Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Routing Protocols

  • Support for micro-SIDs in TI-LFA, microloop avoidance, flex algo, and IS-IS MT (ACX Series)—Starting in Junos OS Evolved Release 23.4R1, we extend the support of compressing SRv6 addresses into a single IPv6 address (micro-SID) in topology-independent loop-free alternate (TI-LFA), microloop avoidance, and Flexible Algorithm (flex algo) path computations. From this release onward, you can also configure algorithms for micro-segment identifiers (micro-SIDs) to facilitate the new extended feature. We also support IPv6 unicast topology (part of IS-IS MT) in TI-LFA, microloop avoidance, and flex algo computations.

    To enable flex algo to install the ingress routes in transport class routing information bases (RIBs), configure the use-transport-class statement at the [edit routing-options flex-algorithm id] hierarchy level.

    [See How to Enable SRv6 Network Programming in IS-IS Networks .]

  • Support for OSPFv2 HMAC SHA-1 keychain authentication and optimization for multi-active MD5 keys (ACX7024, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509, PTX10001-36MR, PTX10003, PTX10004, PTX10008, and PTX10016)—Starting in Junos OS Evolved Release 23.4R1, you can enable OSPFv2 HMAC-SHA1 authentication with keychain to authenticate packets reaching or originating from an OSPF interface. This feature ensures a smooth transition from one key to another for OSPFv2 with enhanced security.

    You can enable OSPFv2 to send packets authenticated with only the latest MD5 key after all the neighbors switch to the latest configured key. In Junos OS Evolved releases earlier than Release 23.4R1, we support advertising authenticated OSPF packets always with multiple active MD5 keys with a maximum limit of two keys per interface.

    To enable OSPFv2 HMAC-SHA1 authentication, configure the authentication keychain <keychain name> option at the [edit protocols ospf area area-id interface interface_name hierarchy level. To enable optimization of multiple active MD5 keys, configure the delete-if-not-inuse option at the [edit protocols ospf area area-id interface interface_name authentication multi-active-md5] hierarchy level.

    [See Understanding OSPFv2 Authentication.]

  • Support for Next-Hop Dependent Capability Attribute (ACX7100-32C and PTX10001-36MR)—Starting in Junos OS Evolved Release 23.4R1, we use the Entropy Label Capability (ELCv3) attribute defined within the IETF Next-Hop Dependent Capability Attribute for load balancing. This attribute replaces the existing ELCv2 attribute. To operate the ELCv2 attribute along with ELCv3, explicitly configure the elc-v2-compatible statement at the labeled-unicast entropy-label hierarchy level.

    [See Understanding Entropy Label for BGP Labeled Unicast LSP.]

  • Support for limiting the number of BGP sessions belonging to a subnet (ACX7100-32C and PTX10001-36MR)—Starting in Junos OS Evolved Release 23.4R1, we support limiting the number of BGP sessions belonging to a given subnet that is configured using the ‘allow statement. You can use this feature to configure wider subnets by limiting the number of BGP sessions over them. You can set this limit using the peer-limit value statement at the [edit protocols bgp group group-name dynamic-neighbor] hierarchy level.

    [See peer-limit.]