network. An ACX5000 router configured as a DHCPv6 relay agent passes messages between the DHCPv6 client and the DHCPv6 server, similar to the way a DHCP relay agent supports an IPv4 network.

    To configure the DHCPv6 relay agent on ACX5000 line of routers, include the dhcpv6 statement at the [edit forwarding-options dhcp-relay] hierarchy level. You can also include the dhcpv6 statement at the [edit routing-instances routing-instance-name forwarding-options] hierarchy level.

  • Support for DHCPv6 server (ACX5000)—Junos OS supports configuring ACX5000 line of routers as a DHCPv6 server. The DHCPv6 server provides IPv6 address and other configuration information for the clients to configure itself. To configure the DHCPv6 server on the router, include the dhcpv6 statement at the [edit system services dhcp-local-server] hierarchy level.

    To configure the DHCPv6 server in a routing instance, include the dhcpv6 statement at the [edit routing-instances routing-instance-name system services dhcp-local-server] hierarchy level.

    You must also configure individual address pools and the DHCP attributes for the common address pools at the [edit access] hierarchy level.

    To maintain DHCPv6 subscribers whenever an interface delete event occurs (such as PFE reboot or crash), the following CLI is supported:

Management

  • Support for Ethernet ring protection switching (ACX5000)—Junos OS for ACX5000 line of routers supports Ethernet ring protection switching (G.8032v2). With the G.8032v2 capability, the ACX5000 line of routers support manual commands (force switch, manual switch, and clear) and interconnection of multiple Ethernet rings without virtual channels.

  • Support for OAM features (ACX5000)—Junos OS for ACX5000 line of routers supports the following OAM features:

    • Ethernet OAM

      • IEEE 802.3ah link fault management

      • Connectivity fault management (CFM) of down MEPs and up MEPs

      • ITU Y.1731 delay measurement and synthetic loss measurement (SLM)

    • Virtual circuit connection verification (VCCV) and Bidirectional Forwarding Detection (BFD)

  • Support for Layer 2, IP, MPLS, CoS, firewall, and OAM features (ACX5000)—Junos OS for ACX5000 line of routers supports Layer 2, IP, MPLS, multicast, CoS, firewall, and OAM features. The ACX5000 line of routers do not support the following features:

    • T1/E1 interfaces

    • IPsec and NAT services

    • Hierarchical policer

    • RFC 2544 generator

    • Real-time performance monitoring and Two-Way Active Measurement Protocol

    • Precision Timing Protocol (PTP) and Synchronized Ethernet

  • Connectivity fault management support for maintenance association intermediate points (ACX5000)—Junos OS for ACX5000 line of routers supports connectivity fault management (CFM) support for maintenance association intermediate points (MIPs). A MIP provides monitoring capability of intermediate points within a service.

  • Support for analyzer and flow mirroring (ACX5000)—Junos OS for ACX5000 line of routers supports both port mirroring and analyzer for mirroring the packets received or sent from a specific port. This feature is useful for debugging network problems and to prevent attacks on a network.

    Note

    ACX5000 line of routers supports only ingress mirroring. Analyzer with ingress interface or interface list is not supported.

    The ACX5000 line of routers supports the following mirroring:

    • VLAN mirroring—Support for VLAN mirroring using analyzer where input to mirror is a VLAN (Bridge domain).

    • Flow mirroring—Support for flow-based mirroring where the input for mirror is through firewall filter match and supports only Ethernet-switching and inet family types.

  • Support for unified forwarding table (ACX5000)—Junos OS for the ACX5000 line of routers supports the use of a unified forwarding table to optimize address storage. Using this feature, you can control the allocation of forwarding table memory available to store the following entries:

    • MAC addresses

    • Layer 3 host entries

    • Longest prefix match (LPM) table entries

    You can use five predefined profiles (l2-profile-one, l2-profile-two, l2-profile-three, l3-profile, lpm-profile) to allocate the table memory space differently for each of these entries. You configure and select the profiles that best suits your network environment needs.

    In addition to interface statistics, the following statistics are also supported on the ACX5000 line of routers with increased scale:

    • Logical interface statistics

    • MPLS unicast next hops statistics

    • Multicast route statistics

Routing Protocols

  • Support for Virtual Router Redundancy Protocol version 3 (ACX5000)—Junos OS for ACX5000 line of routers supports Virtual Router Redundancy Protocol (VRRP) version 3. With version 3, VRRP is supported over IPv6 addresses.

    VRRPv3 on ACX5000 line of routers supports:

    • Fast interval with minimum advertisement interval of 100 milliseconds

    • IRB interfaces

    • Aggregated Ethernet (AE) interfaces

    • Auto-generation of link local address

VPLS

  • Support for virtual private LAN service (ACX5000)—Junos OS for ACX5000 line of routers support the virtual private LAN service (VPLS) feature. With this feature, you can deploy the ACX5000 line of routers as part of a full-mesh VPLS domain, as well as a hub site for hierarchical VPLS (H-VPLS).

    Note

    Applying a forwarding table filter to a VPLS routing instance is not supported on ACX5000 line of routers.

Release 16.2R1 New and Changed Features

This section describes the new features or enhancements to existing features for ACX Series Universal Metro Routers in Junos OS Release 16.2R1.

Firewall

  • Enhancements to firewall filters (ACX Series)—Starting in Release 16.2, Junos OS for ACX Series Universal Metro Routers supports the following firewall filter enhancements:

    • Loopback filter support in egress direction.

    • Firewall filter rule match for source-prefix-list and destination-prefix-list.

    • Additional firewall filter actions on IRB interfaces.

  • Enhancements to support log and syslog firewall filter actions (ACX Series)—Starting in Release 16.2, Junos OS for ACX Series Universal Metro Routers supports log and syslog firewall filter actions in ingress and egress directions for family inet and family bridge protocol families.

    The following limitations apply:

    • Broadcast, unknown unicast, and multicast (BUM) traffic is not logged for family bridge and family inet filters in egress direction.

    • For egress log and syslog actions, DSCP, TTL, and IEEE 802.1p bits are matched based on ingress values.

    • For familyinet, the log and syslog filter actions do not work at egress if a packet is forwarded through the default route entry to egress.

    • For family bridge, the log and syslog filter actions do not work at egress if the filter term contains user-vlan-id, user-vlan-pri, and user-vlan-dei match conditions.

    • For family bridge and family inet, if a packet hits log or syslog actions on both the ingress and egress directions, only one log and one syslog message are recorded.

    • For family inet, if a packet hits reject action on ingress, the packet is not logged on the egress filter action.

  • Enhancements to unicast reverse-path forwarding (uRPF) check (ACX Series)—Starting in Release 16.2, Junos OS for ACX Series Universal Metro Routers supports uRPF check on IRB interfaces and uRPF fail filter configuration on IPv4 and IPv6 interfaces.

    Note

    The uRPF fail filter cannot match packets failed at ingress port check (strict mode).

    The uRPF fail filter can match packets failing source IP lookup but cannot match packets failing the input interface check (strict mode).

    The uRPF fail filter applies only to interface-specific instances of the firewall filter.

  • Filter support on the loopback interface (ACX Series)—Junos OS for ACX Series Universal Metro Routers provide support for applying a firewall filter on the loopback interface (lo0). Filters on the loopback interface are applied to protect the Routing Engine from various attacks.

IPv6

  • Support for IPv6 multicast using Multicast Listener Discovery protocol (ACX Series)—Junos OS for ACX Series Universal Metro Routers support IPv6 multicast using Multicast Listener Discovery (MLD) protocol. To support multicast data delivery, ACX line of routers support MLD (version 1 and version 2) for forming group membership in IPv6 networks and Protocol Independent Multicast (PIM) version 6 to form IPv6 multicast delivery tree.

    To configure MLD, include the mld statement at the [edit protocols] hierarchy level.

    To configure PIM, include the pim statement at the [edit protocols] hierarchy level.